s90

Home / Compliance / NIST CSF 2.0

For teams that need a recognized standard

NIST CSF 2.0Included

A recognized standard you can show, not just name.

NIST CSF 2.0 is a voluntary framework for managing cybersecurity risk, organized into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It's included in Complete IT and built into your Technology Posture Report, which maps every check to it each quarter, so when someone asks what standard you follow, you can show them, not just tell them.

A small conference room just after a planning exercise, with six neat columns of sticky notes on a whiteboard and papers and coffee cups left on the table.

At a glance

Framework
NIST CSF 2.0
Evidence
Technology Posture Report, quarterly
Included in
Complete IT: Managed or Co-Managed

Does this apply to you?

It likely fits if someone is asking what standard you follow, such as:

What the rule asks for, and what you receive.

  1. 01

    Govern: decide who owns security decisions

    Documented roles and decisions

    Where you stand in Govern, and how it has changed

  2. 02

    Identify: know what you have and what's at risk

    Asset and risk tracking

    Where you stand in Identify, and how it has changed

  3. 03

    Protect: put safeguards in place

    Safeguards across devices, accounts and data

    Where you stand in Protect, and how it has changed

  4. 04

    Detect: know when something is wrong

    Monitoring

    Where you stand in Detect, and how it has changed

  5. 05

    Respond: know what you'd do about it

    A response runbook

    Where you stand in Respond, and how it has changed

  6. 06

    Recover: know how you'd get back to work

    Tested backup and recovery

    Where you stand in Recover, and how it has changed

We provide the evidence. You decide.

s90 does

  • Runs the controls the framework calls for
  • Keeps the documentation current
  • Reports it in your Technology Posture Report every quarter

You decide

  • Whether the evidence meets your obligations
  • Which open gaps to close first
  • Whether you meet the standard

The Technology Posture Report

Built into your Technology Posture Report, with every check mapped to NIST CSF 2.0, delivered every quarter without asking. The proof in your hands is never more than three months old.

Get the sample Technology Posture Report by email

Sample · Technology Posture Report

ACME Corp · Quarter 3 · Mapped to NIST CSF 2.0

Where you stand in Govern, and how it has changed
7 of 10 in place
Where you stand in Identify, and how it has changed
9 of 11 in place
Where you stand in Protect, and how it has changed
17 of 19 in place

Sample report for a fictional business. Example figures.

Other frameworks you may answer to.

Low-rise office buildings with tile roofs among oaks and palms in the south Orange County foothills, with Saddleback Mountain in the morning haze beyond.
s90

One question to ask yourself

If a client asked what standard you follow, could you show them?

Up to$500,000Cyber WarrantyBacked by Cork Inc.

In 30 minutes, we talk through your setup and you leave knowing which plan fits.

Book a call

See exactly what you'd receive each quarter, by email.

Get the sample Posture Report by email