Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST CSF vs ISO 27001 explained

NIST CSF vs ISO 27001: 5 Clear Differences Explained (2026)

NIST CSF vs ISO 27001 is the comparison every security programme makes when a customer asks for one and the board has heard of the other — and the two are different kinds of thing that map to each other well. The NIST Cybersecurity Framework 2.0, published on 26 February 2024, is a voluntary framework of outcomes: six Functions — Govern, Identify, Protect, Detect, Respond, Recover — 22 Categories and 106 Subcategories, with Tiers 1 to 4 describing governance rigour and Profiles describing an organisation’s current and target state; nobody certifies to it.

ISO/IEC 27001:2022 is a certifiable management-system standard: clauses 4 to 10 that an accredited certification body audits, and 93 Annex A controls selected through a risk assessment and a Statement of Applicability. The CSF describes what a good programme achieves; ISO 27001 specifies how a management system is run and proves it with a certificate. This guide sets the two side by side on five differences, maps the six Functions to the ISO clauses and Annex A themes, explains which to adopt first for four situations, and describes how organisations run one programme that reports in CSF and certifies to ISO.

NIST CSF vs ISO 27001: outcome framework vs certifiable system
NIST CSF 2.0: 6 Functions, 22 Categories, 106 Subcategories, Tiers 1–4, Profiles; voluntary, no certificate · ISO/IEC 27001:2022: clauses 4–10, 93 Annex A controls in 4 themes, SoA, accredited certificate on a 3-year cycle · Govern ↔ clauses 4–6, 9–10; Identify ↔ 6.1, 8.2; Protect/Detect/Respond/Recover ↔ Annex A.

NIST CSF vs ISO 27001: what each one is

NIST CSF 2.0 replaced CSF 1.1 in 2024, adding the Govern Function and widening the audience from critical infrastructure to all organisations. Each Subcategory is an outcome — “the organization’s cybersecurity risk management strategy is established”, “incidents are contained” — not a control, and the framework supplies Informative References that map outcomes to controls in ISO 27001, NIST SP 800-53, the CIS Controls and others. Tiers characterise how an organisation governs and manages risk, from Partial (1) to Adaptive (4); Profiles record the Current and Target selection of outcomes. Our guide to NIST CSF 2.0 vs 1.1 covers the 2024 changes; NIST CSF Tiers covers the four levels.

ISO/IEC 27001:2022 specifies requirements for an information security management system: context, leadership, planning, support, operation, performance evaluation and improvement in clauses 4 to 10, with risk assessment and treatment in 6.1 and the Statement of Applicability in 6.1.3, and Annex A’s 93 controls — 37 organizational, 8 people, 14 physical, 34 technological. Amendment 1 of 2024 added climate change as a context consideration. Certification is by accredited bodies, on a three-year cycle with annual surveillance.

NIST CSF vs ISO 27001: the five differences

Difference NIST CSF 2.0 ISO/IEC 27001:2022
1. Nature A framework of outcomes for describing and improving a programme A requirements standard for a management system
2. Assurance Self-assessed Profiles and Tiers; no certification scheme Accredited third-party certification; a certificate customers verify
3. Scope Cybersecurity risk, with Govern covering strategy, roles, policy, oversight and supply chain Information security in all forms — including physical, people and organizational controls
4. Prescription None: outcomes with Informative References to controls elsewhere Requirements in clauses 4–10; controls in Annex A selected through the SoA with justification
5. Demand US federal expectation; sector regulators; boards and insurers as a vocabulary Global procurement, tenders, regulators (NIS2, DORA evidence), customers who want a certificate

1 and 2. Framework vs standard, Profile vs certificate

The first NIST CSF vs ISO 27001 differences are about what each produces. The CSF answers “what should be true of our programme, and how far along are we?” — a Target Profile and a Tier. ISO 27001 answers “does a management system exist, does it meet the requirements, and can an independent auditor confirm it?” — a certificate. A CSF Profile is a management tool; an ISO certificate is a market instrument. Our guide to the NIST CSF audit checklist covers how CSF outcomes are tested in the absence of a certification scheme.

3. Scope

The CSF’s Govern Function reaches into strategy and supply chain risk management in a way ISO 27001’s clauses touch more lightly; ISO 27001’s Annex A reaches into physical security, HR and legal controls the CSF treats as outcomes to be achieved by whatever means. Neither is a subset of the other.

4. Prescription

Neither prescribes technical controls in detail — ISO 27002 gives guidance and the CSF gives references — but ISO 27001 requires the organisation to decide and justify every Annex A control in the SoA, which is a discipline the CSF leaves to the Profile.

5. Demand

A US customer, regulator or insurer asks whether you follow the CSF; a European or global customer asks for the ISO 27001 certificate. Most organisations selling internationally end up holding the certificate and describing the programme in CSF terms.

NIST CSF vs ISO 27001: the mapping by Function

CSF 2.0 Function ISO 27001:2022 clauses Annex A themes and examples
Govern (GV) 4 Context; 5 Leadership; 6 Planning; 7.1–7.4 Support; 9 Performance evaluation; 10 Improvement 5.1 Policies; 5.2 Roles; 5.4 Management responsibilities; 5.19–5.23 Supplier relationships; 5.31 Legal requirements; 5.35 Independent review
Identify (ID) 6.1.2 Risk assessment; 8.2 Risk assessment in operation; 9.1 Monitoring; 10.1 Improvement 5.9 Inventory of assets; 5.12 Classification; 8.8 Technical vulnerabilities; 5.7 Threat intelligence
Protect (PR) 6.1.3 Risk treatment; 7.2–7.3 Competence and awareness; 8.1 Operational control 6.3 Awareness; 5.15–5.18 Access control; 8.2–8.5 Privileged access, restriction, authentication; 8.24 Cryptography; 8.9 Configuration; 8.13 Backup; 7.x Physical controls
Detect (DE) 9.1 Monitoring, measurement, analysis and evaluation 8.15 Logging; 8.16 Monitoring activities; 8.7 Malware; 5.24 Incident planning
Respond (RS) 8.1 Operational control; 10.1 Nonconformity and corrective action 5.24–5.28 Incident management planning, assessment, response, learning, evidence; 6.8 Event reporting
Recover (RC) 8.1; 10.1 5.29 Security during disruption; 5.30 ICT readiness for business continuity; 8.13 Backup; 8.14 Redundancy

NIST’s own Informative References in the CSF 2.0 tool map each Subcategory to ISO 27001:2022 controls; the table above is the Function-level summary. Our guide to NIST CSF to 800-53 mapping covers the other mapping most organisations need.

NIST CSF vs ISO 27001: which to adopt first

Situation Start with Then
Selling internationally; customers want a certificate ISO 27001 Describe the ISMS as a CSF Profile for US customers and the board
US organisation; board, regulator or insurer speaks CSF; no certificate demanded NIST CSF 2.0 Current and Target Profiles ISO 27001 when a contract requires it — the Profile is most of the gap analysis
Regulated in the EU (NIS2, DORA) ISO 27001 CSF as the risk-management vocabulary if the board prefers it
Small organisation building a programme from nothing CSF Govern and Identify outcomes to frame; a control set such as CIS IG1 to act ISO 27001 when the programme is mature enough to audit

Running one programme for NIST CSF and ISO 27001

  1. Make ISO 27001 the system and the CSF the report. Clauses 4–10 supply the management system an auditor can certify; the CSF Functions supply the structure the board reads.
  2. Map the SoA to Subcategories. Each Annex A control in the SoA lists the CSF outcomes it serves, using NIST’s Informative References; the Target Profile is then derived from the SoA rather than maintained separately.
  3. Use the ISO risk assessment for both. Clause 6.1 produces the treatment plan and the SoA; the same assessment sets the Target Profile’s priorities.
  4. Measure once. ISO 9.1 monitoring metrics roll up to CSF outcome status; the internal audit under 9.2 tests both.
  5. Report the Tier alongside the certificate. The certificate says the system exists and conforms; the Tier says how adaptive the governance is — two different, useful claims.

Frequently asked questions

What is the difference between NIST CSF and ISO 27001?
NIST CSF 2.0 is a voluntary framework of cybersecurity outcomes — 6 Functions, 22 Categories, 106 Subcategories, with Tiers and Profiles — that nobody certifies to. ISO/IEC 27001:2022 is a certifiable management-system standard with clauses 4–10 and 93 Annex A controls selected through a Statement of Applicability. The CSF describes what a programme achieves; ISO 27001 specifies and certifies how the system is run.

Can you be certified to NIST CSF?
No. There is no accreditation scheme or certificate for the CSF; organisations self-assess Profiles and Tiers, and may have them reviewed by a third party without any formal recognition. ISO 27001 certification is by accredited bodies.

Do they map to each other?
Closely. NIST publishes Informative References mapping every CSF 2.0 Subcategory to ISO 27001:2022 controls; at Function level, Govern maps to ISO clauses 4–6 and 9–10, Identify to 6.1 and 8.2, and Protect, Detect, Respond and Recover to Annex A themes.

Which should we choose?
The one your customers and regulators ask for: ISO 27001 where a certificate is demanded or EU regulation applies; CSF where US boards, regulators or insurers use it as a vocabulary. Most international organisations hold the certificate and report in CSF terms.

Is ISO 27001 harder?
It requires a management system that is audited every year — internal audit, management review, corrective action — which the CSF does not. The CSF’s Govern Function asks for strategy and supply chain outcomes that ISO 27001 addresses more lightly.

Where this leaves you

Settle NIST CSF vs ISO 27001 by what each is for: ISO 27001 is the system and the certificate, the CSF is the description and the vocabulary, and NIST’s own references join them — so run the ISMS, derive the Target Profile from the Statement of Applicability, measure once, and report the certificate and the Tier together.

References

More on NIST CSF

The CSF 2.0 Profile workbook with the ISO 27001:2022 mapping per Subcategory, the Tier assessment, and the policies organised by Function are in the NIST CSF Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.