You decide
- Whether the evidence meets your obligations
- Which open gaps to close first
- Whether you meet the standard
For teams that need a recognized standard
NIST CSF 2.0 is a voluntary framework for managing cybersecurity risk, organized into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It's included in Complete IT and built into your Technology Posture Report, which maps every check to it each quarter, so when someone asks what standard you follow, you can show them, not just tell them.

It likely fits if someone is asking what standard you follow, such as:
Govern: decide who owns security decisions
Documented roles and decisions
Where you stand in Govern, and how it has changed
Identify: know what you have and what's at risk
Asset and risk tracking
Where you stand in Identify, and how it has changed
Protect: put safeguards in place
Safeguards across devices, accounts and data
Where you stand in Protect, and how it has changed
Detect: know when something is wrong
Monitoring
Where you stand in Detect, and how it has changed
Respond: know what you'd do about it
A response runbook
Where you stand in Respond, and how it has changed
Recover: know how you'd get back to work
Tested backup and recovery
Where you stand in Recover, and how it has changed
Built into your Technology Posture Report, with every check mapped to NIST CSF 2.0, delivered every quarter without asking. The proof in your hands is never more than three months old.
Sample · Technology Posture Report
ACME Corp · Quarter 3 · Mapped to NIST CSF 2.0
Sample report for a fictional business. Example figures.

One question to ask yourself
In 30 minutes, we talk through your setup and you leave knowing which plan fits.
Book a callSee exactly what you'd receive each quarter, by email.
Get the sample Posture Report by email