Cyber framework · Global (US-origin)NIST CSF
A voluntary framework that organises cybersecurity outcomes into six functions, from governance through to recovery, for any organisation to profile against.
- 1Govern
- 2Identify
- 3Protect
- 4Detect
- 5Respond
- 6Recover
Why it matters
The common language for cyber risk, widely used to set a target profile, communicate to the board and align other frameworks.
Who it's for
Any organisation, of any size, that wants a structured, outcome-based way to manage and communicate cyber risk.
How you get to NIST CSF
- 1Create profileScope outcomes
- 2Assess currentWhere you are
- 3Set targetWhere you want to be
- 4Prioritise gapsBy risk
- 5ImplementClose the gaps
- 6MeasureImprove over time
NIST CSF, worked in the platform
Get the evidence you need
The AI recommends which evidence answers each NIST CSF control, ready to confirm.
See what's missing
Gaps and missing artifacts surface on their own, not the week of the audit.
Create from templates
Spin up policies, assessments and charters from standard templates, then tailor them to your scope.
Collected once, reused
One artifact satisfies this framework and every other it maps to.
Get NIST CSF-ready on your own stack.
Demos are scoped to your frameworks. Pick a slot and we'll run NIST CSF live.