NIST CSF 2.0 · The 4-Week Cybersecurity Readiness Assessment

Before the regulator asks, know your posture. Measured against the framework they all build on.

A fixed-scope, four-week assessment of your cybersecurity programme against NIST Cybersecurity Framework 2.0 — the baseline behind NIS2, DORA, CyFun and Ireland's public-sector standards. You leave with a current profile, a target profile, a tier, and a roadmap your board can act on.

CSF 2.0 opens with a new function, Govern: the organisation's cybersecurity risk management strategy, expectations and policy are "established, communicated, and monitored." Every other function depends on it — and it belongs to leadership, not IT.

Quoted phrase from the Govern function of the NIST Cybersecurity Framework 2.0 (February 2024). CyFun and the NCSC's public-sector baseline standards are both built on the NIST framework.
Source: National Institute of Standards and Technology — Cybersecurity Framework 2.0nist.gov/cyberframework
Trusted expertise in regulated digital resilience
Operating since 2014 CyberPrism on Azure Marketplace Enterprise Ireland-backed technology Partnered with eir business
Awards and accreditations: IRM Global Risk Awards 2016, Bank of Ireland Startup Awards 2017 Fintech Award, HM Government G-Cloud approved supplier, CIR Risk Management Awards winner — Risk Management Specialist Company of the Year

One framework underneath all of them.

NIS2, DORA, CyFun, ISO 27001 and Ireland's public-sector Cyber Security Baseline Standards all describe the same underlying capabilities. NIST CSF 2.0 is the common language — assess against it once, and every regulatory view follows.

FEB 2024

CSF 2.0 published

The first major revision in a decade. It broadened the framework from critical infrastructure to every organisation, of any size and sector, and added a governance function.

6 FUNCTIONS

Govern, Identify, Protect, Detect, Respond, Recover

Govern is new in 2.0 and sits across the other five. It is where board accountability, risk appetite, supply-chain policy and oversight live — the material regulators now examine first.

4 TIERS

Partial to Adaptive

Tiers describe how rigorously an organisation manages cyber risk. The assessment places you on a tier, agrees the tier you should be at, and shows the gap between the two.

The question every leadership team should be able to answer is not "are we compliant" but "what is our posture, what should it be, and what will it take to get there."

CSF 2.0's current profile, target profile and tiers exist precisely to answer that in terms a board can use.

What CSF 2.0 expects of leadership

The Govern function sets out what an organisation's leadership is responsible for. It reads very like Article 20 of NIS2 and Article 5 of DORA, which is no accident — both were written with it in view.

Under the Govern function, leadership is expected to establish and oversee:

  • Organisational context — mission, stakeholders, legal and regulatory requirements
  • Risk management strategy, risk appetite and tolerance
  • Roles, responsibilities and authorities for cybersecurity
  • Policy — established, communicated and enforced
  • Oversight — results used to inform and adjust the strategy
  • Cybersecurity supply-chain risk management

In Ireland, the NCSC's guidance for boards, the CyFun framework it prefers for NIS2, and the Cyber Security Baseline Standards for public bodies all use the NIST structure. A CSF 2.0 assessment is therefore the one that translates into whichever regime reaches you next.

BOARD QUESTIONS

What a leadership team should be able to answer

  • What are our critical assets and services, and who owns them?
  • What is our risk appetite, and has the board set it?
  • Which tier are we at, and which should we be at?
  • How do we know our suppliers meet our standard?
  • When did we last test detection, response and recovery?
CSF 2.0 OUTCOMES

What the assessment measures

The framework's structure, applied to your organisation
  • Six functions — Govern, Identify, Protect, Detect, Respond, Recover
  • 22 categories and their subcategories, each declared and evidenced
  • Current profile — where you are today, outcome by outcome
  • Target profile — where you should be, set with your leadership
  • Tier — Partial, Risk Informed, Repeatable or Adaptive
  • Gap analysis between current and target, weighted by exposure
  • Regulatory views — the same evidence read through NIS2, DORA and CyFun
  • Remediation roadmap with owners and timeframes
CyberPrism carries a complete NIST CSF 2.0 declarations library with guidance for every outcome, so the assessment is structured and comparable rather than a bespoke questionnaire.

Who it is for

CSF 2.0 is written for every organisation, not a sector. In practice, three groups get the most from a framework-first assessment.

Organisations without a named regulation — yet

Or not sure which one reaches them
  • Mid-sized businesses whose customers, insurers or banks are starting to ask cyber questions
  • Organisations that may fall under NIS2 once the Irish Bill is enacted and want a baseline now
  • Groups with subsidiaries in different regimes who want one measure across all of them
  • Boards that want a posture, a tier and a plan before choosing a certification route

Organisations already in a regime

Who want the foundation under it
  • Public bodies working to the NCSC Cyber Security Baseline Standards
  • NIS2 entities preparing to demonstrate compliance through CyFun
  • Financial entities that want their DORA framework anchored to a recognised standard
  • ISO 27001-certified organisations that want a leadership-level view the certificate does not give
NIST CSF 2.0 — Govern at the centre, with Identify, Protect, Detect, Respond and Recover around it
Govern sits across the other five functions. Which regimes reach you, and which view to lead with, is settled in week one.

The six functions — and what each asks of you

The assessment scores every category under all six functions. Together they describe a complete cybersecurity programme, from board oversight to recovery.

GOVERN

Strategy, policy and oversight

Context, risk strategy and appetite, roles and responsibilities, policy, oversight and supply-chain risk management. Where leadership accountability is measured.

IDENTIFY

Assets, risks and improvement

Asset management, risk assessment, and the improvement processes that learn from incidents, tests and evaluations.

PROTECT

Safeguards

Identity and access control, awareness and training, data security, platform security and technology infrastructure resilience.

DETECT

Finding what is happening

Continuous monitoring and adverse-event analysis — the capability to notice a compromise early, not weeks later.

RESPOND

Acting on an incident

Incident management, analysis, reporting and communication, and mitigation — including the regulatory clocks that now apply.

RECOVER

Restoring and learning

Recovery planning and execution, and recovery communication — restoring services within tolerances and telling stakeholders what happened.

Illustrative current profile against target profile across the six NIST CSF 2.0 functions
The current profile is where you are; the target profile is where leadership agrees you should be. The gap between them is the roadmap.

Most organisations have controls. Few have a posture they can describe.

Firewalls, backups, awareness training and a policy folder are not a posture. A posture is a measured position against a recognised framework, a target the leadership has set, and a plan to close the gap. Four weeks is enough to establish all three.

The Cybersecurity Readiness Assessment

Fixed scope. Four weeks. Delivered on the CyberPrism platform with a CRI practitioner guiding your team throughout — so the work is done with you, not to you.

WEEK 1

Onboarding and profile

Establish where you start from
  • Capture business context, obligations and which regimes reach you
  • Identify critical services and assets
  • Inherent risk profile and a first view of the target tier
WEEK 2

Assessment

Measure the current profile
  • Structured working sessions across all six functions — your team answers, we structure
  • Evidence gathered as you go
  • Every category and subcategory declared
WEEK 3

Gap analysis and dashboards

Current profile against target
  • Live dashboards by function, category and tier
  • Target profile agreed with leadership
  • Regulatory views generated — NIS2, DORA, CyFun as relevant
WEEK 4

Board and roadmap

Decide what happens next
  • Executive readiness report delivered
  • Prioritised remediation roadmap to the target tier
  • Board or executive briefing in person
Paul C Dwyer, CEO of Cyber Risk International

"Every regulation we work with is a dialect of NIST CSF. Assess against the framework properly once, and NIS2, DORA and CyFun become views of the same evidence rather than three separate projects."

Paul C Dwyer — CEO, Cyber Risk International; President, ICTTF; author of Cyber Risk Leadership

What you receive

Every deliverable is written for the leadership team that owns the Govern function — and the report is the artefact it signs off.

Context and obligations map

Which regimes, standards and stakeholder expectations apply to you, and which framework view to lead with.

Inherent risk profile

What the organisation relies on, where it is exposed, and what an incident would mean for it.

Current profile and tier

Your position against all six functions and 22 categories, evidenced, with your tier from Partial to Adaptive.

Target profile

The posture your leadership agrees you should hold, set against your risk appetite and obligations.

Executive readiness report

Written for a board, not an IT department. Where you stand, what matters most, and what closing the gap will take.

Prioritised remediation roadmap

Actions ordered by exposure and effort, with owners and timeframes, to move from current to target.

Regulatory views

The same assessment read through NIS2, DORA or CyFun, ready for whichever supervisor asks first.

Board briefing and threat context

A session with your board or executive team, with ThreatLens tying current threat activity to where you are weakest.

The CyberPrism Executive Report — Board Level Digital Resilience Assessment: cover, Digital Resilience Score and function maturity by tier
The Executive Report — Board Level Digital Resilience Assessment, sample pages
INSIDE THE REPORT

What your board will read

  • Executive summary — overall maturity position, key strengths, weaknesses and gaps, areas of concern
  • Digital Resilience Score — a single 0–1000 executive measure of resilience, with the trend since last assessment
  • NIST CSF 2.0 results — the six functions, category by category, and maturity across the four tiers
  • Regulatory alignment — the same evidence read through DORA and NIS2
  • Real-world threat resilience — readiness against eight threat vectors, from spoofing to ransomware
  • Questions for the board — a structured starting point for the oversight conversation
6 functions4 tiersDigital Resilience Score8 threat vectors

Built on CyberPrism

CyberPrism holds your assessment, evidence, dashboards and reports in one place — and keeps them current after the assessment ends, rather than leaving you with a document that dates on the day it is delivered.

NIST CSF 2.0 is CyberPrism's native structure. Every regulatory module — NIS2, DORA, CyFun, the EU AI Act, UK operational resilience, JFSA — is an overlay on the same declarations, which is why one assessment can produce every view without a second questionnaire.

NIST CSF 2.0CyFunNIS2DORAEU AI ActThreatLens
NIST CSF 2.0 readiness dashboard with function maturity, tier distribution and gap analysis
NIST CSF 2.0 — the six functions scored across four implementation tiers.Click to enlarge

After the four weeks

The assessment ends with a decision, not a filing cabinet. Most organisations choose one of two paths.

CONTINUOUS ASSURANCE

Keep your CyberPrism environment live. Track remediation toward the target tier, re-assess quarterly, receive ongoing threat intelligence, and give your board a standing view — with NIS2, DORA or CyFun reporting switched on the day it is needed.

DELIVER IT YOURSELVES

Take the report and roadmap and work through it with your own team or existing providers. Nothing in the assessment ties you to CRI, and the roadmap is written so it can be handed to whoever will deliver it.

NIST CSF 2.0 tiers — Partial, Risk Informed, Repeatable, Adaptive
A posture is something a board maintains, not something it receives once.

Common questions

NIST is an American framework. Why use it in Ireland?

Because the Irish and EU regimes already do. CyFun, which the NCSC prefers for demonstrating NIS2 compliance, is built on NIST CSF. The NCSC's Cyber Security Baseline Standards for public bodies are based on it. DORA's ICT risk framework follows its identify-protect-detect-respond-recover structure. Assessing against CSF 2.0 is assessing against the common denominator.

We are ISO 27001 certified. What does this add?

ISO 27001 certifies that a management system exists and is operated. CSF 2.0 measures the outcomes that system produces, function by function, and gives leadership a tier and a target it can reason about. The two are complementary, and the assessment credits your certification wherever it applies.

Should we do this, or the NIS2 or DORA assessment?

If a specific regulation clearly reaches you and a supervisor will ask about it, start with that assessment — the CSF 2.0 baseline comes with it. If you are not yet sure which regime applies, want one measure across a group, or want a posture before choosing a route, start here. Either way the evidence is the same, so nothing is wasted if you move from one to the other.

How much of our team's time does it take?

Typically two to three hours a week from a coordinator, plus one short session each with the people who own the relevant areas — IT, operations, HR, procurement, legal. Our practitioner does the structuring, mapping and analysis so your team is answering questions, not writing reports. Four weeks works because the platform holds the framework; nobody is building spreadsheets.

Is this an audit?

No. It is a readiness assessment, designed to give you an accurate position and a plan. Where independent validation is required, CRI's Independent Validation Assessment is a separate engagement, and the readiness assessment gives it a well-organised evidence base to work from.

What does it cost?

The programme is fixed-price for a defined scope, which is confirmed on the scoping call. We will not sell you a longer engagement than you need.

What if four weeks is not enough for us?

Four weeks suits most organisations with a single legal entity and a coordinator who can give it a few hours a week. Larger groups or multi-site operators may need longer, and the programme can be extended by agreement at scoping or during week one. The scope, timetable and price are settled before work starts, so an extension is never a surprise.

Know your posture before someone else measures it.

A 30-minute scoping call is enough to confirm which regimes reach you, what the four weeks would cover, and when it could start.

Book a scoping call
CRI partner with eir business
Prefer to talk? Call +353 (0)1 905 3260.