The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
NIST CYBERSECURITY FRAMEWORK
Where your company stands today and where the board decided it needs to stand. That difference, measured with method and revisited over time, is the only honest answer to the question every board asks and almost no security function can answer without a forty-page deck.
The NIST CSF is a public framework adopted voluntarily. What DM11 delivers is the assessment, both profiles, the plan and the tracking routine, which is what answers the board. Where the goal also includes a document to send a customer, the ISO 27001 or SOC 2 pages explain that route, and the two pieces of work support each other.
Who runs the implementation
ISO/IEC 27001 Lead Auditor certified by BSI
CISA, information systems auditing
Specialists in risk management and business continuity
17 years of governance, risk and compliance
WHAT IT IS
The Cybersecurity Framework is published by the United States standards and technology institute, and has been at version 2.0 since 26 February 2024. It organises security into functions, categories and subcategories, and each subcategory describes an outcome to reach. It is neither a certifiable standard nor a technical manual: it is the structure that lets you track security over time in vocabulary a board understands.
Identify, protect, detect, respond and recover already existed. Version 2.0 added govern, and placed it at the centre of the other five. The change has a practical consequence: govern deals with who decides, who answers and what the company's risk appetite is, which is precisely what was missing while the framework described activity without describing accountability. If the material you hold shows five functions, it belongs to the previous version.
There are 22 categories and 106 subcategories, and each describes what has to be true without saying which technology gets you there. That is deliberate and it is the framework's greatest strength: it does not age alongside the tooling market, and no vendor can use it to argue that their product is mandatory.
The current profile records where the company stands, subcategory by subcategory. The target profile records where it decided to stand, which is not the same as the maximum available. The distance between the two is the plan, the budget and the thing you put in front of the board. No other reference on this page produces that artefact.
The four tiers describe how rigorously a company governs and manages risk, and choosing a tier is a decision about risk appetite and resources, not a ladder to climb for sport. Most companies cannot justify the highest tier, and treating it as the target is the most common misreading. Because the framework is adopted voluntarily, it produces no certificate of conformity, which is why its value shows in the tracking over time.
WHO USUALLY NEEDS IT
Note that none of them ends in a certificate. The CSF solves tracking and conversation; where the problem is proving something to a third party, the route is a different standard.
And today the answer is a long presentation nobody can turn into a decision. With both profiles built, the question gets a one-page answer, with a measured distance and a cost attached to closing it, which is the format boards decide in.
Penetration testing on one side, data protection work on another, a continuity project stalled somewhere in the middle and tools bought at different moments. The CSF is the umbrella that shows what those efforts cover together, and above all what none of them covers.
Common in subsidiaries of US companies and among suppliers to regulated sectors. The request usually arrives without detail, and the first useful deliverable is translating what it means: almost always a documented current profile, not a promise of Tier 4.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern of the problems repeats. Where a client agrees, we give named references in a conversation.
Financial services
Each quarter the board asked whether the company was secure, and the technology function answered with a long pack full of tool metrics and no thread running through it. The question returned identical the following quarter, because the answer never turned into an investment decision.
We built the current CSF profile and ran a session with the executive team to define the target profile, function by function. The discussion was about risk appetite rather than technology, and it was the first time that group had explicitly stated how far it wanted to go on each front.
The distance between the two profiles became a single page with a cost attached. The board started discussing how much of the gap to close instead of asking whether it was secure, and the technology function stopped defending a budget with no reference point.
Subsidiary of a multinational
The parent company asked for CSF alignment. The Brazilian operation held a current ISO 27001 certificate, and the internal reading was that the request was already satisfied: send the certificate and close the matter.
We mapped the existing controls against the six functions. Identify, protect and detect came out strong, as you would expect from a certified management system. Respond looked reasonable on paper and had never been exercised, and recover was practically empty: there were backups and there was no business resumption plan.
The certificate did not answer the request, and that became clear in two weeks rather than after six months of misunderstanding with the parent company. The project that came out of it was continuity, which was the real gap, rather than one more security control.
Logistics
The company suffered a serious incident and reacted by investing heavily in detection tooling, which was where the pain had been felt. A year later, with the money spent, nobody could say whether the company would hold up better against the same event.
We ran the assessment across the six functions and the wheel came out visibly lopsided: detect well above everything else, respond with no tested procedure, and recover with no defined timeframe for anything. We showed that the next unit of budget bought more outside detection than inside it.
The incident had bought the right tool for the wrong problem. The company carried on detecting well and gained an answer for what to do after detecting, which was exactly what had been missing the first time.
SELF-ASSESSMENT
Twenty-one questions, and the first one does not count towards the score: it is there to understand your case. The full result appears on screen, with a score for each function and an honest read on what is missing. The CSF is not certifiable, and this diagnosis is not an assessment: it estimates your current profile, which is half the work. The other half is your leadership deciding where it wants to be. We do not ask for your email to show the result.
The reading for each area, across the three result ranges. It is the same text emailed to those who identify themselves, published here for anyone who wants to understand what the score measures before answering.
Below 50
A low score here weighs more than it looks, because govern accounts for a quarter of the result and it is the function version 2.0 placed at the centre of the other five. In practice it says that security at your company belongs to the people who execute rather than the people who decide. What is usually missing is four things in writing: how much risk the company accepts, who answers for each function, when the topic returns to the agenda and what criterion applies to accepting a supplier. The concrete step fits on one page, not into a programme: a single sheet with those four items, approved in a meeting and dated, moves this number more than any technical project this half.
50 to 79
Governance exists, and it lives in people instead of living in decisions. The symptom is familiar: each director would describe the risk appetite differently, and nobody notices until the team changes. What is usually missing is not writing from scratch, it is formalising what is already consensus and dating it, plus the supplier criterion, which 2.0 pulled inside govern and almost everybody still treats as a procurement matter. The concrete step is to turn the next conversation that was going to happen anyway into minutes, with a named decision and an owner per front.
80 or above
The company decides on security instead of reacting to it, which is a clear minority in the market. What is usually missing in this band is a recorded measurement method: anyone who has commissioned a diagnosis tends to consider the item settled, and the real test is a different one, whether somebody else could repeat the same measurement a year from now and arrive at a comparable number. It is worth checking too that the written risk appetite gets cited when deciding what not to do, because that is where it proves it exists. And the usual caveat applies: a high govern score is not a declared tier, because a tier is decided with leadership against appetite and resources, not self-declared.
Below 50
Without knowing what the company cannot afford to lose, every priority becomes the preference of whoever speaks loudest, and that is why this function often explains low scores in protect and in recover. The most common ordering mistake is starting with the technical inventory of equipment, which is long and yields little here. The shorter path is the reverse: sit with the business areas, list the processes that stop first and only then ask which systems each one depends on. An afternoon with three areas produces more than a month of automated discovery.
50 to 79
The mapping exists and it has aged, which is the most common state of this function. A list built once and updated when someone remembers stops being valid the day an area contracts a cloud service on its own, and nobody finds out until the incident. What is usually missing is the trigger: who flags a new system, and how often the list gets checked. The concrete step is to date the last review of each item and schedule the next, because an item without a date does not announce that it is stale.
80 or above
The company knows what it has, whose it is and what hurts first, and that is the base that makes the rest of the CSF pay off. The point to watch in this band is the edge: what a business area contracted directly, what runs inside a third party's service and the data that exists only in someone's spreadsheet rarely make it onto the good list. It is also worth setting the risk register against the decisions of recent months, because a risk accepted with nobody's name on it comes back as a surprise. The next step is to review when the context changes, rather than on a calendar date.
Below 50
This is the function where most money is spent and least decision is recorded, and a low score here almost always means the second thing rather than the first. There are probably controls working, and what is missing is the rule that says who may see what, with a review that actually happens and leaves a trace. The concrete and cheap step is to pick the three most critical systems, list who has access to them today and check that list with the area manager. The conversation about how much to invest comes after that one, never before.
50 to 79
Protection exists, and it depends on the right people staying at the company. A rule that lives in the policy and a review that happens when there is spare time produce exactly this number. What is usually missing has two fronts: an access review with a record of who reviewed it and what was removed, and some measure of the effect of training, because an attendance list measures turnout rather than understanding. The concrete step is to fix an access review date in the owner's calendar, with the instruction to record what was taken away, which is the part that becomes evidence.
80 or above
The controls follow a rule and the rule gets reviewed, which already covers most of what this function asks for. What is usually missing in this band is self-criticism about where the investment came from: the question about purchase priority is the least reliable in this diagnosis, because the person answering is often the person who signed. A simple and uncomfortable test is worth running: take the three largest security spends of the last two years and look for the identified risk that preceded them. If it does not exist in writing, this function's real score is a step below the one you have just seen.
Below 50
A low score here usually coexists with an expensive tool already installed, and that combination is the most frequent in the market. Monitoring what the tool delivers by default means watching what the vendor thought likely, rather than what your company cannot afford to lose. What is usually missing before any technology is the decision about what needs to be seen, and it comes from the list of critical systems. The concrete step is to take the five most critical systems and answer, for each, whether anyone today would be able to say it had been accessed improperly. The negative answers are your work list.
50 to 79
Someone looks at the alerts, and there is no queue. That is the difference between having attention and having a process, and it shows on the first day the person who usually looks is on holiday. What is usually missing is an owner, a deadline by severity and a record of the outcome, which is what lets you say later whether an alert was handled or merely closed. The concrete step is to set a deadline for two severities only, not five, and record the closure of every alert for a month. The real volume tends to surprise, and it is what sizes whatever comes next.
80 or above
Detection grows out of what matters and the gaps are known, which is rare enough to be worth stating. The risk in this band is silent drift: the environment changes, a new service arrives, and coverage assessed a year ago starts describing a company that no longer exists. It is worth tying the coverage review to the arrival of a new system rather than to the calendar. And it is worth checking the next link, because good detection with weak response only brings forward the moment the company discovers it does not know what to do.
Below 50
With no written plan, the response to an incident depends on whoever happens to be available and on how much that person can improvise under pressure. It is the function where the distance between the score and reality is cruellest, because nobody discovers the problem in a meeting, they discover it at two in the morning. What is usually missing first is not a technical procedure, it is contacts and authority: who calls whom, who can decide to shut a system down and who authorises bringing in a third party. The concrete step is one page with those names and numbers, saved outside the company's environment, because a plan stored in the system that went down is not a plan.
50 to 79
The document exists and it has never been put to any test. An unexercised plan ages in silence: a number changes, a person leaves, a supplier is replaced, and the discovery happens at the worst possible moment. What is usually missing is two things in the same room, someone from leadership taking part in the exercise and the agreed communication with customers and with the authority, including the data protection law deadline, which runs while the technical team is still putting out the fire. The concrete step is a ninety-minute tabletop exercise with a single scenario, and the list of what jammed is worth more than any revision of the plan's text.
80 or above
There is a plan, it has been exercised and the communication is agreed, which puts the company ahead of most certified ones. What is usually missing in this band is varying the scenario: repeating the same ransomware exercise every year trains the team for a script rather than for an incident. It is worth running a compromised supplier or an insider leak scenario, which stress authority and communication differently. And it is worth checking whether the lessons from the last exercise became fixes with owners, because an exercise with no consequence is expensive theatre.
Below 50
It is the function that most often turns up empty, including at companies that have already invested heavily in security, and the reason is that it is only called on after the worst has happened. A low score here means there is an expectation of quick resumption with nothing behind it, and that expectation usually sits in the heads of the leadership team. What is missing before any technology is a short conversation with the business: how long each critical process can stand still, stated by whoever answers for the process rather than by IT. The concrete step is to write that number down for the three most critical processes and compare it with the time IT would take today. The difference between the two is your project.
50 to 79
IT has an estimate and the business has an expectation, and the two have never been set against each other. It is the origin of the sentence heard after every long incident, that nobody imagined it would take so long. What is usually missing is the clock: a partial test, run by IT without involving the areas, proves the data comes back and does not prove the company gets back to operating. The concrete step is to pick one critical process and test its resumption end to end with someone from the business area present, measuring the total time to normal operation rather than to the system coming up.
80 or above
A deadline agreed with the business and a timed test put this function at a level few companies reach, and it is the one that most protects revenue in a serious event. What is usually missing in this band is the external dependency: a critical supplier with no contracted resumption deadline hands you a period of time you do not control. It is also worth closing the loop that hands information back to govern, because post-incident analysis that produces a report without a tracked fix makes the same event return. The next step is to verify, months later, whether the fixes from the last incident were actually carried out.
HOW WE RUN IT
The step that separates this from an ordinary assessment is the second one. The target profile is not set by technology: it is an executive decision about risk appetite, and running that conversation is part of the delivery, because a target profile set by IT alone does not survive the first budget cut.
We define what enters the assessment and start with govern, which is where version 2.0 placed the centre. Who decides on risk, who answers for each front, what has been formally decided and what exists only by habit. Without that, the rest of the assessment becomes a picture with no owner.
Assessment scope defined, with the units included
A map of who decides and who answers for each front
A record of what is a formal decision and what is informal practice
Stakeholders identified, inside and outside the company
Delivery milestoneScope approved and accountability defined for each of the six functions.
We assess the 106 subcategories against evidence, through interviews and verification, accepting no positive answer without proof. The result is a picture of the current state by function and by category, in the form that allows comparison later.
A documented current profile, subcategory by subcategory
Evidence attached to every positive assessment
A reading by function, with the asymmetries visible
Reuse of whatever exists from ISO 27001, CIS or earlier projects
Delivery milestoneCurrent profile closed, with evidence for every subcategory assessed as met.
We run the session where leadership defines where it wants to be, function by function, against risk appetite, contractual obligation and available resources. We bring sector reference points into the conversation, but the decision belongs to the company, and it has to be taken by whoever signs the budget.
A target profile defined and signed off by leadership
A tier chosen per category, with the rationale recorded
The distance between the two profiles quantified
Priorities set against risk and against cost
Delivery milestoneTarget profile approved by leadership, with a recorded rationale for every choice.
We turn the distance into a plan with owners and dates, executed with your team. And we set the reassessment cadence, because the CSF's value shows up on the second measurement rather than the first: an isolated picture shows no direction at all.
A closure plan with an owner and a date per item
Execution supported, with periodic progress review
Board-facing tracking material, free of jargon
A reassessment cadence defined, with who runs it and when
Delivery milestoneSecond measurement completed with the same method, showing the direction of travel.
HOW LONG IT TAKES
We do not publish a standard timeline, because a published timeline turns into a promise. There is a particularity here worth saying up front: gathering the current profile takes a predictable amount of time, and what stretches the project is almost always the executive calendar for deciding the target profile. These are the three factors that move the clock most.
A single operation is one profile. A group with businesses of different kinds usually needs more than one, because the risk appetite of a manufacturer and of a finance arm in the same group are not the same, and forcing a single profile produces a number that serves neither.
With calendar time secured, that stage takes weeks. When it is delegated to IT, the project moves faster and delivers less, because the target profile becomes a technical opinion rather than a business decision, and it will not carry a budget.
A company holding a current ISO 27001 certificate, or with the CIS Controls implemented, assembles the current profile far faster, because the evidence already exists and only needs rereading in the CSF's structure. With nothing measured, the gathering is the longest stretch.
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered straight.
No. The framework is voluntary, NIST issues no certificate of conformity and accredits nobody to issue one. There is a market selling what it calls NIST CSF certification: what gets delivered there is a third-party assessment report, which is legitimate and useful, and is not a recognised certificate. If your customer needs a document carrying third-party weight, the route is ISO 27001 or SOC 2.
The CSF is the language and the map: it organises the conversation and lets you track progress over time. The CIS Controls are the ordered task list: they tell you what to do first. They do not compete, and CIS Controls v8.1 aligned itself with CSF 2.0. In practice, plenty of companies use the CSF to talk to the board and CIS to do the work.
No, and the difference is one of purpose. ISO 27001 certifies, so it serves to prove something to a third party. The CSF does not certify, and works better for tracking maturity over time and for talking to the people who decide budgets. Mature companies tend to use both: the certificate answers the customer, the profile answers the board.
It is out of date rather than wrong: it is version 1.1. Version 2.0, published on 26 February 2024, added the govern function and placed it at the centre of the other five. It is worth checking, because govern is precisely the function where most companies discover a gap, and older material does not even ask about it.
Almost certainly not, and treating the tiers as a ladder is the most common misreading. The four tiers describe how rigorously a company governs and manages risk, and the right tier is the one your risk appetite and your resources justify. A company sitting at Tier 2 across the board, by conscious and documented decision, is in better shape than one aiming at Tier 4 everywhere and arriving nowhere.
It does, and it is used worldwide. It is a public, voluntary framework with no jurisdiction attached, and version 2.0 was explicitly rewritten for organisations of any size and sector, where the previous one was aimed at critical infrastructure. What it does not do is answer a data protection law: statutory obligations remain a matter for a compliance project and legal advice.
The assessment across the six functions shows where your company stands and where the gaps concentrate. The next conversation, with your leadership, sets where it needs to stand. The distance between those two things is what becomes the plan.
Comparisons on this subject
See all 13 comparisonsNIST, instituto nacional de padrões e tecnologia dos Estados Unidos · NIST CSWP 29, publicado em 26/02/2024 · accessed on
Center for Internet Security · versão 8.1, de junho de 2024 · accessed on
ISO/IEC · ISO/IEC 27001:2022, edição 3, com a emenda 1:2024 · accessed on
This page is informational and describes how DM11 reads and applies the sources above. It does not reproduce the text of any standard, does not replace reading the official document, and does not replace an audit, a certification, an independent assessment or legal advice. Where a standard requires formal assessment, it is carried out by an accredited body, auditor or assessor, always separate from whoever did the preparation.