Skip to content
Framework · NIST 2.0

NIST CSF

The most widely adopted cybersecurity framework in the United States. Voluntary but increasingly expected by regulators, partners, and insurance carriers.

185 Talarity controls mapped
Who it's for: Any organization wanting a defensible security baseline — especially those that touch critical infrastructure or sell to the federal government.
Talarity coverage

Mapped, monitored, and audit-ready.

Every NIST CSF control has a place in Talarity — with cross-mapping, automated evidence, and continuous validation.

185
Talarity controls mapped

Talarity's pre-built control library covering NIST CSF, with linked evidence, owners, and testing schedules.

Cross-maps to
CIS ControlsISO 27001SOC 2NIST 800-53

Answer once, prove everywhere. Talarity's mapping engine reuses your evidence across every framework you run.

Automated evidence
  • Asset inventory with criticality ratings
  • Vulnerability scan output and remediation tickets
  • Identity and access management logs
  • Incident response runbooks and post-incident reports
  • Detection capability coverage matrices

Your NIST CSF dashboard

Every completed NIST CSF assessment updates this automatically — where you stand now, how that has changed, and which areas need work.

Click to enlarge
The Talarity dashboard for a completed NIST Cybersecurity Framework assessment: the latest score, the trend across previous assessments, and a breakdown by control area
Common pain points

What gets easier with Talarity.

Pain

CSF 2.0 added the Govern function — and existing maturity assessments don't account for it.

Talarity

Talarity ships CSF 2.0 with all six functions (Govern, Identify, Protect, Detect, Respond, Recover) and 185 outcomes. Govern functions are pre-populated; you focus on validation.

Pain

Maturity-tier scoring (Partial → Adaptive) is subjective and inconsistent across teams.

Talarity

Talarity uses evidence-based maturity scoring. A control's tier is computed from the artifacts behind it — not someone's opinion.

Pain

Boards want a CSF radar chart; technical teams want safeguard-level detail. Two audiences, two views.

Talarity

Two dashboards from the same data. Executive radar for the board; technical drilldown for the practitioner.

Pain

Mapping CSF to your other frameworks (SOC 2, ISO, NIST 800-53) is painful when done manually.

Talarity

Built-in cross-mappings to NIST 800-53, ISO 27001, CIS Controls, and SOC 2. One assessment, multiple frameworks satisfied.

NIST CSF — common questions

What is new in NIST CSF 2.0?
CSF 2.0 added Govern as a sixth Function alongside Identify, Protect, Detect, Respond and Recover, raising organisational context, risk management strategy, roles, policy and oversight of the supply chain to the same level as the technical functions. Its stated scope also broadened beyond critical infrastructure to organisations of any size and sector, and it added implementation examples and quick-start guides to make the outcomes more actionable.
What are the six CSF Functions?
Govern establishes and monitors the cybersecurity risk management strategy, expectations and policy. Identify develops understanding of assets, risks and dependencies. Protect implements safeguards. Detect finds occurrences of cybersecurity events. Respond acts on detected incidents. Recover restores capabilities and services. They are concurrent and continuous rather than sequential phases.
Is NIST CSF mandatory, and can you be certified against it?
The Framework is voluntary and there is no certification body issuing CSF certificates. It is widely adopted because it maps cleanly onto other frameworks and gives boards a common vocabulary for risk. Some sectors and contracts reference it, in which case the obligation comes from that contract or regulation rather than from the Framework itself.
What is the difference between a CSF Tier and a Profile?
Tiers describe how rigorous and integrated your risk management practices are, from Partial through Risk Informed and Repeatable to Adaptive — they characterise practice, not maturity scores to be chased. Profiles describe outcomes: a Current Profile records what you achieve today and a Target Profile what you intend to achieve, with the gap between them driving the action plan. Profiles are where the framework becomes a programme.

Working with NIST CSF

Step-by-step walkthroughs from the Talarity library.

Ready to ship NIST CSF?

Start a 7-day trial and run this framework end-to-end on your own evidence — then buy online in-app when you're ready.