Cyber risk management
Use a common language to govern cybersecurity risk.
The NIST Cybersecurity Framework 2.0 gives organizations a flexible way to understand, assess, prioritize, and communicate cybersecurity outcomes. We help develop current and target profiles, connect them to business risk, and turn the gaps into an owned roadmap.
Our implementation focus
Make the requirements operational.
- 01
Define the organizational context and risk priorities
- 02
Assess current outcomes across the six CSF functions
- 03
Create a target profile aligned to business goals
- 04
Prioritize improvement initiatives and ownership
- 05
Establish measures for review and communication
NIST CSF 2.0 is voluntary guidance, not an independent certification scheme.
Questions we hear
Get the distinctions right.
Can an organization be certified to NIST CSF 2.0?
NIST CSF 2.0 is a voluntary framework for managing cybersecurity risk; NIST does not issue a CSF certification. Treat third-party assessments as their own scoped services.
What changed with the Govern function?
Govern makes strategy, policies, roles, oversight, and supply-chain decisions explicit in the framework. It helps leadership connect cybersecurity outcomes to enterprise risk.
How does NIST CSF differ from NIS2?
CSF 2.0 is a risk-management framework that can be used across jurisdictions. NIS2 is an EU directive whose requirements are implemented through national law for covered entities.
Work with Normstone
Build a defensible path to readiness.
Tell us the outcome you need and the markets involved. We’ll help define the work.