NIST CSF position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

What it does well

  • Function structure intuitive. Govern / Identify / Protect / Detect / Respond / Recover maps to operational reality.
  • Outcome-oriented. Subcategories are outcomes, not prescribed activities.
  • Free, accessible. No cost; documents free.
  • Adopted globally beyond US. ISO 27002:2022 attribute axis includes CSF function mapping.
  • Cross-framework references to NIST 800-53, ISO 27001, CIS, ATT&CK.
  • Sector profiles support sector-specific implementations.
  • Implementation examples in 2.0 provide concrete guidance.
  • Govern function in 2.0 elevates governance.

What it does poorly

  • Not certifiable. Self-claim only; no third-party attestation.
  • US-origin framing in places.
  • Tier structure ambiguous. Often misused as maturity model.
  • Implementation depth varies. Two orgs both "CSF-aligned" can have very different rigor.
  • Profile development cost. Substantive Current / Target Profile work is non-trivial.
  • No formal Statement of Applicability equivalent.

Evidence

  • Widely adopted by US federal contractors, state government, US enterprises, increasingly internationally.
  • Combined with ISO 27001 in many SaaS organizations.
  • State privacy laws (Colorado AI Act, others) reference NIST CSF.
  • Sector profiles published for multiple sectors.

Personal calibration

  • For US-customer-facing work: NIST CSF fluency expected.
  • For framework communication: function vocabulary useful bridge between technical and non-technical stakeholders.
  • For procurement evidence: NIST CSF alignment statement supplements ISO 27001 / SOC 2.

See also