NIST CSF: find out where you stand without committing to certification.
CSF 2.0 is a taxonomy of security outcomes rather than a control list, and NIST states it is for any organisation regardless of size, sector or maturity. That makes it the most useful way to get an honest picture before you decide whether ISO 27001 or anything else is worth pursuing.

- CSF 2.0Current since February 2024
- 6 FunctionsGovern was added in 2.0
- No certificateAssessment, not certification
- Any organisationNot critical infrastructure only
Eight things to understand before using it.
A taxonomy of outcomes, not a set of controls
NIST states plainly that the framework does not prescribe how outcomes should be achieved. It describes what good looks like and links to other resources for how. This is why CSF works alongside ISO 27001, sector regulation and your existing controls rather than competing with them, and it is also why a provider who hands you a CSF control checklist has misunderstood the document.
For any organisation, regardless of size, sector or maturity
The 2.0 abstract says exactly that. Earlier versions were positioned around critical infrastructure, which is why many UAE businesses filed it as not applicable to them. That framing is gone. A forty-person professional services firm can use CSF as sensibly as a utility, and the outcome language is deliberately readable by people who are not security specialists.
Govern, the Function added in 2.0
GOVERN covers the organisation cybersecurity risk management strategy, expectations and policy being established, communicated and monitored, and NIST positions it as informing and prioritising the outcomes of the other five Functions. Its addition is the single biggest change in 2.0 and it reflects what actually goes wrong in most organisations, which is not a missing control but an absent decision.
The six Functions, and what each is for
GOVERN sets strategy, roles, policy and supply chain risk management. IDENTIFY establishes understanding of your assets, suppliers and risks. PROTECT applies safeguards. DETECT finds what is happening. RESPOND acts on it. RECOVER restores operations. Reading them in that order is itself instructive, because most organisations have invested heavily in the middle and very little at either end.
Current Profile, the honest picture of today
A Current Profile specifies the outcomes you are currently achieving, or attempting to achieve, and characterises how well. The value is entirely in its honesty. A Current Profile that reflects what people wish were true is worthless, and getting an accurate one usually requires talking to the engineers and administrators rather than only to management.
Target Profile, and the gap between them
A Target Profile specifies the outcomes you have selected and prioritised, taking account of anticipated changes such as new requirements or new technology. NIST documented approach is then to analyse the gaps between Current and Target and produce a prioritised action plan. That gap analysis is the actual deliverable, and it is what makes CSF useful rather than academic.
Community Profiles, so you are not starting blank
A Community Profile is a published baseline of CSF outcomes addressing a shared set of circumstances, and NIST explicitly suggests using one as the basis for your Target Profile. For a UAE organisation this is a practical shortcut: rather than deciding every target outcome from first principles, start from a relevant published baseline and adjust it for your context.
Tiers describe rigour, they are not a score to climb
CSF Tiers characterise the rigour of your cybersecurity risk governance and management practices. They are frequently misused as a maturity ladder, with organisations declaring a target Tier the way they might target a certification level. That is not what they are for, and chasing a Tier for its own sake produces exactly the box-ticking the framework was designed to avoid.
CSF tells you where you stand before you spend anything.
The most common sequencing error we see in the UAE is committing to a certification programme before anybody has established what the actual security position is. CSF is the cheap, fast way to find out.
- There is no certificate, no accredited body, no audit fee and no annual surveillance. That is a feature. It means an assessment can be scoped to what is useful rather than to what an assessor will sample, and it means you can be honest in it, which you cannot always be in an audit.
- It produces a comparable picture across the whole security function, from governance through to recovery, rather than a control list. That breadth is what makes it a good basis for a board conversation and for deciding what to fund next, because the gaps show up in the Functions people rarely look at.
- It maps onto whatever comes next. If you subsequently pursue ISO 27001, most of the understanding transfers directly, and the same is true for UAE sector obligations. Doing CSF first almost never wastes work, whereas starting a certification programme without knowing your position frequently does.
- It is also the right answer for organisations that will never certify. Plenty of UAE businesses have no customer or regulator asking for a certificate and still need to know whether they are exposed. For them CSF gives a defensible, structured answer without the recurring cost of a certification cycle.
Four things that make the picture worth having.
We talk to the people who know, not only to management
The accurate answer about whether alerts get reviewed, whether patching actually happens on schedule and whether that runbook has ever been used lives with the engineers and administrators. We interview them, with the understanding that the assessment is not about individual performance. Assessments built only from management interviews are consistently and predictably optimistic.
We assess outcomes, not our own product list
NIST is explicit that the framework does not prescribe how outcomes are achieved, and we hold to that. If you already achieve an outcome with a tool we do not sell, or with a manual process that works, that is an achieved outcome. An assessment that concludes you need to buy the assessor product set is not an assessment.
We produce something a board can actually read
The six Functions are unusually good at communicating a security position to non-specialists, because the language is about outcomes rather than technology. We use that deliberately: the output is a picture of where you stand across all six, a prioritised gap plan, and a short set of decisions to be taken, rather than a spreadsheet of findings.
We make it repeatable so the second one is comparable
A single CSF assessment tells you where you are. Two, done the same way a year apart, tell you whether anything is improving, which is a far more useful thing to put in front of a board. We document the method and the basis for each judgement so the reassessment measures change rather than measuring a different assessor opinions.
Six situations where we would recommend it over anything else.
A new leader who needs an honest baseline
A new chief executive, chief operating officer or IT director inherits a security position they had no part in creating and needs to know what they have taken on. CSF gives a structured, defensible picture quickly, without the political charge of an audit, and it gives them something concrete to take to the board in their first quarter.
A business deciding whether to pursue certification
The right sequencing, and the one most often skipped. Establish your position first, then decide whether ISO 27001 or SOC 2 is worth the commitment. Organisations that commit first frequently discover mid-programme that the gap is much larger than assumed, at which point the budget is already spent and the timeline is already promised to a customer.
A regulated firm wanting a view beyond the regulation
Sector obligations tell you what you must do, which is not the same as telling you where you are exposed. DIFC and ADGM firms frequently find that a CSF assessment surfaces real risks their regulatory compliance work never looks at, particularly in RECOVER and in supply chain, and that is a useful complement rather than a duplication.
An organisation with operational technology
Manufacturing, logistics, utilities, facilities. CSF handles the breadth of a mixed IT and operational environment better than frameworks written for corporate systems alone, because it is expressed as outcomes rather than as controls that assume a particular kind of network. It is also a common language for teams who do not usually work together.
A business that will never certify and still needs to know
No customer asking, no regulator applying, no tender requiring it, and a genuine need to understand exposure. For these organisations certification would be an expensive answer to a question nobody asked, and CSF gives them the substance without the certificate and without the recurring commitment.
A group wanting one comparable view across entities
Several businesses, several IT setups, several inherited arrangements, and no consistent picture. Assessing each against the same framework produces something genuinely comparable, which is what makes it possible to decide where group investment should go rather than funding whichever entity argues most persuasively.
The shape we find most often in UAE organisations.
| Feature | Balanced across Functions | Protect-heavy, the usual shape |
|---|---|---|
GOVERN, named accountability and risk appetite | Established | Absent or implicit |
IDENTIFY, accurate asset and supplier picture | Maintained | Partial and stale |
PROTECT, safeguards deployed | Proportionate | Heavily invested |
DETECT, somebody reads what is collected | Yes | Collected, rarely reviewed |
RESPOND, plan rehearsed with leadership | Yes | Written, never exercised |
RECOVER, restores tested against real objectives | Yes | Backups assumed to work |
Improvement loop after incidents | Closed | Open |
Spend sequenced by risk | Yes | By vendor and opportunity |
Board can see the whole picture | Yes | Only the tooling |
Frequency in the UAE market | Uncommon | The default |
What each one is for, and when to use which.
| NIST CSF 2.0 | ISO 27001 | UAE sector standards | |
|---|---|---|---|
| What it produces | A picture and a plan | A certificate | Regulatory compliance |
| Independent body required | No | Yes, accredited | Sector regulator |
| Recurring cost | Only if you reassess | Annual surveillance | Ongoing obligation |
| Prescribes controls | No, outcomes only | Annex A reference set | Yes, often specifically |
| Covers governance explicitly | Yes, the GOVERN Function | Yes, clauses 4 to 10 | Varies |
| Useful before you know your position | Ideal | Premature | Not optional |
| Satisfies a customer questionnaire | Partially, with evidence | Yes | Sector dependent |
| Optional | Yes | Yes | No |
| Work transfers to the others | Substantially | Substantially | Substantially |
| Good board communication tool | Strongest of the three | Moderate | Compliance framing |
Five stages, typically three to six weeks.
- 1
Scope it, and pick a starting baseline
Which entities, systems and operations are in scope, and whether a published Community Profile provides a sensible basis for your Target Profile. NIST explicitly suggests starting from one where a relevant baseline exists, which saves deciding every target outcome from first principles.
- 2
Build the Current Profile honestly
Interviews across the organisation, evidence review and technical checks, covering all six Functions. We deliberately include the people who operate the systems, because the difference between the documented process and the practised one is where most of the useful findings are, and management usually reports the documented one in good faith.
- 3
Agree the Target Profile with leadership
Which outcomes matter to you, prioritised against your mission, your obligations and anticipated changes. This is a business conversation. Not every outcome needs to be achieved, and deciding deliberately which ones do not is a legitimate result rather than a gap.
- 4
Analyse the gaps and prioritise
The difference between Current and Target, turned into a prioritised action plan with owners, effort and sequence. Prioritisation is by risk reduction per unit of effort rather than by Function order, which usually means unglamorous work in GOVERN and IDENTIFY comes before anything anyone wants to buy.
- 5
Report, then reassess on a cadence
A board-readable picture across the six Functions, a prioritised plan, and a documented basis for every judgement so the next assessment is comparable. We would usually suggest reassessing annually, or after any significant change, so that the second assessment measures progress rather than restating opinions.
“We had spent three years and a lot of money on detection tooling. The assessment showed we were strong in the middle and had almost nothing at either end, no clear accountability at one side and no tested recovery at the other. It reframed the next two budget cycles entirely.”
What organisations ask about NIST CSF.
Fifteen questions, ordered by the six Functions.
Govern and Identify
- Who is accountable for cyber risk, by name?The GOVERN Function starts here and most gaps do too.
- Is there a written statement of what risk you accept?Undocumented acceptance is the most common governance gap.
- Do you have a current inventory of systems and data?IDENTIFY depends on it and almost nobody has one that is accurate.
- Do you know which suppliers could hurt you?Supply chain risk is called out explicitly in GOVERN in 2.0.
- Has anybody assessed risk in the last twelve months?Not a scan. An assessment with decisions attached.
Protect and Detect
- Is multi-factor authentication enforced everywhere it should be?Including administrators, third parties and legacy paths.
- Are systems patched on a defined and evidenced cadence?Evidenced is the operative word.
- Do you know what normal looks like on your network?DETECT is impossible without it.
- Is anybody actually reading the alerts?Collection without review is the single most common false comfort.
- Would you notice a compromise that did not announce itself?Most organisations find out from a third party.
Respond and Recover
- Is there an incident response plan somebody has rehearsed?Written is not the same as rehearsed.
- Who decides to disconnect a system, and can you reach them at 2am?A commercial decision that needs deciding in advance.
- Have you restored from backup recently, as a test?Backup success reports prove nothing about restore.
- Do you know your notification obligations before you need them?Federal, sector, contractual and free zone regimes may all apply.
- Does anything you learn from an incident change what you do?RECOVER includes improvement, and it is routinely skipped.
The pages around this one.
IT audit services in Dubai
The wider audit practice, and how to tell which kind of engagement your situation actually calls for before anybody quotes for one.
ISO 27001 certification in the UAE
What to do if the assessment concludes you should certify, including the 2013 edition transition that closed in October 2025.
Virtual CISO in Dubai
If the biggest gaps land in GOVERN, this is the role that closes them: accountability, risk decisions and board reporting.
Find out where you stand before deciding what to spend.
A CSF assessment produces an honest picture across all six Functions, a prioritised plan, and a basis for measuring progress next year. It is also the cheapest way to establish whether a certification programme is worth starting, which is a question worth answering before the budget is committed.
Related Services
Explore more solutions that work great with this service
Active Directory Audit
Privilege paths, service accounts and local admin passwords
DMARC Audit UAE
Stop exact-domain spoofing, and keep your mail delivering
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
Virtual CISO Dubai
Security governance and accountability, not more tools
Cybersecurity Audit
Security assessment and compliance audit
SOC 2 Readiness UAE
Type II preparation, and when ISO 27001 fits better
NESA / IA Compliance
UAE Information Assurance Standards compliance