40 / 63NIST Cybersecurity Framework

NIST Cybersecurity Framework, and the Govern function everyone skips

NIST Cybersecurity Framework for Canadian organisations, starting with the Function CSF 2.0 put at the centre.

  • CCIE Security-led assessments
  • CSF 2.0, Govern included
  • Canadian obligations mapped alongside
THE WORK

NIST Cybersecurity Framework, three pillars, one operator.

One Canadian team scores where you are, agrees where you're going, and prices the distance. A NIST CSF assessment here ends in a current profile, a target profile and the ordered gap between them.

  1. 1

    Current profile, scored

    Every Function and Category rated on evidence we saw working, not on a questionnaire somebody filled in. The score sits beside the evidence that earned it, which is what makes a CSF profile still worth reading six months later.

  2. 2

    Govern, the missing one

    Strategy, roles, policy and risk decisions. NIST CSF 2.0 moved the Govern function to the centre of the wheel when it landed in February 2024, and most programmes we assess still name five Functions and no policy owner.

  3. 3

    Target profile, costed

    Where you need to be, what getting there costs, and which order to buy it in. We set CSF tiers per outcome instead of defaulting every category to the top, because a target that calls everything critical has decided nothing.

THE PROOF

Built to last. Evidence over promises.

CSF 2.0 turned two in February 2026. Ask most teams to name the cybersecurity framework's Functions and they'll still say five, which tells you exactly which one was never assessed.

IN PRODUCTION

A profile a Canadian board could read.

We'd been told we were at Tier 3 by a firm that never asked for evidence. SMEnode scored us on what they could see and half the Protect categories dropped. The uncomfortable part was Govern, where we had no policy owner at all. That became the first thing we fixed.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

NIST Cybersecurity Framework in Canada, made real.

The framework isn't the hard part. Deciding what good enough means for your business is the hard part.

Profiles and tiers, not a checklist of controls.

The CSF is a taxonomy of outcomes rather than a checklist of controls, and that distinction decides whether an assessment is useful. You build a current profile describing what you actually do, a target profile describing what your risk appetite and your customers require, and the gap between them is the plan. CSF tiers describe how systematic your risk management is, not how much technology you own. A NIST CSF assessment that hands you a score without a target profile has given you a number and no decision.

Why we score on evidence, and where this goes wrong.

We score on evidence rather than on a questionnaire, because self-assessment inflates reliably and in one direction. The risk sits in two places. Setting a target profile at the highest tier everywhere, which is unaffordable and nobody needs. And treating the Govern function as paperwork, when it's where the decisions live: who owns risk, what the appetite is, which policies bind, and how suppliers get held to them.

The CSF is voluntary, and that's the useful part.

One thing to be plain about in a Canadian context. The CSF is voluntary and it comes from a United States agency, so it isn't what makes you compliant here. What binds you is Canadian law, and this cybersecurity framework is the map you organise the work on rather than the requirement itself. That's a strength, not a caveat: one CSF profile can carry your legal obligations, your customer questionnaires and your insurer's questions at the same time, which is cheaper than running three programmes.

Control checklist
THE METHOD

How our NIST CSF assessment and CSF profile work runs.

Four steps, and step 02 is where the conversation gets useful. Scoring a current profile is mechanical once you insist on evidence. Agreeing the target is a business decision, and it's the one most assessments skip by defaulting every category to the top tier. We push the other way, asking which outcomes actually matter to your risk, your customers and your regulators, because a target profile that calls everything critical has decided nothing.

  1. Step 01

    Score the current profile

    Every Function and Category rated against what we can see working, with the evidence recorded next to the score so anybody can check it later.

  2. Step 02

    Agree the target profile

    Which outcomes matter, to what tier, and why. A business conversation with your risk owners, not a questionnaire sent round for comment.

  3. Step 03

    Cost the gap

    What closing each gap takes in tooling, effort and time, ordered so the cheapest risk reductions land first.

  4. Step 04

    Wire in Govern

    Named owners, a policy set that matches practice, risk appetite written down, and a review cadence that survives a quarter without us.

QUESTIONS

NIST Cybersecurity Framework questions, answered straight.

Answers first, including the one where we tell you a different framework suits you better. An architect takes the call.

Not by NIST, and the distinction matters when someone sells you one. NIST publishes the framework and certifies nobody against it. Two other things do exist: personal credentials for practitioners, listed in CISA's NICCS catalogue, and third-party conformity schemes run by private accreditation bodies. Neither is a NIST certificate. If a customer contract demands a certificate, you probably need a certifiable standard instead, and we'll say which.

Different tools, and the answer usually comes from who's asking. ISO 27001 certifies a management system, so it satisfies a customer or a tender that wants a certificate on file. The CSF gives you a shared vocabulary for outcomes and a profile you can argue about with your board, with no certificate at the end. Many organisations run the CSF to decide what to do, then certify later if a contract requires it.

No, and anyone implying otherwise is selling you comfort. The framework is voluntary guidance from a US agency. Your actual obligations come from Canadian law, sector regulation and your contracts, and PIPEDA is a common starting point. What the CSF does well is give those obligations one structure to sit in, so you build a control once and point three different audiences at it. We map your real obligations onto the profile as part of the work.

Govern arrived as a Function and sits at the centre of the others, which reframes the framework around decisions rather than activities. Scope widened past critical infrastructure to any organisation, and supply chain expectations got sharper. You don't redo the work. Your existing Identify through Recover assessment largely maps across, and the honest gap for most teams is that Govern was never assessed at all.

When a contract demands a certificate, because the CSF doesn't produce one. When you already run a mature ISO management system, since a second framework adds vocabulary and not much else. And when nobody senior will sit through the target profile conversation, because without that the assessment becomes a score in a slide deck. We'd rather tell you than take the engagement.

Whoever can decide, plus whoever can sign. In practice that's the person who carries risk for the business, someone from legal or privacy, whoever answers customer security questionnaires, and your senior technology lead. Govern is the Function that needs that room, because named owners, risk appetite and policy scope aren't technical calls. Get them in one session and the target profile takes an afternoon.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.