Structure Govern, Identify, Protect, Detect, Respond and Recover, and map them onto the frameworks you already run.
The NIST Cybersecurity Framework 2.0, published in February 2024, is a voluntary framework for organising cybersecurity, not a certifiable standard. Version 2.0 introduces a sixth function, Govern, alongside Identify, Protect, Detect, Respond and Recover, and it explicitly widens the scope beyond critical infrastructure to organisations of any size. The framework is organised into functions, categories and subcategories, and is completed by profiles describing the current and the target state. That structure is what makes it a shared language between technical teams and the board.
Because the CSF carries no certification, its practical value lies in measurement: where you stand on each subcategory, where you want to be, and what gap that represents. A useful tool therefore holds the current profile, the target profile, the gap and the plan connecting them. It also has to map CSF subcategories onto the controls you already run, ISO 27001 and NIST SP 800-53 in particular, or you end up maintaining two parallel frameworks describing the same measures.
Vailor automatically maps CSF 2.0 subcategories onto the ISO 27001 controls and risk assessments you have already produced, so measurement lands on the real gap rather than on re-entry. Agentic AI documents the gaps and prepares the steering deliverables, with every output explainable and traceable. For a European organisation using the CSF as an organising frame while answering to NIS2 or DORA, the point is to hold all three readings on one data layer.
Govern, Identify, Protect, Detect, Respond and Recover, structured into categories and subcategories.
Measure where you stand, define where you are going, and track the gap between the two.
CSF subcategories mapped onto your ISO 27001 controls and your EBIOS RM assessments.
Your posture data stays sovereign, hosted in France and the European Union.
No. The five original functions stay in place, so most of the work already done on Identify, Protect, Detect, Respond and Recover carries over. The changes to handle are specific: the new Govern function, which takes in the governance and supplier risk outcomes previously attached to Identify, and the renumbering of some categories and subcategories. The sensible route is to map your existing assessment onto the 2.0 subcategories, then reassess only the ones that genuinely moved.
ISO/IEC 27001 is a certifiable standard: it requires an information security management system, with a defined scope, a policy, management review and an audit by an accredited certification body. The NIST CSF describes expected security outcomes, organised into functions and subcategories, without imposing a management system and without granting any certificate. The two combine well: the CSF gives you a reading and communication grid, ISO 27001 gives you the proof a customer or an insurer will accept.
Govern deals with what frames security rather than what implements it: organisational context, risk management strategy, roles and responsibilities, policy, oversight of results, and cybersecurity supply chain risk management. It is the function that ties security to business priorities and names who decides, who arbitrates and who answers for the outcome. It is also the hardest one to hold in a spreadsheet, because its outputs are decisions and trade-offs rather than ticked boxes.
The Tiers, from Partial to Adaptive, describe how rigorously an organisation governs and manages its cyber risk: how formalised the practices are, how third-party risk is taken into account, how far security is integrated into wider decisions. They are neither a per-control maturity score nor a target to push to the maximum: the Tier you aim for follows your context, your obligations and your means. Read them alongside profiles, not instead of them: the profile says where you stand subcategory by subcategory, the Tier says how you steer the whole.
No. NIS2 and DORA set their own legal obligations: risk management measures, incident reporting, oversight of third-party providers, accountability for management bodies. The CSF is not a compliance framework recognised by those texts, and no profile creates a presumption of conformity. It still works as a backbone: structuring your measures across the six functions, then mapping each subcategory onto the applicable requirements, lets you handle the shared ground once and isolate what belongs to each text.
To get started, yes. The limit arrives quickly: every subcategory carries a current state, a target state, a rationale, evidence, an owner and a due date, and you need the history to show a trajectory. Add the mapping onto ISO 27001 or SP 800-53 and you are maintaining a matrix by hand every time a control changes. A spreadsheet does not record who changed what, does not tie a subcategory to dated evidence, and cannot replay the gap after a reorganisation.
Through documentation rather than a certificate: a dated current profile backed by evidence attached to each subcategory, an owned target profile, and a tracked action plan. An independent third-party assessment remains possible, but it does not commit NIST and produces no official label. If the person asking wants proof they can rely on contractually, an ISO 27001 certificate or an audit report is what you hand over, with the CSF profile used to explain the trajectory.
Discover all our resources on governance, risk, and compliance powered by artificial intelligence.
Everything you need to know about AI GRC: definition, benefits, implementation, and best practices to transform your governance with artificial intelligence.
Essential criteria for selecting the best cyber AI GRC platform. Architecture, sovereignty, features: the complete buying guide.
Book a demo and watch your current profile build itself from your own data.