Skip to main content
NIST CSF 2.0 · Six functions · CERT-In empanelled since 2008

The NIST Cybersecurity Framework,
assessed against what you actually do.

A Current Profile, a Target Profile, an implementation Tier and a prioritised gap analysis across all six CSF 2.0 functions — evidenced by technical testing, not by a policy review. If you are SEBI-regulated, most of the evidence already exists under headings you will recognise.

First, the thing nobody selling this says

There is no NIST certification.

NIST does not certify organisations against the Cybersecurity Framework. It does not accredit certification bodies for it, and it issues no certificate. The framework is voluntary guidance, and that is by design.

Anything marketed as "NIST CSF certification" is a private firm attesting to its own assessment. That can be genuinely useful — an independent read on your posture usually is — but it is not a certification in the sense ISO 27001 is, and presenting it as one to a customer, an underwriter or an auditor will not survive the first informed question.

What you can legitimately hold, and what this assessment produces, is a defensible profile: where you are, where your risk appetite and obligations say you should be, and what closing the distance costs.

CSF 2.0

Six functions, and where your CSCRF work already lands.

The right-hand column is not an analogy. Those are the control identifiers SEBI uses in the CSCRF master circular — the CSF function and category codes, used as CSCRF's own. An entity that has done real CSCRF work has already produced much of what a CSF assessment asks for, filed under the same headings.

GV

Govern

Added in CSF 2.0 and the reason most existing assessments are out of date. Covers organisational context, risk management strategy, roles and responsibilities, policy, oversight, and — the part that catches people — cybersecurity supply chain risk management.

Appears in SEBI CSCRF as  GV.OC · GV.OV · GV.PO · GV.RM · GV.RR · GV.SC

ID

Identify

Asset management, risk assessment, and improvement. You cannot protect an inventory you do not have, and this is the function where most assessments find the largest gap between the documented estate and the real one.

Appears in SEBI CSCRF as  ID.AM · ID.RA

PR

Protect

Identity management and access control, awareness and training, data security, platform security, and technology infrastructure resilience.

Appears in SEBI CSCRF as  PR.AA · PR.AT · PR.DS · PR.IP · PR.MA

DE

Detect

Continuous monitoring and adverse event analysis — whether you would know, and how quickly.

Appears in SEBI CSCRF as  DE.CM · DE.DP

RS

Respond

Incident management, analysis, reporting and communication, and mitigation.

Appears in SEBI CSCRF as  RS.AN · RS.CO · RS.IM · RS.MA

RC

Recover

Incident recovery plan execution and recovery communication. The function most often documented and least often tested.

Appears in SEBI CSCRF as  RC.CO · RC.IM · RC.RP

Implementation Tiers

Tiers describe rigour, not maturity scores.

A Tier is not a grade and Tier 4 is not the goal for everyone. It describes how deliberate and adaptive your risk management is, and the right answer depends on what you are protecting and what your counterparties require.

Tier 1

Partial

Risk management is ad hoc and reactive. Cybersecurity risk is not considered in organisational objectives, and there is limited awareness of supply chain risk.

Tier 2

Risk Informed

Risk management practices are approved but not established as organisation-wide policy. Awareness exists; consistent action does not.

Tier 3

Repeatable

Formally approved, expressed as policy, and updated as requirements change. Consistent methods for responding to change.

Tier 4

Adaptive

Practices adapt from lessons learned and predictive indicators. Cybersecurity risk is part of the organisational culture and budgeting cycle.

Who asks for it

Four reasons this lands on an Indian CISO's desk.

A global parent or acquirer

CSF is the language their board already uses. A profile travels; an Indian-framework gap report does not.

An enterprise customer's vendor questionnaire

Increasingly built on CSF categories. Answering from an existing profile turns a two-week scramble into an extract.

A cyber insurance underwriter

Underwriters want a maturity view, not a control checklist. Tiers and Profiles are built for exactly that conversation.

You are already regulated under something CSF-shaped

SEBI CSCRF is the clearest Indian example. One assessment can serve both if it is scoped to.

How we run it

Evidenced by testing, not by interview alone.

Most CSF assessments are a document review and a series of workshops. That produces a Current Profile describing what people believe is true. Pairing the assessment with technical testing produces one describing what is.

Identify and Protect, verified

Asset inventory checked against what is actually reachable from outside, and access controls checked by trying to bypass them.

Detect, measured

Whether your monitoring saw the testing, how quickly, and what it recorded — the only honest evidence for this function.

One programme, two frameworks

Where you are SEBI-regulated, the CSCRF evidence and the CSF profile come out of the same engagement rather than two.

Questions

Frequently asked

Is there such a thing as NIST certification?

No, and this is worth being clear about even though the search term is popular. The NIST Cybersecurity Framework is voluntary guidance. NIST does not certify organisations, does not accredit certification bodies, and issues no certificate. Anything sold as "NIST CSF certification" is a private firm attesting to its own assessment, which may be perfectly useful — but it is not a certification in the sense ISO 27001 is, and describing it as one to a customer or an auditor will not survive scrutiny. What you can legitimately hold is an independent assessment: a Current Profile, a Target Profile, an implementation Tier, and a prioritised gap analysis.

What changed in NIST CSF 2.0?

The headline change is a sixth function, Govern, which sits alongside the original five and covers organisational context, risk strategy, roles, policy, oversight and cybersecurity supply chain risk management. CSF 2.0 also broadened scope explicitly beyond critical infrastructure to organisations of any size and sector, and added implementation examples and Quick Start Guides. If your last assessment predates it, the gap is almost always concentrated in Govern — particularly supply chain, which was previously scattered across other categories.

We are SEBI-regulated. Does CSCRF work count towards NIST CSF?

Substantially, yes, and the reason is structural rather than coincidental. SEBI's CSCRF uses the CSF function and category codes as its own control identifiers — GV.OC, GV.RM, GV.SC, ID.AM, ID.RA, PR.AA, PR.DS, DE.CM, DE.DP, RS.AN, RC.RP and the rest all appear in the master circular. An entity that has done real CSCRF work has already produced most of the evidence a CSF assessment asks for, organised under the same headings. The gaps tend to be in scope rather than substance: CSCRF governs your SEBI-regulated activity, while a CSF profile covers the whole organisation.

Why would an Indian company need a NIST CSF assessment?

Four reasons come up repeatedly. A US or European parent or acquirer asks for a CSF profile because it is the language their board already uses. An enterprise customer sends a vendor questionnaire built on CSF categories. A cyber insurance underwriter wants a maturity view rather than a control checklist. Or the organisation is regulated under a framework that is CSF-shaped anyway — SEBI CSCRF being the clearest Indian example — and wants one assessment that serves both.

What does a NIST CSF assessment actually produce?

A Current Profile describing what you do today against the six functions, a Target Profile describing what your risk appetite and obligations require, the gap between them, an implementation Tier, and a prioritised remediation plan sequenced by risk rather than by category order. Where the assessment is paired with technical testing, the Detect and Protect findings are evidenced by what testing actually found rather than by what a policy says should happen.

How is this different from ISO 27001?

ISO 27001 certifies a management system against a defined standard, through an accredited body, with a certificate at the end. CSF is a risk-based framework for describing and improving posture, with no certificate. They are complementary rather than competing: many organisations run an ISO 27001 ISMS and use CSF profiles to communicate posture to boards, customers and insurers. If you need a certificate for procurement, you need ISO 27001. If you need a shared language for risk, CSF is the one most global counterparties already speak.