NIST
NIST Cybersecurity Framework 2.0 services for UK organisations. Maturity assessment, a funded roadmap and control evidence mapped to ISO 27001.
Service Details
The NIST Cybersecurity Framework (CSF) 2.0 gives you a shared way to measure and improve your cyber security, and Falx gives you an honest maturity score, a roadmap your board can fund and the evidence to show progress. The framework comes from the US National Institute of Standards and Technology and is built around six functions: Govern, Identify, Protect, Detect, Respond and Recover.
There is no NIST certificate to chase. The value is a common language for risk that your engineers, your board and your customers all understand. This work sits within our governance services, alongside the certifiable standards it maps to.
INFO
NIST CSF is voluntary and has no certification. If a client asks for “NIST compliance”, they usually want to see a current maturity profile and a plan to close the gaps.
Who NIST CSF applies to
No UK regulation requires NIST CSF, so the question is whether it is useful to you. UK organisations tend to adopt it when:
- US clients or partners ask for it — Security questionnaires from US firms often reference CSF functions directly.
- US investors or a US parent company expect it — Private equity owners and group security teams use it to compare portfolio companies on one scale.
- You want a maturity model — CSF shows where you are today, where you need to be and how far you moved this year, which a pass-or-fail certificate does not.
Version 2.0, published in February 2024, widened the framework from critical infrastructure to organisations of every size and sector.
What the framework asks of you
CSF 2.0 describes outcomes, not specific products or settings. You decide how to meet each one, based on your risk.
The six functions of CSF 2.0
Each function breaks down into categories and subcategories you score yourself against:
Govern
Who owns cyber risk, what your strategy and policies are, and how you manage risk from suppliers.
Identify
Knowing your assets, data and risks, so you protect what matters most first.
Protect
Access control, training, data security and network segmentation that keep attacks from spreading.
Detect
Monitoring that spots unusual activity and confirms whether it is an incident.
Respond
A tested plan for containing an incident, communicating about it and analysing what happened.
Recover
Restoring systems and services in priority order, and learning from the incident.
In practice, you record a current profile (how you perform today) and a target profile (where you need to be). The gap between the two becomes your improvement plan.
How Falx helps you adopt NIST CSF
We work with your team across all six functions, drawing on more than a decade of industry experience. You get a clear score, a plan and the engineering to deliver it.
- Maturity assessment — We review your operations against each CSF category and subcategory, scoring current against target maturity.
- Strategic roadmap — We turn findings into a phased roadmap your board can fund and your engineers can deliver, with quick wins first.
- Remediation — We deliver hands-on engineering across network security, access management and monitoring to close the gaps the assessment finds.
- Ongoing gap analysis — We re-assess on a schedule that suits you, keeping your profile current as threats and business priorities change.
What you get at the end
A maturity profile you can hand to a client, investor or board, backed by evidence rather than self-assessment alone.
Profiles
Current and target maturity scored across all six functions
Roadmap
Phased improvements prioritised by risk and budget
Control map
One map linking CSF to ISO 27001 and Cyber Essentials
One programme, several frameworks
One framework rarely satisfies every stakeholder. Because CSF describes outcomes, it works well as the umbrella over certifiable standards. We map it to ISO 27001 and Cyber Essentials so you implement controls once and reuse the evidence. For control-level hardening underneath the framework, see our CIS Controls service.
If you are regulated in the UK or EU, CSF can sit alongside NIS2, DORA, FCA requirements, UK GDPR and PCI DSS. Comparing regimes? See how NIST stacks up against NIS2, CIS and DORA in our framework comparison, or read about our wider compliance programme.
Services that work alongside
A NIST assessment often leads into related work. Risk management feeds the Govern and Identify functions, and security posture reviews and penetration testing test whether Protect and Detect hold up. Identity and access closes common Protect gaps, and compliance support packages the evidence for clients and auditors.
NIST CSF is most relevant to financial services, insurance and private equity firms with US connections, and to manufacturing businesses that supply US customers.
Frequently asked questions
Find out where you sit on NIST CSF 2.0
Tell us who is asking about NIST and what you already have in place. You get a view of your current maturity, your likely gaps and the controls you can reuse from ISO 27001 or Cyber Essentials.