A fixed-scope, four-week assessment of your cybersecurity programme against NIST Cybersecurity Framework 2.0 — the baseline behind NIS2, DORA, CyFun and Ireland's public-sector standards. You leave with a current profile, a target profile, a tier, and a roadmap your board can act on.
CSF 2.0 opens with a new function, Govern: the organisation's cybersecurity risk management strategy, expectations and policy are "established, communicated, and monitored." Every other function depends on it — and it belongs to leadership, not IT.
Quoted phrase from the Govern function of the NIST Cybersecurity Framework 2.0 (February 2024). CyFun and the NCSC's public-sector baseline standards are both built on the NIST framework.
NIS2, DORA, CyFun, ISO 27001 and Ireland's public-sector Cyber Security Baseline Standards all describe the same underlying capabilities. NIST CSF 2.0 is the common language — assess against it once, and every regulatory view follows.
The first major revision in a decade. It broadened the framework from critical infrastructure to every organisation, of any size and sector, and added a governance function.
Govern is new in 2.0 and sits across the other five. It is where board accountability, risk appetite, supply-chain policy and oversight live — the material regulators now examine first.
Tiers describe how rigorously an organisation manages cyber risk. The assessment places you on a tier, agrees the tier you should be at, and shows the gap between the two.
The question every leadership team should be able to answer is not "are we compliant" but "what is our posture, what should it be, and what will it take to get there."
CSF 2.0's current profile, target profile and tiers exist precisely to answer that in terms a board can use.The Govern function sets out what an organisation's leadership is responsible for. It reads very like Article 20 of NIS2 and Article 5 of DORA, which is no accident — both were written with it in view.
Under the Govern function, leadership is expected to establish and oversee:
In Ireland, the NCSC's guidance for boards, the CyFun framework it prefers for NIS2, and the Cyber Security Baseline Standards for public bodies all use the NIST structure. A CSF 2.0 assessment is therefore the one that translates into whichever regime reaches you next.
CSF 2.0 is written for every organisation, not a sector. In practice, three groups get the most from a framework-first assessment.
The assessment scores every category under all six functions. Together they describe a complete cybersecurity programme, from board oversight to recovery.
Context, risk strategy and appetite, roles and responsibilities, policy, oversight and supply-chain risk management. Where leadership accountability is measured.
Asset management, risk assessment, and the improvement processes that learn from incidents, tests and evaluations.
Identity and access control, awareness and training, data security, platform security and technology infrastructure resilience.
Continuous monitoring and adverse-event analysis — the capability to notice a compromise early, not weeks later.
Incident management, analysis, reporting and communication, and mitigation — including the regulatory clocks that now apply.
Recovery planning and execution, and recovery communication — restoring services within tolerances and telling stakeholders what happened.
Firewalls, backups, awareness training and a policy folder are not a posture. A posture is a measured position against a recognised framework, a target the leadership has set, and a plan to close the gap. Four weeks is enough to establish all three.
Fixed scope. Four weeks. Delivered on the CyberPrism platform with a CRI practitioner guiding your team throughout — so the work is done with you, not to you.
"Every regulation we work with is a dialect of NIST CSF. Assess against the framework properly once, and NIS2, DORA and CyFun become views of the same evidence rather than three separate projects."
Paul C Dwyer — CEO, Cyber Risk International; President, ICTTF; author of Cyber Risk LeadershipEvery deliverable is written for the leadership team that owns the Govern function — and the report is the artefact it signs off.
Which regimes, standards and stakeholder expectations apply to you, and which framework view to lead with.
What the organisation relies on, where it is exposed, and what an incident would mean for it.
Your position against all six functions and 22 categories, evidenced, with your tier from Partial to Adaptive.
The posture your leadership agrees you should hold, set against your risk appetite and obligations.
Written for a board, not an IT department. Where you stand, what matters most, and what closing the gap will take.
Actions ordered by exposure and effort, with owners and timeframes, to move from current to target.
The same assessment read through NIS2, DORA or CyFun, ready for whichever supervisor asks first.
A session with your board or executive team, with ThreatLens tying current threat activity to where you are weakest.
CyberPrism holds your assessment, evidence, dashboards and reports in one place — and keeps them current after the assessment ends, rather than leaving you with a document that dates on the day it is delivered.
NIST CSF 2.0 is CyberPrism's native structure. Every regulatory module — NIS2, DORA, CyFun, the EU AI Act, UK operational resilience, JFSA — is an overlay on the same declarations, which is why one assessment can produce every view without a second questionnaire.
The assessment ends with a decision, not a filing cabinet. Most organisations choose one of two paths.
Keep your CyberPrism environment live. Track remediation toward the target tier, re-assess quarterly, receive ongoing threat intelligence, and give your board a standing view — with NIS2, DORA or CyFun reporting switched on the day it is needed.
Take the report and roadmap and work through it with your own team or existing providers. Nothing in the assessment ties you to CRI, and the roadmap is written so it can be handed to whoever will deliver it.
Because the Irish and EU regimes already do. CyFun, which the NCSC prefers for demonstrating NIS2 compliance, is built on NIST CSF. The NCSC's Cyber Security Baseline Standards for public bodies are based on it. DORA's ICT risk framework follows its identify-protect-detect-respond-recover structure. Assessing against CSF 2.0 is assessing against the common denominator.
ISO 27001 certifies that a management system exists and is operated. CSF 2.0 measures the outcomes that system produces, function by function, and gives leadership a tier and a target it can reason about. The two are complementary, and the assessment credits your certification wherever it applies.
If a specific regulation clearly reaches you and a supervisor will ask about it, start with that assessment — the CSF 2.0 baseline comes with it. If you are not yet sure which regime applies, want one measure across a group, or want a posture before choosing a route, start here. Either way the evidence is the same, so nothing is wasted if you move from one to the other.
Typically two to three hours a week from a coordinator, plus one short session each with the people who own the relevant areas — IT, operations, HR, procurement, legal. Our practitioner does the structuring, mapping and analysis so your team is answering questions, not writing reports. Four weeks works because the platform holds the framework; nobody is building spreadsheets.
No. It is a readiness assessment, designed to give you an accurate position and a plan. Where independent validation is required, CRI's Independent Validation Assessment is a separate engagement, and the readiness assessment gives it a well-organised evidence base to work from.
The programme is fixed-price for a defined scope, which is confirmed on the scoping call. We will not sell you a longer engagement than you need.
Four weeks suits most organisations with a single legal entity and a coordinator who can give it a few hours a week. Larger groups or multi-site operators may need longer, and the programme can be extended by agreement at scoping or during week one. The scope, timetable and price are settled before work starts, so an extension is never a surprise.
A 30-minute scoping call is enough to confirm which regimes reach you, what the four weeks would cover, and when it could start.