Partial
Risk management practices may be informal, reactive, or inconsistently understood across the organization.
- Ad hoc decisions
- Limited awareness
- Inconsistent outcomes
NIST CSF 2.0 is an outcome-based way for a small organization to organize cybersecurity risk, communicate priorities, and improve over time. It is not a certification by itself—and it works best when leadership direction is explicit.
01 · The CSF Core
The Functions describe complementary cybersecurity outcomes. Use them as a loop of decisions and feedback—not a rigid waterfall where one Function is ever “finished.”
The CSF 2.0 addition
Strategy, roles, policy, supply-chain risk, and oversight set the direction for every other Function.
Govern is not an afterthought or a policy shelf. It is where a small organization decides what matters, who can make the call, how risk fits the mission, and when leadership revisits those decisions.
Know what matters
Build enough context to decide what deserves protection first.
Identify is the organization’s working picture of assets, data, people, dependencies, threats, and business impact. A small team does not need an inventory project that never ends; it needs a useful boundary and a shared view of material risk.
Put safeguards to work
Use sensible protections to reduce the chance and impact of harm.
Protect covers the safeguards that make the organization harder to compromise and easier to operate safely. Think access, training, data security, platforms, and resilient technology—not a stack of policies disconnected from daily work.
Notice meaningful change
Spot anomalies, compromise, and control drift early enough to act.
Detect makes visibility operational. It helps a small organization define what it watches, what counts as an anomaly, how alerts are triaged, and how it knows when a control or service has drifted away from the intended state.
Contain and coordinate
Act on a cybersecurity event with clear decisions and communication.
Respond is the playbook for when something changes. It connects incident analysis, containment, reporting, communications, and mitigation so the organization is not inventing its first move during an already stressful event.
Restore and improve
Bring important services back and turn disruption into learning.
Recover focuses on restoring operations, communicating progress, and improving the system after an event. It includes the resilience habits that keep one incident from becoming the organization’s recurring operating model.
A lifecycle, not a checklist
Govern sets the conditions for Identify and Protect. Detect feeds Respond; Respond and Recover update what the organization governs next. Real improvement moves back and forth as the business, threats, and dependencies change.
02 · Organizational rigor
Partial, Risk Informed, Repeatable, and Adaptive are not pass/fail certification levels. They characterize the rigor and integration of governance and management across the organization.
Risk management practices may be informal, reactive, or inconsistently understood across the organization.
Leadership recognizes risk, but practices may not yet be organization-wide, repeatable, or consistently funded.
Policies, processes, and practices are formally approved, consistently followed, and reviewed as conditions change.
The organization adapts its cybersecurity practices using lessons, changing threats, and near-real-time awareness.
A Tier is context for a conversation about maturity and integration. It is not a substitute for a framework-specific requirement, assessment, attestation, or certification.
03 · Make it useful
A Profile gives the CSF context: why the work matters, what is in scope, where the organization is now, and what a defensible next state looks like.
The Profile is a decision document, not a giant spreadsheet. Keep the scope narrow enough to maintain and specific enough to guide owners and evidence work.
A practical test
Can a leader understand the priority, the owner, and the next decision without opening a 200-page binder?
Name the mission, service, customer promise, contract, or risk decision the Profile should support. Identify the systems, people, facilities, suppliers, and stakeholders that belong in the conversation.
Use the CSF Core to choose the Functions, Categories, and outcomes that fit the organization’s objectives. The CSF is flexible; a useful Profile is scoped, not maximal.
Describe the outcomes the organization currently achieves, the evidence behind that view, and the assumptions or gaps that need attention. Keep uncertainty visible instead of grading around it.
Describe the outcomes needed for the mission, buyer, contract, or risk appetite. Target does not mean “everything for everyone”; it means a defensible future state for this boundary.
Turn the Current-to-Target gap into a sequence of decisions, owners, evidence requests, and dates. Revisit the Profile when the business, threats, suppliers, or obligations change.
04 · Know the boundary
The frameworks overlap in useful ways, especially for mapping and evidence reuse. They still answer different questions and carry different kinds of authority.
Organizing layer
Prescriptive CUI reference
Contract-driven program
Overlap supports translation, not automatic equivalence.
A CSF Profile can help explain priorities and map evidence toward NIST SP 800-171 or CMMC work. It does not establish CUI protection, satisfy a contract, replace an assessment or attestation, or turn a readiness signal into certification.
05 · Choose the next conversation
Keepgrade’s readiness score is a preparation signal for organizing scope, gaps, and evidence work. It is not a certification or a contract decision.
Start with the framework picker when the requirement is still unclear.
Move from the organizing layer into a CUI protection reference.
Understand scope, practice depth, and formal assessment routes.
Review the paths available for readiness and assessment preparation.
06 · Questions teams ask
Use these answers as a starting point, then confirm the contract, regulatory, or customer requirement that applies to your actual boundary.