
NIST CSF 2.0 and ISO 27001: Why the Strongest Programs Use Both
Every security leader eventually gets asked the same question by a board member, a founder, or a prospect’s procurement team: “Which framework are we doing?”
The question assumes the frameworks compete. They don’t. NIST CSF 2.0 and ISO/IEC 27001:2022 are built for different jobs, and the strongest answer is usually not one or the other. It is understanding what each one is designed to achieve — and then letting each do the work it is actually good at.
Here is how that plays out in practice.
What NIST CSF 2.0 Is Designed to Do
NIST released CSF 2.0 in February 2024. It helps organizations organize, prioritize, and communicate cybersecurity outcomes across six core functions:
Govern → Identify → Protect → Detect → Respond → Recover
The addition of Govern (GV) in 2.0 was the significant change. In CSF 1.1, governance was buried inside Identify. In 2.0 it sits at the center, with six categories covering organizational context, risk management strategy, roles and responsibilities, policy, oversight, and — importantly — supply chain risk (GV.SC), which expanded from a single category into a serious body of guidance.
Three structural features matter:
- Functions, categories, subcategories. Six functions, 22 categories, 106 subcategories. Each subcategory is an outcome statement, not a prescribed control. GV.OC-01 tells you the organizational mission must be understood and inform risk management. It does not tell you what tool to buy.
- Profiles. You build a Current Profile (outcomes you achieve today) and a Target Profile (outcomes you need, based on business goals and risk appetite). The delta between them is your roadmap. This is the most underused feature of the framework.
- Tiers 1–4 (Partial, Risk-Informed, Repeatable, Adaptive). These are not maturity levels, and Tier 4 is not the goal. Tier advancement should be driven by risk reduction needs across three dimensions: risk management process, integrated risk management program, and external participation.
CSF is voluntary, sector-neutral, and free. There is no certification body and no certificate.
What ISO/IEC 27001 Is Designed to Do
ISO/IEC 27001:2022 provides auditable requirements for establishing, operating, maintaining, and continually improving an Information Security Management System (ISMS).
The part people miss: Annex A is not the standard. Annex A is a reference set of 93 controls across four themes (organizational, people, physical, technological). The actual requirements live in Clauses 4 through 10, and they are where certification is won or lost:
| Clause | Requirement | What it forces you to produce |
|---|---|---|
| 4 | Context of the organization | ISMS scope, interested parties |
| 5 | Leadership | Signed information security policy, defined roles |
| 6 | Planning | Risk assessment methodology, risk treatment plan, Statement of Applicability, security objectives |
| 7 | Support | Competence records, awareness evidence, document control |
| 8 | Operation | Executed risk assessments, treatment evidence, change records |
| 9 | Performance evaluation | Metrics, internal audit program, management review minutes |
| 10 | Improvement | Nonconformity and corrective action records |
Clauses 9 and 10 are the engine. Internal audit, management review, nonconformity, corrective action — that closed loop is what makes an ISMS a management system rather than a filing cabinet of policies.
And the output is independently verifiable: a Stage 1 and Stage 2 audit by an accredited certification body, surveillance audits in years one and two, recertification in year three. A customer can ask for the certificate and the Statement of Applicability, and get a real answer.
The Distinction That Actually Matters
| NIST CSF 2.0 | ISO/IEC 27001:2022 | |
|---|---|---|
| Nature | Outcome-oriented, adaptable | Requirements-based, prescriptive on process |
| Answers | What should we achieve? | How do we govern and prove it? |
| Structure | 6 functions → 22 categories → 106 subcategories | Clauses 4–10 (mandatory) + 93 Annex A controls |
| Assurance | Self-assessment; no certificate | Accredited third-party certification |
| Strength | Prioritization, communication, roadmapping | Governance discipline, evidence, continual improvement |
| Cost to adopt | Free, flexible, fast to start | Fee-bearing, structured, 6–12 months to certify |
| Weakness | No enforcement mechanism; easy to self-grade generously | Annex A checkbox culture; scope games |
Put plainly: NIST helps you decide what to do. ISO 27001 makes sure you actually keep doing it.
Used Together: One Operating Model
The two are complementary by design. NIST publishes ISO 27001:2022 mappings as Informative References in the CSF 2.0 Reference Tool, so the crosswalk is not something you have to invent.
Here is the mapping at the level you’ll actually use it:
| CSF 2.0 outcome area | ISO 27001:2022 anchor |
|---|---|
| GV.OC — Organizational context | Clauses 4.1, 4.2 |
| GV.RM — Risk management strategy | Clauses 6.1.2, 6.1.3 |
| GV.SC — Supply chain risk | A.5.19–A.5.22 |
| ID.AM — Asset management | A.5.9–A.5.12 |
| ID.RA — Risk assessment | Clause 6.1.2, A.5.7 |
| PR.AA — Identity and access control | A.5.15–A.5.18 |
| PR.DS — Data security | A.5.33, A.8.24 |
| PR.IR — Technology resilience | A.5.29, A.5.30, A.8.6 |
| DE.CM — Continuous monitoring | A.8.15, A.8.16 |
| RS.MA — Incident management | A.5.24–A.5.28 |
| RC.RP — Recovery planning | A.5.29, A.5.30 |
| ID.IM — Improvement | Clauses 9.2, 9.3, 10.1 |
And here is the sequence that turns the mapping into an operating model:
- Set direction with CSF. Build the Current and Target Profile. The Target Profile is where regulatory obligations, customer commitments, and board risk appetite get written down as required outcomes.
- Convert the gap into a risk-driven roadmap. Sequence matters: GV.OC and GV.RM before ID.RA; ID.AM before PR.AA. You cannot protect an asset inventory you don’t have.
- Wrap the roadmap in an ISMS. ISO 27001 Clauses 4–6 turn your Target Profile into a scoped, risk-assessed, formally approved program with a Statement of Applicability that documents every control decision — including the exclusions and why.
- Operate with evidence. Clauses 7–8 make the work produce artifacts as a byproduct rather than as a fire drill before an audit.
- Verify and improve. Clauses 9–10 give you internal audit, management review, and corrective action. Feed the findings back into the next CSF profile revision.
That last step is the whole point. CSF tells you where you’re going. ISO 27001 is the drivetrain that keeps you moving and the odometer that proves you did.
Where This Breaks in Practice
Four failure patterns, in rough order of how often I see them:
Annex A as the whole standard. A team builds 93 control descriptions, skips Clauses 9 and 10, and shows up to a Stage 2 audit with no internal audit program and no management review minutes. Those are major nonconformities. The controls were never the hard part.
Self-graded CSF profiles. Without an audit function forcing the question, “partially implemented” quietly becomes “largely implemented” over two quarters with nothing changing. CSF has no immune system of its own. This is precisely the gap ISO Clause 9.2 fills.
Scope games. Certifying a narrow slice of the business and letting sales imply the whole company is covered. Sophisticated buyers read the certificate scope statement. It does not end well.
Two programs instead of one. Separate risk registers, separate control libraries, separate reporting. If your CSF assessment and your ISO risk treatment plan are maintained by different people in different tools, you’ve doubled the cost and halved the value. One control library, mapped both ways.
My Perspective
I’ll be direct about where I land, having implemented both.
CSF 2.0 is the better thinking tool. ISO 27001 is the better governing tool.
CSF’s real strength is communication. Six functions is a structure a CFO can follow in a ten-minute board slot. When you tell an executive team “we’re strong in Protect, thin in Detect, and we have no Recover capability worth the name,” they understand the risk without you translating a control matrix. Profiles and gaps are a language non-security stakeholders can actually engage with, and that is worth more than most people credit.
But CSF has no teeth. Nothing in the framework compels you to revisit your profile, audit your own claims, or escalate a stalled remediation. It is a map with no engine. Programs built on CSF alone tend to drift — good in year one, stale by year three, because nothing in the structure forces the review.
ISO 27001 supplies exactly what’s missing: a required cadence. Risk assessment must be repeated. Internal audit must happen on a program. Management review must occur with defined inputs and produce decisions. Nonconformities must be tracked to closure. That discipline is unglamorous and it is the difference between a security program and a security posture.
The honest criticism of ISO 27001 is that the discipline can become the product. Certified organizations with genuinely weak security exist — usually via a narrow scope, generous risk acceptance, and controls documented rather than operated. The certificate proves a management system functions. It does not prove you’d survive a competent adversary.
Which is why I think the pairing is more than a compliance convenience. CSF pushes an ISMS toward outcomes that matter — particularly Detect and Recover, where ISO’s Annex A coverage is thinner than the threat landscape warrants. ISO pushes a CSF program toward evidence and cadence. Each covers the other’s structural blind spot.
One more thing worth saying: CSF 2.0’s Govern function narrowed the historical gap considerably. GV.OC, GV.RM, GV.RR, and GV.PO now cover much of the territory ISO Clauses 4, 5, and 6 occupy. If you built a serious CSF 2.0 program including Govern, your distance to ISO 27001 certification is shorter than it was under CSF 1.1. The remaining delta is mostly Clauses 9 and 10 — the audit and review machinery — plus formal documentation control.
Which One Should You Start With?
Start with the forcing function, not the framework.
Start with NIST CSF 2.0 if:
- You need to establish direction and priorities before spending money
- Your budget or headcount can’t absorb a certification effort this year
- You need to explain risk to a board or executive team quickly
- You’re US-based, in critical infrastructure, or a federal supply chain participant where CSF and SP 800-53 are the shared language
- You’re honestly at Tier 1 and need to know what “better” even looks like before committing to an audit date
Start with ISO 27001 if:
- Deals are stalling in security review right now — that’s a revenue problem with a deadline
- Enterprise or EU customers are asking for a certificate, not a self-attestation
- You already have reasonable controls and need the governance layer and third-party validation
- You have a related obligation nearby (SOC 2, ISO 42001, DORA, NIS2) and can share the management system across them
A practical default for most mid-market B2B SaaS and fintech companies: run a CSF 2.0 profile as a two-to-three week exercise to establish the outcome map, then immediately build the ISMS around it. The profile makes your ISO scope decision defensible and your Statement of Applicability grounded in something better than “the auditor asked for it.” You’re not doing two projects. You’re doing the thinking before the building.
And if your organization is already certified but the program feels performative — controls documented, nothing improving — the fix is usually not another framework. It’s a CSF 2.0 profile laid over your existing ISMS to surface the outcomes your Annex A implementation quietly failed to deliver.
The Real Question
It was never which framework is better. It’s which combination best supports your risk profile, regulatory obligations, customer expectations, assurance needs, and current maturity.
Get that answer right and the frameworks stop being compliance overhead. They become how the program runs.
Which does your organization use today — NIST CSF, ISO 27001, or both? If you’re deciding where to start, or you have a certification that isn’t producing real risk reduction, I’m happy to talk it through: info@deurainfosec.com
HD is Principal Consultant at DISC InfoSec, providing vCISO, ISO 27001, ISO 42001, NIST and SOC 2 advisory to B2B SaaS and financial services organizations. He led ShareVault through a successful ISO 42001 Stage 2 certification audit.
This article provides informational guidance based on NIST CSF 2.0 (February 2024) and ISO/IEC 27001:2022. It is not legal, audit, or certification advice. Certification decisions should be validated with your certification body and qualified advisors.
DISC-AI-Governance-Readiness-Assessment-1-1 pdf downloadDownload
MachineLearning & Artificial Intelligence
AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do
Your Shadow AI Problem Has a Name-And Now It Has a Score
Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Securit
NIST CSF 2.0 and ISO 27001: Why the Strongest Programs Use Both- Continuous NIST 800-53 Compliance: How to Stop Failing in the Eleven Months Between Audits
- AI Governance Readiness Assessment — Service
- GRC Engineering: From Evidence Theater to Genuine Assurance
- AI Risk Management: AIRM isn’t a Security Problem — It’s Bigger
DISC InfoSec blog | DISC InfoSec Site | Contact us at info@deurainfosec.com





















