Free resource
Map your existing evidence to the six CSF 2.0 functions - Govern, Identify, Protect, Detect, Respond, Recover. NIST CSF is voluntary and not certifiable; this shows coverage and gaps in the vocabulary a US buyer uses.
The actual structure of the file, straight from the template we use on live engagements.
Sheet: Start here
Read this tab first, then work through the checklist. Score honestly - a 'Partly' you can see is worth more than a 'Yes' you cannot evidence. This is a working tool, not a certificate: it shows where an assessor will push, before they do.
| Topic | Detail |
|---|---|
| What this is | A coverage worksheet mapping your existing evidence to all six CSF 2.0 functions and their categories. NIST CSF is voluntary and not certifiable - this speaks a US buyer's vocabulary without starting a second programme. |
| How to use it | For each category, note your current outcome and the evidence, and mark the gap. Most of it likely maps to work you already do for ISO 27001; this reframes it in CSF terms. |
| On the ISO 27001 mapping | An ISO 27001-to-CSF informative reference exists in the NIST OLIR catalog (reference 154). It is a useful starting point, not an official NIST crosswalk - confirm the mappings for your own context. |
| A second pair of eyes | If you want someone who has sat on the other side of the audit table to sanity-check your scoring before it counts, that is what we do at kellwick.com. |
Sheet: CSF 2.0 Coverage
NIST CSF 2.0 (CSWP 29, published 26 February 2024) is a voluntary framework - not certifiable. Map your evidence to the six functions and their categories. 'What good looks like' and 'Common gap' are filled in for you.
| Function | Category (CSF 2.0 ID) | What it covers | What good looks like | Common gap | Your outcome / evidence |
|---|---|---|---|---|---|
| GOVERN | Organizational Context (GV.OC) | Mission, stakeholders and the legal / regulatory requirements the strategy must reflect | Context and obligations documented and driving the risk strategy | Security strategy set with no view of business context or obligations | - |
| GOVERN | Risk Management Strategy (GV.RM) | Risk appetite, tolerance and how risk decisions get made | A stated risk appetite that actually guides decisions | No defined appetite - every risk argued from scratch | - |
| GOVERN | Roles, Responsibilities & Authorities (GV.RR) | Who is accountable, resourced and empowered | Named owners with real authority and budget | Responsibility handed out without authority or resource | - |
| GOVERN | Policy (GV.PO) | Cybersecurity policy established and maintained | Current, approved policies that people actually follow | Policies that exist but are stale or unknown to staff | - |
Preview only. The download is a fully editable .xlsx file.
Go deeper
See how this template fits the wider readiness work, and where we pick it up on a live engagement.
Explore the related serviceMore resources