NIST & CIS

ISO 27001 vs NIST CSF 2.0: differences, overlap and when to use both

One is a certifiable management system standard, the other a free framework of outcomes with no certificate. Here is how they differ, where they overlap and how one control set can serve both.

Short answer

ISO 27001 vs NIST CSF 2.0 comes down to proof against guidance. ISO/IEC 27001:2022 is a certifiable standard for an information security management system, audited by an accredited body. NIST CSF 2.0 is a free, voluntary framework of outcomes with no certificate. They overlap heavily, so most teams map one control set to both.

Key takeaways

  • ISO 27001 ends in a certificate; NIST CSF ends in a self-assessed Profile and Tier.
  • ISO 27001:2022 has 93 Annex A controls; NIST CSF 2.0 has 6 functions, 22 categories and 106 subcategories.
  • NIST CSF has no controls of its own: each subcategory points to other sources, ISO 27001 among them.
  • An ISO 27001 ISMS covers most CSF outcomes, so one control set can serve both.

The short version

ISO/IEC 27001 sets requirements. It says what an information security management system (ISMS) shall do, from understanding context and assessing risk to internal audit and management review, and an accredited certification body audits you against it. The NIST Cybersecurity Framework describes outcomes. It says what good looks like across six functions and leaves the method to you. Nobody certifies you against it.

ISO 27001NIST CSF 2.0
What it isRequirements for an information security management systemA framework of cybersecurity outcomes
Current versionISO/IEC 27001:2022, with Amendment 1:2024CSF 2.0, published 26 February 2024
Published byISO and IECNIST, US Department of Commerce
Cost of the textPaid standardFree to download
StructureClauses 4 to 10, plus 93 Annex A controls in 4 themes6 functions, 22 categories, 106 subcategories
CertificationYes, by an accredited certification bodyNone
How you show progressCertificate, Statement of Applicability, audit reportsCurrent and Target Profiles, and Tiers 1 to 4
Audit cycleThree years, with a surveillance audit each yearSelf-assessed; no fixed cycle
Best known inWorldwideUnited States, and growing elsewhere

How the two are built

ISO 27001 has two layers. Clauses 4 to 10 are the management system: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A then lists 93 controls in four themes (organisational, people, physical and technological). You choose the controls that your risk assessment calls for and record the choice in a Statement of Applicability.

NIST CSF 2.0 is a tree of outcomes. Six functions (Govern, Identify, Protect, Detect, Respond and Recover) break down into 22 categories and 106 subcategories. Each subcategory is a result, such as "identities and credentials for authorized users, services, and hardware are managed". The framework gives no control text. It lists informative references that show where to find controls, including ISO/IEC 27001.

What changed with CSF 2.0

Version 2.0 added the Govern function, which covers organisational context, risk management strategy, roles, policy, oversight and cybersecurity supply chain risk. That moved CSF closer to ISO 27001, whose clauses 4 to 6 have always covered the same ground. CSF 2.0 also dropped its focus on critical infrastructure and is now written for any organisation.

Where ISO 27001 and NIST CSF overlap

Each CSF function has a natural home in ISO 27001. The rows below are indicative and at category level. NIST publishes official informative references that map CSF 2.0 to ISO/IEC 27001:2022; use those for a formal mapping.

NIST CSF 2.0ISO 27001:2022
  1. GVGovernClauses 4–6, A.5.1, A.5.2Context, leadership, planning, policies and roles
  2. GV.SCSupply chain riskA.5.19–A.5.22Supplier relationships
  3. ID.AMAsset managementA.5.9Inventory of information and assets
  4. ID.RARisk assessmentClauses 6.1.2 and 8.2Information security risk assessment
  5. PR.AAIdentity and accessA.5.15–A.5.18Access control and access rights
  6. PR.ATAwareness and trainingA.6.3Awareness, education and training
  7. PR.DSData securityA.8.13, A.8.24Backup and use of cryptography
  8. DE.CMContinuous monitoringA.8.15, A.8.16Logging and monitoring activities
  9. RS.MAIncident managementA.5.24–A.5.28Incident planning, response and evidence
  10. RC.RPRecovery plan executionA.5.29, A.5.30Security during disruption and ICT readiness
Full mappingPartial mappingIndicative mapping. Check each row against NIST's informative references before relying on it.

Which should you choose?

Choose ISO 27001 first when customers or tenders ask for a certificate, when you sell outside the United States, or when you want an independent audit every year. Choose NIST CSF first when you need a common language for the board and for US customers and regulators, or when you want to measure maturity before committing to certification.

Many organisations use both: ISO 27001 for proof and CSF Profiles for reporting. If you already hold ISO 27001 and a US customer asks how you align to CSF, build a Current Profile from your Statement of Applicability instead of starting again.

Checklist

Using one control set for both

0 of 6 done

A CSF Tier describes how risk is managed, from Tier 1 (Partial) to Tier 4 (Adaptive). It is not a maturity score for individual controls and it is not a certification level.

Put this into practice on QULDEX

Frequently asked questions

Is NIST CSF the same as ISO 27001?

No. ISO 27001 is a certifiable management system standard. NIST CSF 2.0 is a voluntary framework of outcomes with no certificate.

Can you be certified to NIST CSF?

No. NIST does not offer or recognise a CSF certification. Organisations assess themselves using Profiles and Tiers.

Does ISO 27001 cover NIST CSF?

Largely. An ISO 27001 ISMS addresses most CSF outcomes, and NIST publishes informative references that map the two. Build a CSF Profile to find any gaps.

How many controls do ISO 27001 and NIST CSF have?

ISO 27001:2022 has 93 Annex A controls. NIST CSF 2.0 has 106 subcategories, which are outcomes, not controls.

Which is better for a small company, ISO 27001 or NIST CSF?

If customers ask for proof, ISO 27001. If you need a structured starting point and the text at no cost, NIST CSF.

Sources

  1. ISO/IEC 27001:2022 Information security management systems, ISO
  2. The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29), NIST
  3. NIST Cybersecurity Framework, NIST
  4. NIST informative references, NIST