Blog

NIST CSF 2.0 Implementation: 5 Practical Steps | StickmanCyber

Written by Ajay Unni | Sep 18, 2026, 12:17:27 PM

The NIST Cybersecurity Framework (CSF) 2.0 provides guidance for managing cybersecurity risk. Its six core functions are Govern, Identify, Protect, Detect, Respond and Recover. You may be wondering how best to implement it into your organisation.

Below are five practical steps to help implement the NIST framework:

Establishing a set of goals

Great, your organisation is looking to implement the NIST Framework, the first step towards achieving this is establishing a set of goals in regards to data security so that you can better measure success. Goals can be created based on the following questions; What is your organisation’s tolerance to risk? Where should your organisation prioritise protection? How much do you want to spend on your cybersecurity? By setting goals you can organize a plan of action, establish a scope for your security efforts and ensure that everyone within the organisation is clear of what needs to be achieved.

Profile creation

Most organisations use the NIST Framework voluntarily, although requirements may apply through government or contractual obligations. It is applicable to a wide range of industries. The way it needs to be applied when it comes to your business may look completely different to another business in another industry. A Current Profile describes the outcomes your organisation is achieving, while a Target Profile sets out the outcomes it wants to achieve, so that the framework can be effectively tailored to your organisation’s needs. The CSF Tiers describe the rigour of cybersecurity risk governance and management: Partial, Risk Informed, Repeatable and Adaptive. Select a tier appropriate to your organisation’s risks and resources; Tier 4 is not a universal target.

Assessing your current position

The next step in implementing the NIST Framework in your organisation is to carry out a detailed risk assessment. A detailed risk assessment provides valuable information to your organisation on how your current cybersecurity practices align with your selected CSF outcomes and what needs to be improved. You can either use open source or other software tools to score your security efforts on your own or hire a cybersecurity specialist like StickmanCyber to conduct a thorough assessment for your organisation.

Conduct a gap analysis and create a plan of action

The findings from the completed risk assessment need to be communicated with key stakeholders. Findings should include vulnerabilities and threats to the organisation’s operations, assets and individuals. Now that you have identified the gaps in your cybersecurity requirements, an analysis of how best to address them can be carried out. Comparing your Current and Target Profiles alongside the risk assessment findings, your organisation can prioritize what needs to be addressed first, through the creation of a plan of action.

Implementation

With a clear picture of your organisation's current cybersecurity efforts provided by the risk assessment and gap analysis and an idea of what you want to achieve via your set of goals and plan of action, it is now time to implement the NIST Cybersecurity Framework.

It is important to note that your cybersecurity efforts should not end with implementation, for the NIST Framework to succeed, continuous monitoring and improvement needs to take place so that the framework is tailored to your business's needs.

Summary

A cyber security framework can help organisations manage cyber crime risks. Without goals and an understanding of risk tolerance levels, evaluating your cyber security efforts becomes more difficult. By following the above steps and tailoring the NIST Framework to your business, you can better prioritise actions to manage cyber risk.

Looking to manage your cybersecurity with the NIST framework approach? StickmanCyber's governance, risk and compliance services can help assess your current position and build a prioritised plan for managing cyber risk.