Short answer
ISO 27001 vs NIST CSF 2.0 comes down to proof against guidance. ISO/IEC 27001:2022 is a certifiable standard for an information security management system, audited by an accredited body. NIST CSF 2.0 is a free, voluntary framework of outcomes with no certificate. They overlap heavily, so most teams map one control set to both.
Key takeaways
- ISO 27001 ends in a certificate; NIST CSF ends in a self-assessed Profile and Tier.
- ISO 27001:2022 has 93 Annex A controls; NIST CSF 2.0 has 6 functions, 22 categories and 106 subcategories.
- NIST CSF has no controls of its own: each subcategory points to other sources, ISO 27001 among them.
- An ISO 27001 ISMS covers most CSF outcomes, so one control set can serve both.
The short version
ISO/IEC 27001 sets requirements. It says what an information security management system (ISMS) shall do, from understanding context and assessing risk to internal audit and management review, and an accredited certification body audits you against it. The NIST Cybersecurity Framework describes outcomes. It says what good looks like across six functions and leaves the method to you. Nobody certifies you against it.
| ISO 27001 | NIST CSF 2.0 | |
|---|---|---|
| What it is | Requirements for an information security management system | A framework of cybersecurity outcomes |
| Current version | ISO/IEC 27001:2022, with Amendment 1:2024 | CSF 2.0, published 26 February 2024 |
| Published by | ISO and IEC | NIST, US Department of Commerce |
| Cost of the text | Paid standard | Free to download |
| Structure | Clauses 4 to 10, plus 93 Annex A controls in 4 themes | 6 functions, 22 categories, 106 subcategories |
| Certification | Yes, by an accredited certification body | None |
| How you show progress | Certificate, Statement of Applicability, audit reports | Current and Target Profiles, and Tiers 1 to 4 |
| Audit cycle | Three years, with a surveillance audit each year | Self-assessed; no fixed cycle |
| Best known in | Worldwide | United States, and growing elsewhere |
How the two are built
ISO 27001 has two layers. Clauses 4 to 10 are the management system: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A then lists 93 controls in four themes (organisational, people, physical and technological). You choose the controls that your risk assessment calls for and record the choice in a Statement of Applicability.
NIST CSF 2.0 is a tree of outcomes. Six functions (Govern, Identify, Protect, Detect, Respond and Recover) break down into 22 categories and 106 subcategories. Each subcategory is a result, such as "identities and credentials for authorized users, services, and hardware are managed". The framework gives no control text. It lists informative references that show where to find controls, including ISO/IEC 27001.
What changed with CSF 2.0
Version 2.0 added the Govern function, which covers organisational context, risk management strategy, roles, policy, oversight and cybersecurity supply chain risk. That moved CSF closer to ISO 27001, whose clauses 4 to 6 have always covered the same ground. CSF 2.0 also dropped its focus on critical infrastructure and is now written for any organisation.
Where ISO 27001 and NIST CSF overlap
Each CSF function has a natural home in ISO 27001. The rows below are indicative and at category level. NIST publishes official informative references that map CSF 2.0 to ISO/IEC 27001:2022; use those for a formal mapping.
GVGovernClauses 4–6, A.5.1, A.5.2Context, leadership, planning, policies and rolesGV.SCSupply chain riskA.5.19–A.5.22Supplier relationshipsID.AMAsset managementA.5.9Inventory of information and assetsID.RARisk assessmentClauses 6.1.2 and 8.2Information security risk assessmentPR.AAIdentity and accessA.5.15–A.5.18Access control and access rightsPR.ATAwareness and trainingA.6.3Awareness, education and trainingPR.DSData securityA.8.13, A.8.24Backup and use of cryptographyDE.CMContinuous monitoringA.8.15, A.8.16Logging and monitoring activitiesRS.MAIncident managementA.5.24–A.5.28Incident planning, response and evidenceRC.RPRecovery plan executionA.5.29, A.5.30Security during disruption and ICT readiness
Which should you choose?
Choose ISO 27001 first when customers or tenders ask for a certificate, when you sell outside the United States, or when you want an independent audit every year. Choose NIST CSF first when you need a common language for the board and for US customers and regulators, or when you want to measure maturity before committing to certification.
Many organisations use both: ISO 27001 for proof and CSF Profiles for reporting. If you already hold ISO 27001 and a US customer asks how you align to CSF, build a Current Profile from your Statement of Applicability instead of starting again.
Checklist
Using one control set for both
0 of 6 done
A CSF Tier describes how risk is managed, from Tier 1 (Partial) to Tier 4 (Adaptive). It is not a maturity score for individual controls and it is not a certification level.
Put this into practice on QULDEX
Frequently asked questions
Is NIST CSF the same as ISO 27001?
No. ISO 27001 is a certifiable management system standard. NIST CSF 2.0 is a voluntary framework of outcomes with no certificate.
Can you be certified to NIST CSF?
No. NIST does not offer or recognise a CSF certification. Organisations assess themselves using Profiles and Tiers.
Does ISO 27001 cover NIST CSF?
Largely. An ISO 27001 ISMS addresses most CSF outcomes, and NIST publishes informative references that map the two. Build a CSF Profile to find any gaps.
How many controls do ISO 27001 and NIST CSF have?
ISO 27001:2022 has 93 Annex A controls. NIST CSF 2.0 has 106 subcategories, which are outcomes, not controls.
Which is better for a small company, ISO 27001 or NIST CSF?
If customers ask for proof, ISO 27001. If you need a structured starting point and the text at no cost, NIST CSF.