CyberFrame supports NIST CSF 2.0 assessments with the complete framework structure, from Govern through Recover. Evaluate categories and subcategories per asset group with structured test methods and produce reports aligned to the NIST framework.
NIST CSF 2.0 Functions
6
Functions
22
Categories
106
Subcategories
The NIST Cybersecurity Framework (CSF) is a set of guidelines published by the National Institute of Standards and Technology (NIST) in the United States. It provides a structured approach to managing cybersecurity risk and is widely adopted by organisations globally, including in Australia by organisations seeking international alignment.
NIST CSF 2.0 is organised around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Each function contains categories (such as Asset Management under Identify) and subcategories that define specific security outcomes. The framework is designed to be flexible, allowing organisations to assess at the depth appropriate to their needs.
A NIST CSF assessment evaluates an organisation's security posture against the framework's categories and subcategories. This involves reviewing current practices, gathering evidence of implementation, identifying gaps, and producing a profile that documents the organisation's current and target security posture.
NIST CSF is framework-agnostic and designed to complement other standards. Organisations often assess against NIST CSF alongside sector-specific requirements. In Australia, it is commonly used by organisations with international operations or those seeking a broadly recognised cybersecurity baseline.
NIST CSF assessments span six functions covering the full breadth of an organisation's security posture. Without a structured platform, assessments become sprawling documents that are hard to maintain, difficult to track, and impossible to compare against future assessments. The framework's flexibility is a strength, but it also means assessors need structure to keep the assessment focused and consistent.
The complete framework with all six functions, categories, and subcategories navigable as a structured hierarchy. Assessors work within the framework's own structure rather than mapping it onto a flat spreadsheet.
Evaluate subcategories per asset group with structured test methods. The evaluation captures implementation status, evidence, and assessor notes at the depth appropriate for the assessment scope.
A structured workflow tailored to NIST CSF methodology with phases, objectives, and activities that guide the assessment from initial scoping through to profile creation and gap identification.
Pre-built test methods guide assessors through the evaluation of each category and subcategory. Assessment techniques are categorised and evidence requirements are clear for each evaluation point.
Report templates aligned to NIST CSF output requirements. Current and target profiles, gap analysis, and findings are structured within the report framework. Data-driven sections auto-populate from evaluation data.
Evidence is linked directly to the functions, categories, and subcategories it supports. Assessors can see which areas have sufficient evidence and which need further collection across all six functions.
See how CyberFrame supports NIST CSF 2.0 assessments with structured methodology, category-level evaluation, and flexible assessment depth.