Stefan Coetzeecreated 2026-05-12updated 2026-05-121 min readposition
Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.
What it does well
Function structure intuitive. Govern / Identify / Protect / Detect / Respond / Recover maps to operational reality.
Outcome-oriented. Subcategories are outcomes, not prescribed activities.
Free, accessible. No cost; documents free.
Adopted globally beyond US. ISO 27002:2022 attribute axis includes CSF function mapping.
Cross-framework references to NIST 800-53, ISO 27001, CIS, ATT&CK.
Sector profiles support sector-specific implementations.
Implementation examples in 2.0 provide concrete guidance.
Govern function in 2.0 elevates governance.
What it does poorly
Not certifiable. Self-claim only; no third-party attestation.
US-origin framing in places.
Tier structure ambiguous. Often misused as maturity model.
Implementation depth varies. Two orgs both "CSF-aligned" can have very different rigor.
Profile development cost. Substantive Current / Target Profile work is non-trivial.
No formal Statement of Applicability equivalent.
Evidence
Widely adopted by US federal contractors, state government, US enterprises, increasingly internationally.
Combined with ISO 27001 in many SaaS organizations.
State privacy laws (Colorado AI Act, others) reference NIST CSF.
Sector profiles published for multiple sectors.
Personal calibration
For US-customer-facing work: NIST CSF fluency expected.
For framework communication: function vocabulary useful bridge between technical and non-technical stakeholders.
For procurement evidence: NIST CSF alignment statement supplements ISO 27001 / SOC 2.