The NIST Cybersecurity Framework (CSF) has become the default way most organisations structure their security programme — including a growing number of South African enterprises. CSF 2.0 added Govern as a sixth function, sharpening the link between strategic oversight and operational execution. This article walks through how to implement the framework in practice, how it interacts with POPIA and ISO 27001, and what a credible implementation actually delivers.
The short answer
Implementing NIST CSF 2.0 follows four steps: define the Target Profile aligned to business and regulatory drivers, assess the Current Profile across the six functions, map gaps against the 23 categories and over 100 subcategories, and execute a sequenced improvement programme tied to outcome metrics. Most organisations integrate it with ISO 27001 and POPIA controls rather than running in parallel.
NIST CSF increasingly supports board reporting, cyber insurance reviews, procurement assurance, operational resilience planning, and executive oversight of cyber risk.
The six functions — Govern, Identify, Protect, Detect, Respond, Recover
CSF 2.0 organises cybersecurity outcomes into six functions. Govern sets strategy and oversight. Identify catalogues, assets, risks, and dependencies. Protect implements controls. Detect surfaces that get through. Responds, contains, eradicates, and communicates. Recover restores operations and learns from the incident. The functions are interdependent — weakness in one creates cost in another.
Define a Target Profile before assessing the Current Profile
Implementation starts with the Target Profile — the outcomes the organisation needs to achieve, scaled to its sector, risk appetite, and regulatory environment. Defining the Target first prevents an implementation that simply assesses everything and produces no priorities. Target Profile statements are written at the category and subcategory level, with informative references to ISO 27001, NIST 800-53, and sector frameworks.
Subcategory mapping — where the real work is
CSF 2.0 has six functions, 23 categories, and over 100 subcategories. Subcategories are the operational unit — each one is a specific outcome (“PR.AA-01: Identities and credentials are issued, managed, verified, revoked, and audited for authorised devices, users, and services”). Subcategory-level mapping produces gap analyses fine-grained enough to be actioned; category-only mapping rarely is.
Tiering — the maturity layer most implementations skip
The NIST CSF defines four Implementation Tiers — Partial, Risk-Informed, Repeatable, and Adaptive — that describe how the organisation manages cybersecurity risk. Tiering is not a maturity score, but it does describe operating discipline. Many implementations skip it; doing so misses an opportunity to communicate posture to the board in a way that connects outcomes to the operating model.
Measuring CSF programme progress
A NIST CSF implementation only becomes meaningful when leadership can measure whether security outcomes are improving over time. Mature programmes track operational, governance, and resilience metrics to demonstrate whether risk-reduction activities translate into measurable capability improvements across the six functions.
Examples commonly tracked include:
- Mean time to detect (MTTD) and mean time to contain (MTTC) security incidents
- MFA coverage across privileged, remote-access, and business-critical accounts
- Patch and vulnerability remediation compliance against defined SLA targets
- Risk-treatment progress against the organisation’s prioritised remediation roadmap
- Phishing reporting rates and user-behaviour improvement trends
- Critical asset visibility and monitoring coverage across cloud, SaaS, and internal environments
These metrics help leadership evaluate whether cybersecurity investment is improving operational resilience, governance maturity, and incident readiness over time rather than simply increasing tooling spend.
Mature CSF implementations increasingly integrate supplier and SaaS risk visibility into the Govern and Identify functions through continuous third-party risk monitoring.
Integrating with ISO 27001 and POPIA
NIST CSF is a framework for structuring the programme; ISO 27001 is a certifiable management system; POPIA is a legal regime. Mature organisations integrate them — CSF subcategories map to ISO 27001 Annex A controls and POPIA Section 19 safeguards, producing a single body of evidence that satisfies multiple stakeholders. Running them as separate programmes creates duplicate work and inconsistent reporting.
Key Takeaways
- CSF 2.0 has six functions — Govern is the new addition, sharpening the strategic-to-operational link.
- Target Profile is defined first; Current Profile is assessed against it. Order matters.
- Subcategory-level mapping (100+ subcategories) is what produces actionable gap analyses.
- Implementation Tiers describe operating discipline — useful for board communication.
- Integrate NIST CSF with ISO 27001 and POPIA — running them separately duplicates evidence and creates inconsistency.
How Cyber Resilience Can Help
Cyber Resilience helps organisations implement NIST CSF 2.0 through structured profile mapping, governance alignment, and operational improvement programmes integrated with ISO 27001 and POPIA requirements.
Speak to our team to arrange a NIST CSF readiness discussion.
