NIST CSF 2.0 · SIX FUNCTIONS · PROFILES

NIST CSF comes with no certificate. It comes with a profile.

CSF is voluntary and has no certificate. What it has is a profile pair, and a gap.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Outcome-based, which is why it stretches
Govern Identify Protect Detect Respond Recover

Our promise

“A maturity score is a view. The profile is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

NIST CSF, in three chapters

The Framework

Voluntary, and built around outcomes rather than controls. CSF says what good looks like across six functions and leaves the how to you - which is why it survives contact with estates its authors never saw, and why a contract naming it binds you to the whole of it, unaltered.

The Change

Version 2.0 added a sixth function, Govern, and it is not a cosmetic one — strategy, roles, policy, oversight and supply chain risk stopped being scattered through the other five and became somewhere you can be seen to have failed. The audience widened well past critical infrastructure too.

The Estate

Being technology-neutral, the outcomes reach an AI estate unchanged. What the framework will not do is tell you which assets you forgot — and in an AI estate that is most of them, because the models and pipelines arrived as product features rather than as infrastructure anybody inventoried.

What CSF is

A description of outcomes, not a list of controls.

It tells you what good looks like. It will not tell you how to build it.

What it gives you № 01
  • Six functions covering the whole security lifecycle
  • Outcomes stated plainly, and technology-neutral
  • Tiers and profiles, to scope the work deliberately
  • A spine the other frameworks hang off cleanly
NIST CSF 2.0 · iDharma · Presented for review
What it does not № 02
  • No certificate, no accredited body, no seal
  • No penalties, unless a contract supplies them
  • No control list telling you what to implement
  • No inventory of the assets you have forgotten
NIST CSF 2.0 · iDharma · Presented for review
Whose job is which

The outcomes are yours. The deadline is theirs.

You

The organisation running the estate

CSF is voluntary, which means nobody will make you adopt it and nobody will stop you claiming that you have. The outcomes are yours either way, and so is the inventory underneath them - the framework assumes you already know what you are running before it asks how well you protect it.

Whoever names it

The contract that made it binding

A voluntary framework becomes an obligation the moment a customer, a prime contractor or an insurer writes it into their terms. That is how most organisations arrive here, and it quietly changes the question from whether to adopt CSF at all to what evidence the counterparty will accept.

The line

No certificate, from us or anyone

NIST accredits nobody and CSF defines no seal, so any firm offering you certification against it is selling something the framework does not contain. We assess, evidence and rank, and nothing else. A tier we record is a characterisation you chose and can defend, not a mark that we awarded to you.

What most teams assume

“We’re NIST CSF compliant.”

What the framework says

There is nothing to be compliant with.

Voluntary means voluntary. A profile is the claim you can make.

  • Who it is for
  • Federal suppliers
  • Critical infrastructure
  • Anyone running AI RMF
  • Boards wanting one picture
  • Multi-framework estates
Why this matters in 2026
A black archive binder on a dark desk beside a clipped stack of printed reports, with a small printed card in front of it reading EVIDENCE OVER PROMISES above a pair of scales.
01 Nobody enforces CSF, so nothing forces the question until a customer asks it — and by then the answer they want is a profile with evidence behind it, not an intention.
02

Govern arrived in 2.0 and most programmes were built before it. A 1.1-era profile is missing a whole function, not a few outcomes.

03

Contracts now name CSF by version. Answering against 1.1 when the terms say 2.0 is a gap your counterparty finds first, rather than you.

04

The AI estate reached production faster than any inventory of it did. Identify is where that shows, and on most estates it shows immediately.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

Current profile -

A profile is evidenced, or it is an opinion. The framework asks what outcomes you are achieving, not what controls you own. A control list is a useful input and is not a profile.

Target profile -

The gap is the deliverable. A current profile alone is a report and a target alone is an aspiration. An uncosted target is where CSF programmes quietly stall, so the price is part of the artefact.

Framework version -

2.0 added a whole function. Govern is not a handful of new outcomes bolted onto the old five — a profile built against 1.1 is missing a function, and contracts increasingly name the version.

The calendar

Four moves, and the first one decides the rest.

Nobody sets these dates for you, which is the difficulty rather than the relief - a voluntary rhythm is one somebody has to keep on purpose.

  1. Inventory

    Before anything

    Every asset the estate runs, models and pipelines included. Identify comes first here for a reason.

  2. Current profile

    First pass

    What the six functions actually achieve today, with each outcome evidenced rather than merely asserted.

  3. Target profile

    Then, deliberately

    The outcomes your risk appetite and your contracts require, with an implementation tier chosen deliberately.

  4. Close it

    Every day between

    The gap ranked by consequence. Re-assessment is your choice; the estate changes either way.

The trap

Teams reach for the target profile first, because it is the enjoyable half. Built on an estate nobody listed, it describes somebody else’s organisation - and every gap measured against it is measured from a baseline that was never true.

Function & artefact

What the framework asks, what we ship

The six functions, and the two devices that apply them. Paired, so every claim can be checked against the ask beside it.

Govern GV - Strategy, roles, policy, oversight
AI risk with a named owner, a policy that exists, and a route to the board somebody has actually used.
Identify ID - Assets, risk assessment, improvement
The asset inventory: models, training data, endpoints and the suppliers behind each. Most estates are incomplete here.
Protect PR - Identity, data, platform, training
Access control over data and artefacts, secure development for ML pipelines, and supplier controls that reach model providers.
Detect DE - Monitoring and event analysis
Evidence that something would notice model abuse, exfiltration through outputs, or a poisoned training run.
Respond RS - Management, analysis, mitigation
An incident path that covers AI-specific incidents, with a named decision-maker who is reachable out of hours.
Recover RC - Plan execution and communication
Rollback to a known-good model version, and a working definition of known-good when the artefact is a set of weights.
The profile pair How the framework is applied
A current profile and a target profile, with the distance between them ranked by consequence and costed.
Cross-framework map One assessment, several asks
Findings tagged to AI RMF, ISO 27001 and the CIS Controls, so one body of evidence answers more than one question.
The engagement

The estate, independently read

From one business unit to the whole estate.

  1. Inventory

    What the estate actually contains, models and pipelines included.

  2. Profile

    All six functions assessed against outcomes, with evidence rather than opinion.

  3. Rank and hand over

    You see the draft first. Then the target profile and the costed gap - dated.

Request an assessment
An auditor in a charcoal suit and open-collared white shirt, with dark curly hair, standing against a warm pale wall and pointing into the open space alongside.
The baseline, settled before anyone plans against it.
Struck in your favour

Why teams choose iDharma to build the profile

Independent by design

We sell none of the tooling, platforms or controls we assess. Nothing we find is convenient for us.

Evidence, not opinion

Every outcome is either backed by a record or recorded as a gap. There is no third category.

The AI estate included

Models, training sets and inference endpoints assessed as assets, not appended as an annex nobody reads.

Costed, so it survives

The target profile is priced at the start. An uncosted target is where CSF programmes quietly stall.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

NIST CSF assessment report

The full assessment: where the estate stands against all six functions, written function by function, with each gap ranked by consequence rather than by how easy it is to close. Where an outcome is genuinely arguable - and on an outcome-based framework several always are - it says so instead of picking the reading that flatters.

Assessed

Current profile

What the six functions achieve today, each outcome carrying its record, and the gaps named honestly.

Costed

Target profile

The outcomes your risk appetite and your contracts require, sequenced by consequence rather than by ease, and priced so the plan survives a budget.

Data map

AI asset inventory

Models, training data, feature stores, inference endpoints and retained prompt logs, each with an owner and a line to the function it serves.

Recorded

Tier decision memo

Which tier you are working to and why, written down before somebody asks - because a supervisor will ask where you drew the line and on what basis.

Tagged

Cross-framework map

Every finding tagged to AI RMF, ISO 27001 and the CIS Controls, so one assessment answers the other asks without being run a second time.

Repository

Policy and procedure set

The documents the functions expect, under version control and written to your operations rather than lifted from a template library.

Format & fee

Real numbers, upfront.

Scope
The estate, AI included
Output
A profile pair, not a mark
Re-review
Against the target profile - $10,500 measured from your own baseline

Six functions is six functions, so the fee is flat - nothing to meter, and nothing charged until you approve the scope.

Request this assessment
NIST CSF 2.0 · Profile assessment $12,500 flat
  • AI asset inventory & dependency map
  • Current and target profiles, both dated
  • 29 policy and procedure documents
  • The gap, ranked and costed
Show your hand

Four things a counterparty will ask you to produce

CSF is not graded at all. Each of these is either in your hand on the day somebody asks, or it is not.

The estate,
listed

An inventory that reaches the models, the training data and the endpoints. Every later function is assessed against this list, so an incomplete one shortens them all.

The profile,
dated

What the six functions achieve today, with a record behind each outcome. Undated, it is an opinion; dated, it is the baseline every later comparison runs against.

The tier,
chosen

Which tier you are working to, and the reasoning. Choosing Tier 2 deliberately and writing down why is a stronger position than claiming Tier 3 with nothing behind it.

The gap,
costed

The distance between the two profiles, ranked by consequence rather than by ease, and carrying a price. It is the part a board can actually fund, and the part it will.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Mandatory, certification, 2.0, profiles, AI. Answered straight.

Request this assessment
Is NIST CSF mandatory?

No. It is voluntary and carries no penalties of its own. It becomes binding where a contract names it, which happens often enough in federal and critical-infrastructure supply chains that many organisations treat it as required.

What is the difference between a current and a target profile?

The current profile records the outcomes you achieve today, with evidence. The target profile records the outcomes you need. The distance between them, ranked by consequence and costed, is the programme - and it is what a board will actually fund.

What are the four Implementation Tiers?

Partial, Risk Informed, Repeatable and Adaptive. They characterise how rigorous your risk governance is - not how good your security is. The framework is deliberate that they are neither a maturity model nor a grade.

Does NIST CSF cover AI risk?

It covers securing the systems AI runs in, which is a large part of the problem but not all of it. Risks the model itself creates sit with NIST AI RMF. Running both is the complete answer, and they were designed to compose.

What does an iDharma CSF assessment cover, and what comes with it?

A flat fee, stated in full on this page, with nothing charged until you approve the scope. It covers the asset inventory, both profiles, the ranked gap, the cross-framework map and the policy suite the assessment writes against.

Get started

Request your CSF assessment

Tell us what the estate runs and we come back with a scoping call inside a day.

What we need from you

Nothing you do not already have. Most of it comes out of your asset register and the last security review, in an afternoon, and we tell you which extracts first.

  1. What the estate runs, models and pipelines included
  2. Which contract named CSF, and at which version
  3. Any existing profile or assessment, however partial
  4. Your most recent risk assessment output
  5. Who owns AI risk today, if anybody does

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request an assessment
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • The NIST Cybersecurity Framework 2.0, published by NIST
  • Its Implementation Tier and Profile guidance
Current version
CSF 2.0
Enforced by
Contract only

What it means

  • General information about what the framework describes — not legal advice, and not a determination about your programme.
  • Where an outcome is genuinely arguable, and on an outcome-based framework several always are, our reports say so rather than pick the flattering reading.

Scope & limitation

  • No category or subcategory count appears on this page. The six functions and the four tiers are printed because they are certain; the totals beneath them are not checked here, and an unchecked count on an indexed page is a published claim. Read them from the framework itself.
  • There is no certificate, from iDharma or anyone. NIST accredits no bodies and CSF defines no seal. We assess, evidence and rank.

Something on this page out of date?

Tell us