By David Chernitzky, Co-Founder and CEO, Armour Cybersecurity | Serving organizations across Canada, the US, and beyond | Last updated August 18, 2026
Quick answer: The NIST Cybersecurity Framework is a structured model for describing, evaluating, and improving an organization’s security program. It organizes security capability into the core functions Identify, Protect, Detect, Respond, and Recover, joined by Govern in the current version 2.0, and measures how completely and consistently each is implemented through a four-tier maturity model. It is the most widely adopted security framework in North America and the common language through which boards, auditors, regulators, and insurers evaluate whether a security program is adequate.
Key Takeaways
- The NIST CSF five core functions, Identify, Protect, Detect, Respond, and Recover, cover the complete lifecycle of cyber risk management. A program that is strong in protection but weak in detection and response is only partially effective, and the NIST CSF structure makes this imbalance visible in a way that a tool inventory does not.
- The four implementation tiers measure not just whether controls exist but whether they are consistently applied, whether they are informed by risk analysis, whether the organization actively shares information about threats with others, and whether the program continuously improves based on performance data.
- NIST CSF maps to ISO 27001, CIS Controls v8, and COBIT 2019, so a NIST CSF-based assessment simultaneously produces findings relevant to multiple compliance frameworks, which is more efficient than assessing each framework separately.
- A NIST CSF maturity scorecard creates a common vocabulary between the security team and leadership. It translates the technical complexity of the security program into a structured visual format that executives and board members can evaluate without requiring technical expertise.
- The NIST CSF was updated to version 2.0 in 2024, adding Govern as a sixth function that explicitly addresses cybersecurity governance, risk management strategy, and supply chain risk at the organizational level.
What the NIST Cybersecurity Framework Is
The National Institute of Standards and Technology published the first version of its Cybersecurity Framework in 2014 in response to an executive order directing the development of a voluntary framework for improving critical infrastructure cybersecurity. It has since been adopted far beyond its original infrastructure focus, becoming the most widely used security program evaluation standard in North America across private sector organizations of all sizes and sectors. Version 2.0, released in February 2024, expanded the framework to include an explicit governance function and broadened its applicability beyond critical infrastructure to all organizations managing cyber risk.
The framework is structured around three components. The Core is the set of cybersecurity activities and outcomes organized into functions, categories, and subcategories. The Tiers describe the degree to which the organization’s cybersecurity risk management practices exhibit the characteristics defined in the framework. The Profile represents the organization’s current or target cybersecurity outcomes, used as the basis for identifying and prioritizing opportunities for improvement. For the purposes of a cybersecurity posture assessment, the Core and Tiers are the primary reference points.
The Five (Now Six) Core Functions
Identify
The Identify function establishes the organizational understanding of cybersecurity risk needed to manage it effectively. It covers asset management, the inventory and understanding of all physical and digital assets and the data they contain; business environment, the organization’s mission, stakeholders, and risk tolerance; governance, the policies and procedures that define the organization’s approach to managing cybersecurity risk; risk assessment, the process for identifying and prioritizing risks; and risk management strategy, the constraints and priorities that guide risk treatment decisions. Without strong Identify capability, the organization cannot know what it needs to protect or what the most important threats to it are.
Protect
The Protect function covers the safeguards that limit the impact of a cybersecurity event: access control, including identity management and multi-factor authentication; awareness and training programs for employees; data security, including encryption, classification, and handling procedures; information protection processes and procedures; maintenance of information systems and industrial control systems; and protective technology including endpoint protection, firewall configuration, and network security controls. The Protect function represents the controls that prevent attackers from achieving their objectives and is typically the most developed function in organizations that have been spending on security for some time.
Detect
The Detect function covers the capabilities that enable timely discovery of cybersecurity events: anomaly and event detection, the monitoring that identifies when something unusual is happening; security continuous monitoring, the ongoing assessment of information systems to identify vulnerabilities and breaches; and detection processes, the procedures that define how detection activities are maintained and tested. Detection capability is frequently underdeveloped relative to protection in organizations that have not conducted a systematic maturity assessment. Organizations can have strong perimeter controls and still have attackers present for weeks or months before detection, because the detection infrastructure was not built or tested to the same standard as the protection controls.
Respond
The Respond function covers the activities that contain the impact of a detected cybersecurity event: response planning, the incident response plan and its maintenance; communications, the protocols for internal and external communication during and after an incident; analysis, the processes for understanding the event, its scope, and its impact; mitigation, the actions taken to prevent expansion of the event and resolve it; and improvements, the lessons learned processes that update the plan based on actual incident experience. Response capability is directly relevant to the financial impact of an incident: organizations with mature breach response capability contain events faster, which reduces total loss and affects both insurance claims and the board’s ability to demonstrate governance during a crisis.
Recover
The Recover function covers the activities that restore normal capabilities after a cybersecurity incident: recovery planning, the documented procedures for restoring systems and services; improvements, the process for incorporating lessons learned into recovery planning; and communications, the procedures for managing stakeholder relationships during recovery. Recover capability is the determinant of how quickly normal operations resume after an incident and is directly connected to the business interruption cost, which is often the largest component of a cyber insurance claim.
Govern (added in version 2.0)
The Govern function, added in version 2.0, covers the organizational context, strategy, and oversight activities that inform and support the other five functions: organizational context, including the mission and stakeholder expectations that shape cybersecurity objectives; risk management strategy, including the risk appetite and tolerance that guide risk treatment decisions; cybersecurity supply chain risk management, the discipline covered in depth by a supplier risk management program; roles, responsibilities, and authorities for cybersecurity across the organization; policies, processes, and procedures; and oversight mechanisms that ensure accountability. The addition of Govern as an explicit function reflects the recognition that board-level governance of cybersecurity is now a foundational expectation, not an optional governance enhancement.
How the Four Implementation Tiers Work
The NIST CSF implementation tiers are the basis for NIST CSF maturity scoring: they measure how completely and systematically the organization’s cybersecurity practices are implemented, ranging from Tier 1 (Partial) through Tier 4 (Adaptive). The tiers describe increasing rigor in how risk-informed, repeatable, and integrated with the broader organizational risk management function the security practices are.
At Tier 1, cybersecurity risk management practices are informal, reactive, and not consistently applied. Risk is managed on an ad hoc basis, with limited awareness of cybersecurity risk at the organizational level. At Tier 2, risk management practices are approved by management but not established as organization-wide policy. There is awareness of cybersecurity risk but no consistent organization-wide approach. At Tier 3, the organization’s risk management practices are formally approved and expressed as policy. The organization regularly updates its cybersecurity practices based on the application of risk management processes to changes in business requirements and the threat and technology landscape. At Tier 4, the organization adapts its cybersecurity practices in real time based on current and previous cybersecurity activities, including lessons learned and predictive indicators derived from previous and current cybersecurity activities.
Most mid-market organizations conducting their first independent posture assessment find themselves at Tier 1 or Tier 2 across most functions. The roadmap produced by the assessment identifies the specific actions that would move the organization to Tier 3 across the priority functions, which is the target state that most boards, regulators, and insurers consider adequate for ongoing governance. To see how NIST CSF maturity scoring works in the context of a full cyber posture assessment, and how the tier picture supports a security program maturity assessment over time, the Core and Tiers are the reference points the engagement is built on.
How NIST CSF Maps to Other Frameworks
One of the most practical advantages of the NIST CSF as the primary cybersecurity framework assessment standard is its explicit mapping to other widely used standards. ISO 27001 controls map to NIST CSF categories and subcategories, so an assessment conducted against NIST CSF simultaneously produces findings relevant to ISO 27001 certification readiness. CIS Controls v8, which provides more prescriptive implementation guidance than the NIST CSF, maps to NIST CSF categories in a way that allows the assessment to produce CIS Controls gap findings alongside the NIST CSF maturity scoring. COBIT 2019 governance and management objectives map to NIST CSF functions in a way that connects the technical security assessment to the governance framework that board advisors and audit committees use.
This cross-framework mapping is the basis for the efficiency claim that a NIST CSF posture assessment produces findings relevant to multiple compliance frameworks. An organization subject to PIPEDA, with customers who require SOC 2 documentation, and with a board that follows recognized cyber governance guidance, can address all three reference frameworks in a single NIST CSF posture assessment rather than conducting three separate compliance-specific assessments. The findings are mapped to each applicable framework as part of the assessment output, so the same engagement simultaneously advances compliance readiness, board governance reporting, and operational security improvement. When the assessment doubles as preparation for an insurance renewal, the same NIST CSF evidence supports a stronger position, as covered in how a cyber posture assessment lowers your insurance premium.
Frequently Asked Questions
Do we need to reach a specific NIST CSF tier to satisfy regulators or customers?
The NIST CSF does not define a mandatory compliance tier; it is a voluntary framework. What regulators and customers typically evaluate is whether the organization can demonstrate systematic, risk-informed security practices rather than a specific tier score. That said, the practical standard for most enterprise customer procurement requirements, cyber insurance underwriting expectations, and board governance purposes is Tier 3: practices are formally approved, documented as policy, and consistently applied. Organizations that can demonstrate Tier 3 across their priority functions typically satisfy the expectations of regulators, customers, and insurers across most sectors. Organizations in critical infrastructure or highly regulated sectors may face higher expectations in specific domains.
Is the NIST CSF 2.0 update a significant change from version 1.1?
The core five-function structure is preserved in version 2.0, so organizations that have been working against version 1.1 do not face a wholesale program redesign. The most significant additions are the Govern function, which formalizes board and organizational governance requirements that were implicit in version 1.1, and expanded guidance on supply chain cybersecurity risk management. The framework also includes more explicit guidance on using the Profile and Tier concepts to set and measure progress toward target states. For organizations conducting their first posture assessment, version 2.0 is the current reference and assessments should be conducted against it.
How long does it take to move from Tier 1 to Tier 3?
Moving from Tier 1 to Tier 3 across priority functions typically takes twelve to thirty-six months depending on organizational size, budget, and the specific domains involved. Quick wins that eliminate the most glaring gaps can be executed in the first ninety days. The process and governance changes that move practices from informal to formally approved and documented typically take six to twelve months because they require policy development, training, and behavioral change across the organization. The technology investments that support consistent control implementation at Tier 3 are typically sequenced in year one and year two of a remediation roadmap. The KPI framework in a posture assessment provides the measurement structure to track progress toward Tier 3 on a quarterly basis.
What is the difference between a NIST CSF current profile and a target profile?
The NIST CSF current profile describes the cybersecurity outcomes the organization is achieving today across the framework categories. The target profile describes the outcomes the organization aims to achieve based on its business requirements, risk tolerance, and regulatory obligations. The gap between current and target profiles is the structured input to the remediation roadmap. Rather than treating all gaps equally, the profile comparison identifies which categories are most important for the organization to advance based on its specific context. An organization in healthcare with significant patient data obligations prioritizes different target profile outcomes than a manufacturing company with operational technology exposure, even if both are assessed against the same NIST CSF structure.
Can a small business meaningfully use the NIST Cybersecurity Framework?
Yes. The NIST CSF is explicitly designed to be applicable at any organizational scale, and NIST has published implementation guidance specifically for small and medium-sized businesses. The framework does not prescribe specific technologies or control implementations; it describes outcomes, which means a small business can achieve Tier 2 or Tier 3 outcomes in priority functions using simple, affordable tools and process disciplines rather than enterprise-grade technology. A posture assessment conducted against the NIST CSF for a small business is scoped to the domains and control complexity appropriate for the organization’s size and risk profile, not modeled on the assessment of a large enterprise.
The Bottom Line
The NIST Cybersecurity Framework matters to a business because it turns “are we secure enough?” into a question you can actually answer. It names the functions that make up a complete program, Identify, Protect, Detect, Respond, Recover, and now Govern, and it measures how consistently each is implemented on a four-tier scale that boards, auditors, regulators, and insurers all recognize. Scoring your program against it shows exactly where the imbalances are, usually strong protection and weak detection and response, and gives you a shared language for the improvement plan. A cyber posture assessment built on the NIST CSF produces that scorecard, maps it to the other frameworks you answer to, and turns it into a prioritized roadmap toward the Tier 3 most organizations are expected to reach.
About the author
David Chernitzky is Co-Founder and CEO of Armour Cybersecurity, a Toronto-based cybersecurity firm founded by military intelligence veterans and advised by senior leaders from PwC, KPMG, Deloitte, EY, and Mandiant. Armour serves more than 260 organizations across 52-plus industries, including finance, healthcare, technology, energy, legal, and government, with a 97 percent client retention rate.



