Voluntary, and built around outcomes rather than controls. CSF says what good looks like across six functions and leaves the how to you - which is why it survives contact with estates its authors never saw, and why a contract naming it binds you to the whole of it, unaltered.
NIST CSF comes with no certificate. It comes with a profile.
CSF is voluntary and has no certificate. What it has is a profile pair, and a gap.
Our promise
“A maturity score is a view. The profile is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditNIST CSF, in three chapters
Version 2.0 added a sixth function, Govern, and it is not a cosmetic one — strategy, roles, policy, oversight and supply chain risk stopped being scattered through the other five and became somewhere you can be seen to have failed. The audience widened well past critical infrastructure too.
Being technology-neutral, the outcomes reach an AI estate unchanged. What the framework will not do is tell you which assets you forgot — and in an AI estate that is most of them, because the models and pipelines arrived as product features rather than as infrastructure anybody inventoried.
A description of outcomes, not a list of controls.
It tells you what good looks like. It will not tell you how to build it.
- Six functions covering the whole security lifecycle
- Outcomes stated plainly, and technology-neutral
- Tiers and profiles, to scope the work deliberately
- A spine the other frameworks hang off cleanly
- No certificate, no accredited body, no seal
- No penalties, unless a contract supplies them
- No control list telling you what to implement
- No inventory of the assets you have forgotten
The outcomes are yours. The deadline is theirs.
The organisation running the estate
CSF is voluntary, which means nobody will make you adopt it and nobody will stop you claiming that you have. The outcomes are yours either way, and so is the inventory underneath them - the framework assumes you already know what you are running before it asks how well you protect it.
The contract that made it binding
A voluntary framework becomes an obligation the moment a customer, a prime contractor or an insurer writes it into their terms. That is how most organisations arrive here, and it quietly changes the question from whether to adopt CSF at all to what evidence the counterparty will accept.
No certificate, from us or anyone
NIST accredits nobody and CSF defines no seal, so any firm offering you certification against it is selling something the framework does not contain. We assess, evidence and rank, and nothing else. A tier we record is a characterisation you chose and can defend, not a mark that we awarded to you.
“We’re NIST CSF compliant.”
There is nothing to be compliant with.
Voluntary means voluntary. A profile is the claim you can make.
- Who it is for
- Federal suppliers
- Critical infrastructure
- Anyone running AI RMF
- Boards wanting one picture
- Multi-framework estates
Govern arrived in 2.0 and most programmes were built before it. A 1.1-era profile is missing a whole function, not a few outcomes.
Contracts now name CSF by version. Answering against 1.1 when the terms say 2.0 is a gap your counterparty finds first, rather than you.
The AI estate reached production faster than any inventory of it did. Identify is where that shows, and on most estates it shows immediately.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your profile check
Four moves, and the first one decides the rest.
Nobody sets these dates for you, which is the difficulty rather than the relief - a voluntary rhythm is one somebody has to keep on purpose.
-
Inventory
Before anythingEvery asset the estate runs, models and pipelines included. Identify comes first here for a reason.
-
Current profile
First passWhat the six functions actually achieve today, with each outcome evidenced rather than merely asserted.
-
Target profile
Then, deliberatelyThe outcomes your risk appetite and your contracts require, with an implementation tier chosen deliberately.
-
Close it
Every day betweenThe gap ranked by consequence. Re-assessment is your choice; the estate changes either way.
Teams reach for the target profile first, because it is the enjoyable half. Built on an estate nobody listed, it describes somebody else’s organisation - and every gap measured against it is measured from a baseline that was never true.
What the framework asks, what we ship
The six functions, and the two devices that apply them. Paired, so every claim can be checked against the ask beside it.
- Govern GV - Strategy, roles, policy, oversight
- AI risk with a named owner, a policy that exists, and a route to the board somebody has actually used.
- Identify ID - Assets, risk assessment, improvement
- The asset inventory: models, training data, endpoints and the suppliers behind each. Most estates are incomplete here.
- Protect PR - Identity, data, platform, training
- Access control over data and artefacts, secure development for ML pipelines, and supplier controls that reach model providers.
- Detect DE - Monitoring and event analysis
- Evidence that something would notice model abuse, exfiltration through outputs, or a poisoned training run.
- Respond RS - Management, analysis, mitigation
- An incident path that covers AI-specific incidents, with a named decision-maker who is reachable out of hours.
- Recover RC - Plan execution and communication
- Rollback to a known-good model version, and a working definition of known-good when the artefact is a set of weights.
- The profile pair How the framework is applied
- A current profile and a target profile, with the distance between them ranked by consequence and costed.
- Cross-framework map One assessment, several asks
- Findings tagged to AI RMF, ISO 27001 and the CIS Controls, so one body of evidence answers more than one question.
The estate, independently read
From one business unit to the whole estate.
-
Inventory
What the estate actually contains, models and pipelines included.
-
Profile
All six functions assessed against outcomes, with evidence rather than opinion.
-
Rank and hand over
You see the draft first. Then the target profile and the costed gap - dated.
Why teams choose iDharma to build the profile
Independent by design
We sell none of the tooling, platforms or controls we assess. Nothing we find is convenient for us.
Evidence, not opinion
Every outcome is either backed by a record or recorded as a gap. There is no third category.
The AI estate included
Models, training sets and inference endpoints assessed as assets, not appended as an annex nobody reads.
Costed, so it survives
The target profile is priced at the start. An uncosted target is where CSF programmes quietly stall.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
NIST CSF assessment report
The full assessment: where the estate stands against all six functions, written function by function, with each gap ranked by consequence rather than by how easy it is to close. Where an outcome is genuinely arguable - and on an outcome-based framework several always are - it says so instead of picking the reading that flatters.
Current profile
What the six functions achieve today, each outcome carrying its record, and the gaps named honestly.
Target profile
The outcomes your risk appetite and your contracts require, sequenced by consequence rather than by ease, and priced so the plan survives a budget.
AI asset inventory
Models, training data, feature stores, inference endpoints and retained prompt logs, each with an owner and a line to the function it serves.
Tier decision memo
Which tier you are working to and why, written down before somebody asks - because a supervisor will ask where you drew the line and on what basis.
Cross-framework map
Every finding tagged to AI RMF, ISO 27001 and the CIS Controls, so one assessment answers the other asks without being run a second time.
Policy and procedure set
The documents the functions expect, under version control and written to your operations rather than lifted from a template library.
Real numbers, upfront.
- Scope
- The estate, AI included
- Output
- A profile pair, not a mark
- Re-review
- Against the target profile - $10,500 measured from your own baseline
Six functions is six functions, so the fee is flat - nothing to meter, and nothing charged until you approve the scope.
Request this assessment- AI asset inventory & dependency map
- Current and target profiles, both dated
- 29 policy and procedure documents
- The gap, ranked and costed
Four things a counterparty will ask you to produce
CSF is not graded at all. Each of these is either in your hand on the day somebody asks, or it is not.
The estate,
listed
An inventory that reaches the models, the training data and the endpoints. Every later function is assessed against this list, so an incomplete one shortens them all.
The profile,
dated
What the six functions achieve today, with a record behind each outcome. Undated, it is an opinion; dated, it is the baseline every later comparison runs against.
The tier,
chosen
Which tier you are working to, and the reasoning. Choosing Tier 2 deliberately and writing down why is a stronger position than claiming Tier 3 with nothing behind it.
The gap,
costed
The distance between the two profiles, ranked by consequence rather than by ease, and carrying a price. It is the part a board can actually fund, and the part it will.
Four cards, and the date on each one is part of the card.
Plain answers
Mandatory, certification, 2.0, profiles, AI. Answered straight.
Request this assessmentIs NIST CSF mandatory?
No. It is voluntary and carries no penalties of its own. It becomes binding where a contract names it, which happens often enough in federal and critical-infrastructure supply chains that many organisations treat it as required.
What is the difference between a current and a target profile?
The current profile records the outcomes you achieve today, with evidence. The target profile records the outcomes you need. The distance between them, ranked by consequence and costed, is the programme - and it is what a board will actually fund.
What are the four Implementation Tiers?
Partial, Risk Informed, Repeatable and Adaptive. They characterise how rigorous your risk governance is - not how good your security is. The framework is deliberate that they are neither a maturity model nor a grade.
Does NIST CSF cover AI risk?
It covers securing the systems AI runs in, which is a large part of the problem but not all of it. Risks the model itself creates sit with NIST AI RMF. Running both is the complete answer, and they were designed to compose.
What does an iDharma CSF assessment cover, and what comes with it?
A flat fee, stated in full on this page, with nothing charged until you approve the scope. It covers the asset inventory, both profiles, the ranked gap, the cross-framework map and the policy suite the assessment writes against.
Request your CSF assessment
Tell us what the estate runs and we come back with a scoping call inside a day.
What we need from you
Nothing you do not already have. Most of it comes out of your asset register and the last security review, in an afternoon, and we tell you which extracts first.
- What the estate runs, models and pipelines included
- Which contract named CSF, and at which version
- Any existing profile or assessment, however partial
- Your most recent risk assessment output
- Who owns AI risk today, if anybody does
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- The NIST Cybersecurity Framework 2.0, published by NIST
- Its Implementation Tier and Profile guidance
- Current version
- CSF 2.0
- Enforced by
- Contract only
What it means
- General information about what the framework describes — not legal advice, and not a determination about your programme.
- Where an outcome is genuinely arguable, and on an outcome-based framework several always are, our reports say so rather than pick the flattering reading.
Scope & limitation
- No category or subcategory count appears on this page. The six functions and the four tiers are printed because they are certain; the totals beneath them are not checked here, and an unchecked count on an indexed page is a published claim. Read them from the framework itself.
- There is no certificate, from iDharma or anyone. NIST accredits no bodies and CSF defines no seal. We assess, evidence and rank.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom