We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. NIST CSF
NIST CSF 2.0 assessment, UAE

NIST CSF: find out where you stand without committing to certification.

CSF 2.0 is a taxonomy of security outcomes rather than a control list, and NIST states it is for any organisation regardless of size, sector or maturity. That makes it the most useful way to get an honest picture before you decide whether ISO 27001 or anything else is worth pursuing.

Book a NIST CSF assessmentSee how it works
NIST Cybersecurity Framework 2.0 assessment for UAE organisations
  • CSF 2.0Current since February 2024
  • 6 FunctionsGovern was added in 2.0
  • No certificateAssessment, not certification
  • Any organisationNot critical infrastructure only
What CSF actually is

Eight things to understand before using it.

Everything here comes from NIST CSWP 29, the CSF 2.0 document published on 26 February 2024, rather than from commentary. The most important thing to grasp early is what CSF is not: it is not a control list, it is not a certification, and it does not tell you how to achieve anything.

A taxonomy of outcomes, not a set of controls

NIST states plainly that the framework does not prescribe how outcomes should be achieved. It describes what good looks like and links to other resources for how. This is why CSF works alongside ISO 27001, sector regulation and your existing controls rather than competing with them, and it is also why a provider who hands you a CSF control checklist has misunderstood the document.

For any organisation, regardless of size, sector or maturity

The 2.0 abstract says exactly that. Earlier versions were positioned around critical infrastructure, which is why many UAE businesses filed it as not applicable to them. That framing is gone. A forty-person professional services firm can use CSF as sensibly as a utility, and the outcome language is deliberately readable by people who are not security specialists.

Govern, the Function added in 2.0

GOVERN covers the organisation cybersecurity risk management strategy, expectations and policy being established, communicated and monitored, and NIST positions it as informing and prioritising the outcomes of the other five Functions. Its addition is the single biggest change in 2.0 and it reflects what actually goes wrong in most organisations, which is not a missing control but an absent decision.

The six Functions, and what each is for

GOVERN sets strategy, roles, policy and supply chain risk management. IDENTIFY establishes understanding of your assets, suppliers and risks. PROTECT applies safeguards. DETECT finds what is happening. RESPOND acts on it. RECOVER restores operations. Reading them in that order is itself instructive, because most organisations have invested heavily in the middle and very little at either end.

Current Profile, the honest picture of today

A Current Profile specifies the outcomes you are currently achieving, or attempting to achieve, and characterises how well. The value is entirely in its honesty. A Current Profile that reflects what people wish were true is worthless, and getting an accurate one usually requires talking to the engineers and administrators rather than only to management.

Target Profile, and the gap between them

A Target Profile specifies the outcomes you have selected and prioritised, taking account of anticipated changes such as new requirements or new technology. NIST documented approach is then to analyse the gaps between Current and Target and produce a prioritised action plan. That gap analysis is the actual deliverable, and it is what makes CSF useful rather than academic.

Community Profiles, so you are not starting blank

A Community Profile is a published baseline of CSF outcomes addressing a shared set of circumstances, and NIST explicitly suggests using one as the basis for your Target Profile. For a UAE organisation this is a practical shortcut: rather than deciding every target outcome from first principles, start from a relevant published baseline and adjust it for your context.

Tiers describe rigour, they are not a score to climb

CSF Tiers characterise the rigour of your cybersecurity risk governance and management practices. They are frequently misused as a maturity ladder, with organisations declaring a target Tier the way they might target a certification level. That is not what they are for, and chasing a Tier for its own sake produces exactly the box-ticking the framework was designed to avoid.

Why this is often the right first engagement

CSF tells you where you stand before you spend anything.

The most common sequencing error we see in the UAE is committing to a certification programme before anybody has established what the actual security position is. CSF is the cheap, fast way to find out.

  • There is no certificate, no accredited body, no audit fee and no annual surveillance. That is a feature. It means an assessment can be scoped to what is useful rather than to what an assessor will sample, and it means you can be honest in it, which you cannot always be in an audit.
  • It produces a comparable picture across the whole security function, from governance through to recovery, rather than a control list. That breadth is what makes it a good basis for a board conversation and for deciding what to fund next, because the gaps show up in the Functions people rarely look at.
  • It maps onto whatever comes next. If you subsequently pursue ISO 27001, most of the understanding transfers directly, and the same is true for UAE sector obligations. Doing CSF first almost never wastes work, whereas starting a certification programme without knowing your position frequently does.
  • It is also the right answer for organisations that will never certify. Plenty of UAE businesses have no customer or regulator asking for a certificate and still need to know whether they are exposed. For them CSF gives a defensible, structured answer without the recurring cost of a certification cycle.
Ask us whether CSF is the right first step
How we run a CSF assessment

Four things that make the picture worth having.

A CSF assessment is only as good as its honesty. Since there is no certificate at the end, there is no external pressure keeping it accurate, which puts the burden entirely on how the assessment is run.

We talk to the people who know, not only to management

The accurate answer about whether alerts get reviewed, whether patching actually happens on schedule and whether that runbook has ever been used lives with the engineers and administrators. We interview them, with the understanding that the assessment is not about individual performance. Assessments built only from management interviews are consistently and predictably optimistic.

We assess outcomes, not our own product list

NIST is explicit that the framework does not prescribe how outcomes are achieved, and we hold to that. If you already achieve an outcome with a tool we do not sell, or with a manual process that works, that is an achieved outcome. An assessment that concludes you need to buy the assessor product set is not an assessment.

We produce something a board can actually read

The six Functions are unusually good at communicating a security position to non-specialists, because the language is about outcomes rather than technology. We use that deliberately: the output is a picture of where you stand across all six, a prioritised gap plan, and a short set of decisions to be taken, rather than a spreadsheet of findings.

We make it repeatable so the second one is comparable

A single CSF assessment tells you where you are. Two, done the same way a year apart, tell you whether anything is improving, which is a far more useful thing to put in front of a board. We document the method and the basis for each judgement so the reassessment measures change rather than measuring a different assessor opinions.

When CSF is the right tool

Six situations where we would recommend it over anything else.

CSF is at its most valuable when the question is what is our actual position, and least valuable when somebody external has already told you exactly what they require.

A new leader who needs an honest baseline

A new chief executive, chief operating officer or IT director inherits a security position they had no part in creating and needs to know what they have taken on. CSF gives a structured, defensible picture quickly, without the political charge of an audit, and it gives them something concrete to take to the board in their first quarter.

A business deciding whether to pursue certification

The right sequencing, and the one most often skipped. Establish your position first, then decide whether ISO 27001 or SOC 2 is worth the commitment. Organisations that commit first frequently discover mid-programme that the gap is much larger than assumed, at which point the budget is already spent and the timeline is already promised to a customer.

A regulated firm wanting a view beyond the regulation

Sector obligations tell you what you must do, which is not the same as telling you where you are exposed. DIFC and ADGM firms frequently find that a CSF assessment surfaces real risks their regulatory compliance work never looks at, particularly in RECOVER and in supply chain, and that is a useful complement rather than a duplication.

An organisation with operational technology

Manufacturing, logistics, utilities, facilities. CSF handles the breadth of a mixed IT and operational environment better than frameworks written for corporate systems alone, because it is expressed as outcomes rather than as controls that assume a particular kind of network. It is also a common language for teams who do not usually work together.

A business that will never certify and still needs to know

No customer asking, no regulator applying, no tender requiring it, and a genuine need to understand exposure. For these organisations certification would be an expensive answer to a question nobody asked, and CSF gives them the substance without the certificate and without the recurring commitment.

A group wanting one comparable view across entities

Several businesses, several IT setups, several inherited arrangements, and no consistent picture. Assessing each against the same framework produces something genuinely comparable, which is what makes it possible to decide where group investment should go rather than funding whichever entity argues most persuasively.

Where organisations sit across the Functions

The shape we find most often in UAE organisations.

This pattern is remarkably consistent. Investment concentrates in PROTECT because that is what vendors sell, while GOVERN at one end and RECOVER at the other are thin, and those are exactly the two that determine what happens when something goes wrong.
GOVERN, named accountability and risk appetite
Balanced across FunctionsEstablished
Protect-heavy, the usual shapeAbsent or implicit
IDENTIFY, accurate asset and supplier picture
Balanced across FunctionsMaintained
Protect-heavy, the usual shapePartial and stale
PROTECT, safeguards deployed
Balanced across FunctionsProportionate
Protect-heavy, the usual shapeHeavily invested
DETECT, somebody reads what is collected
Balanced across FunctionsYes
Protect-heavy, the usual shapeCollected, rarely reviewed
RESPOND, plan rehearsed with leadership
Balanced across FunctionsYes
Protect-heavy, the usual shapeWritten, never exercised
RECOVER, restores tested against real objectives
Balanced across FunctionsYes
Protect-heavy, the usual shapeBackups assumed to work
Improvement loop after incidents
Balanced across FunctionsClosed
Protect-heavy, the usual shapeOpen
Spend sequenced by risk
Balanced across FunctionsYes
Protect-heavy, the usual shapeBy vendor and opportunity
Board can see the whole picture
Balanced across FunctionsYes
Protect-heavy, the usual shapeOnly the tooling
Frequency in the UAE market
Balanced across FunctionsUncommon
Protect-heavy, the usual shapeThe default
Feature
Balanced across Functions
Protect-heavy, the usual shape
GOVERN, named accountability and risk appetite
EstablishedAbsent or implicit
IDENTIFY, accurate asset and supplier picture
MaintainedPartial and stale
PROTECT, safeguards deployed
ProportionateHeavily invested
DETECT, somebody reads what is collected
YesCollected, rarely reviewed
RESPOND, plan rehearsed with leadership
YesWritten, never exercised
RECOVER, restores tested against real objectives
YesBackups assumed to work
Improvement loop after incidents
ClosedOpen
Spend sequenced by risk
YesBy vendor and opportunity
Board can see the whole picture
YesOnly the tooling
Frequency in the UAE market
UncommonThe default
CSF against the certifiable frameworks

What each one is for, and when to use which.

These are not competitors and treating them as alternatives causes bad decisions. CSF tells you where you stand. ISO 27001 and SOC 2 prove something to somebody else. Sector standards are obligations you do not get to choose.
NIST CSF 2.0ISO 27001UAE sector standards
What it producesA picture and a planA certificateRegulatory compliance
Independent body requiredNoYes, accreditedSector regulator
Recurring costOnly if you reassessAnnual surveillanceOngoing obligation
Prescribes controlsNo, outcomes onlyAnnex A reference setYes, often specifically
Covers governance explicitlyYes, the GOVERN FunctionYes, clauses 4 to 10Varies
Useful before you know your positionIdealPrematureNot optional
Satisfies a customer questionnairePartially, with evidenceYesSector dependent
OptionalYesYesNo
Work transfers to the othersSubstantiallySubstantiallySubstantially
Good board communication toolStrongest of the threeModerateCompliance framing
How the assessment runs

Five stages, typically three to six weeks.

The shape follows the approach NIST documents: establish the Current Profile, define a Target Profile, analyse the gaps, and produce a prioritised action plan.
  1. 1

    Scope it, and pick a starting baseline

    Which entities, systems and operations are in scope, and whether a published Community Profile provides a sensible basis for your Target Profile. NIST explicitly suggests starting from one where a relevant baseline exists, which saves deciding every target outcome from first principles.

  2. 2

    Build the Current Profile honestly

    Interviews across the organisation, evidence review and technical checks, covering all six Functions. We deliberately include the people who operate the systems, because the difference between the documented process and the practised one is where most of the useful findings are, and management usually reports the documented one in good faith.

  3. 3

    Agree the Target Profile with leadership

    Which outcomes matter to you, prioritised against your mission, your obligations and anticipated changes. This is a business conversation. Not every outcome needs to be achieved, and deciding deliberately which ones do not is a legitimate result rather than a gap.

  4. 4

    Analyse the gaps and prioritise

    The difference between Current and Target, turned into a prioritised action plan with owners, effort and sequence. Prioritisation is by risk reduction per unit of effort rather than by Function order, which usually means unglamorous work in GOVERN and IDENTIFY comes before anything anyone wants to buy.

  5. 5

    Report, then reassess on a cadence

    A board-readable picture across the six Functions, a prioritised plan, and a documented basis for every judgement so the next assessment is comparable. We would usually suggest reassessing annually, or after any significant change, so that the second assessment measures progress rather than restating opinions.

“We had spent three years and a lot of money on detection tooling. The assessment showed we were strong in the middle and had almost nothing at either end, no clear accountability at one side and no tested recovery at the other. It reframed the next two budget cycles entirely.”
Chief Operating Officer
Logistics group, Dubai · Client reference available on request
Straight answers

What organisations ask about NIST CSF.

CSF 2.0, published on 26 February 2024 as NIST CSWP 29, and NIST confirmed it as current into 2026. The headline change is the addition of GOVERN as a sixth Function, covering cybersecurity strategy, roles, policy, oversight and supply chain risk management. The other significant change is scope: the 2.0 abstract states the framework can be used by any organisation regardless of size, sector or maturity, which removes the critical infrastructure framing that led many UAE businesses to dismiss earlier versions.

No, and that is deliberate rather than a limitation. There is no certification scheme, no accredited body and no certificate. CSF is a framework for understanding and communicating your cybersecurity position. If you need something to show a customer or a regulator, you need ISO 27001, a SOC 2 report, or whatever your sector requires. If you need to know where you actually stand, CSF is better than either, because you can afford to be honest in it.

No. It is published by a United States government agency and it is used internationally as a general-purpose framework, including across the Gulf. Nothing in it is jurisdiction-specific, because it describes security outcomes rather than legal obligations. Your legal and regulatory obligations in the UAE come from elsewhere, and CSF sits alongside them rather than substituting for them.

Purpose, mainly. CSF is a taxonomy of outcomes that helps you understand and communicate where you stand, with no certificate attached. ISO 27001 specifies a management system you can be certified against by an accredited body, which is what you need when somebody external requires proof. They overlap heavily in substance and complement each other in practice: CSF is often the right first engagement, and the understanding it produces transfers almost entirely into an ISO programme if you decide to pursue one.

GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER. GOVERN establishes and monitors the risk management strategy, expectations and policy, and NIST describes it as informing and prioritising the outcomes of the other five. IDENTIFY builds understanding of your assets, suppliers and risks. PROTECT applies safeguards. DETECT finds what is happening. RESPOND acts. RECOVER restores operations and captures what was learned. Reading them in order tends to be uncomfortable for organisations that have invested only in the middle.

A Current Profile describes the outcomes you are achieving today and how well. A Target Profile describes the outcomes you have chosen and prioritised, accounting for anticipated changes. The gap between them, analysed and turned into a prioritised action plan, is the actual deliverable of an assessment. There are also Community Profiles, published baselines for shared circumstances, which NIST suggests using as a starting point for your Target rather than deciding everything from scratch.

Tiers characterise the rigour of your cybersecurity risk governance and management practices. We would discourage treating them as a ladder to climb. Organisations that set a target Tier as an objective in itself end up optimising for the description rather than for their actual risk, which is precisely the box-ticking behaviour the framework is designed to move away from. Tiers are most useful as a way of describing where you are, not as a goal.

For a mid-sized UAE organisation, typically three to six weeks from scoping to report. The variables are how many entities and environments are in scope, how available the right people are for interviews, and how much documentation exists to review. Organisations with operational technology alongside corporate IT take longer, mostly because the two areas are usually run by different teams who have not previously been asked the same questions.

NIST states explicitly that the framework does not prescribe how outcomes are achieved, and we work to that. If you already achieve an outcome using a product we do not sell, or through a manual process that genuinely works at your scale, it is achieved. In practice the highest-priority gaps we report are usually in GOVERN and IDENTIFY, which are addressed by decisions, ownership and record-keeping rather than by purchases, and that is an uncomfortable finding for a business hoping to solve this with budget.

Indirectly but usefully. CSF is not a UAE regulatory framework and completing an assessment does not discharge any obligation. What it does is give you an accurate picture of your position, which makes obligations easier to meet and makes it obvious where a sector requirement is going to be difficult before you are being assessed against it. Where you carry obligations under federal data protection law, national information assurance, DESC, ADHICS or a DIFC or ADGM regime, we map the CSF findings against them so you can see the overlap.

Yes, and NIST publishes the material to make that possible, including quick start guides. Two cautions from experience. First, self-assessment tends toward optimism, particularly when the person assessing also owns the controls being assessed, which is a structural problem rather than a character one. Second, the value is in the prioritisation and the honesty rather than in filling in the framework. If you do self-assess, have somebody outside the IT function interview the engineers.

A picture of where you stand across the six Functions, expressed so that a board can read it without translation. A gap analysis between your Current and Target Profiles. A prioritised action plan with owners, effort estimates and sequence. And a documented basis for each judgement, which matters more than it sounds because it is what makes a reassessment next year a measure of progress rather than a comparison of two assessors opinions.

Annually is a sensible default, with an additional assessment after any significant change such as an acquisition, a major platform migration or a serious incident. The point of reassessment is trend rather than snapshot. A single assessment tells you where you are, which is useful once. Two comparable assessments tell you whether the investment you made in between actually moved anything, which is the question a board will ask and which most organisations cannot currently answer.

It handles them better than most frameworks written for corporate IT, because outcomes translate across environments where prescriptive controls often do not. That said, an assessment covering operational technology needs people who understand that environment, and the practical constraints differ sharply: you cannot patch on the same cadence, availability requirements dominate, and equipment lifecycles run to decades. We scope those environments deliberately rather than applying corporate assumptions to them.

We scope per organisation rather than publishing a figure, and the drivers are the number of entities and environments in scope, whether operational technology is included, and how much of the follow-on plan you want us to help execute. What we will say is that a CSF assessment is materially cheaper than a certification programme and is frequently the thing that tells you whether the certification programme is worth starting, which makes it a reasonable first spend rather than an additional one.
Before a CSF assessment

Fifteen questions, ordered by the six Functions.

These are not the framework outcomes, which are far more detailed. They are the questions we open with, and how an organisation answers them predicts most of what the assessment will find.

Govern and Identify

  • Who is accountable for cyber risk, by name?
    The GOVERN Function starts here and most gaps do too.
  • Is there a written statement of what risk you accept?
    Undocumented acceptance is the most common governance gap.
  • Do you have a current inventory of systems and data?
    IDENTIFY depends on it and almost nobody has one that is accurate.
  • Do you know which suppliers could hurt you?
    Supply chain risk is called out explicitly in GOVERN in 2.0.
  • Has anybody assessed risk in the last twelve months?
    Not a scan. An assessment with decisions attached.

Protect and Detect

  • Is multi-factor authentication enforced everywhere it should be?
    Including administrators, third parties and legacy paths.
  • Are systems patched on a defined and evidenced cadence?
    Evidenced is the operative word.
  • Do you know what normal looks like on your network?
    DETECT is impossible without it.
  • Is anybody actually reading the alerts?
    Collection without review is the single most common false comfort.
  • Would you notice a compromise that did not announce itself?
    Most organisations find out from a third party.

Respond and Recover

  • Is there an incident response plan somebody has rehearsed?
    Written is not the same as rehearsed.
  • Who decides to disconnect a system, and can you reach them at 2am?
    A commercial decision that needs deciding in advance.
  • Have you restored from backup recently, as a test?
    Backup success reports prove nothing about restore.
  • Do you know your notification obligations before you need them?
    Federal, sector, contractual and free zone regimes may all apply.
  • Does anything you learn from an incident change what you do?
    RECOVER includes improvement, and it is routinely skipped.
Related reading

The pages around this one.

IT audit services in Dubai

The wider audit practice, and how to tell which kind of engagement your situation actually calls for before anybody quotes for one.

Learn more

ISO 27001 certification in the UAE

What to do if the assessment concludes you should certify, including the 2013 edition transition that closed in October 2025.

Learn more

Virtual CISO in Dubai

If the biggest gaps land in GOVERN, this is the role that closes them: accountability, risk decisions and board reporting.

Learn more
Next step

Find out where you stand before deciding what to spend.

A CSF assessment produces an honest picture across all six Functions, a prioritised plan, and a basis for measuring progress next year. It is also the cheapest way to establish whether a certification programme is worth starting, which is a question worth answering before the budget is committed.

Book a NIST CSF assessmentCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Active Directory Audit

Privilege paths, service accounts and local admin passwords

Learn more

DMARC Audit UAE

Stop exact-domain spoofing, and keep your mail delivering

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

ISO 27001 Certification UAE

The 2022 edition, and whether you should certify at all

Learn more

Virtual CISO Dubai

Security governance and accountability, not more tools

Learn more

Cybersecurity Audit

Security assessment and compliance audit

Learn more

SOC 2 Readiness UAE

Type II preparation, and when ISO 27001 fits better

Learn more

NESA / IA Compliance

UAE Information Assurance Standards compliance

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy