FreeFind your cybersecurity gaps with a free GAPZe assessmentStart now

Cybersecurity

NIST CSF vs ISO 27001: Which Framework Fits Your Business?

Isometric illustration of two pillars, one labelled ISO and one NIST, joined by a bridge of control blocks, in Anvay's red and stone colours

NIST CSF vs ISO 27001 is not really a contest. ISO/IEC 27001:2022 is a certifiable standard for an information security management system, and NIST CSF 2.0 is a voluntary, outcomes-based framework for understanding and improving cyber risk. Most organisations should pick one as an anchor, usually based on what customers ask for, then map the other to it so controls and evidence are built only once.

TL;DR

  • If a customer or tender asks for a certificate, anchor on ISO/IEC 27001:2022. Only an accredited certification body can issue one, and a first certification typically takes 6 to 12 months.
  • If you need to measure maturity, report to the board or answer US customers, use NIST CSF 2.0 Current and Target Profiles. There is no certificate.
  • For UK public sector supply chains, treat Cyber Essentials as the baseline, whichever framework you anchor on.
  • Build one control set, then map it to both using NIST’s published Informative References. Don’t run two parallel programmes.
  • Give one owner, usually the CISO or head of IT, the mapping, and review it each year alongside the ISO management review.

What is the difference between NIST and ISO 27001?

The short answer: ISO 27001 tells you how to run information security as a managed system, and is something you can be certified against. NIST CSF tells you what good cyber security outcomes look like, and helps you measure how close you are.

ISO/IEC 27001:2022 sets out requirements for an information security management system (ISMS). Clauses 4 to 10 are mandatory and cover context, leadership, planning, support, operation, performance evaluation and improvement. Annex A lists 93 controls in four themes: organisational, people, physical and technological. You choose controls based on your risk assessment and record each decision in a Statement of Applicability. Certification is carried out by independent certification bodies, which in the UK should be UKAS-accredited for the certificate to carry weight. The transition period for organisations certified to the 2013 edition ended on 31 October 2025, so any certificate you rely on now should be to the 2022 edition.

NIST CSF 2.0 was published by the US National Institute of Standards and Technology in February 2024. It groups outcomes under six Functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern is new in 2.0 and puts cyber risk strategy, roles, policy and supply chain risk at the centre. Organisational Profiles describe your Current and Target state. Tiers describe how rigorous your risk governance and management practices are. Informative References link each outcome to other standards and controls. The framework is voluntary and doesn’t prescribe how outcomes are achieved, and there is no NIST CSF certification.

NIST CSF 2.0 vs ISO 27001:2022: a side-by-side comparison

This cybersecurity framework comparison covers the points that usually decide the question in practice.

Comparison of NIST CSF 2.0 and ISO/IEC 27001:2022
AspectISO/IEC 27001:2022NIST CSF 2.0
PurposeRequirements for establishing, running and improving an ISMSA common language and set of outcomes for managing cyber risk
Certifiable?Yes, by accredited certification bodiesNo. You can be assessed against it, but there is no formal certificate
StructureClauses 4–10 (mandatory) plus Annex A (93 controls, four themes)Six Functions, Categories and Subcategories; Profiles; Tiers
Risk approachA formal risk assessment and treatment process drives control selectionRisk-informed prioritisation of the gap between Current and Target Profiles
GovernanceLeadership, management review, internal audit and corrective action are requiredThe Govern Function covers strategy, roles, policy, oversight and supply chain
EvidenceDocumented information, records and audit trails that an auditor samplesYour own, or an assessor’s, judgement of outcomes against the Profile
Typical audienceCustomers, procurement teams, auditors, regulated sectors worldwideBoards, risk committees, US customers and partners, internal security teams
Effort driversScope size, maturity of documentation, audit cycle (surveillance and recertification)Number of Profiles, depth of self-assessment, how often you re-measure

Neither framework is “better”. They answer different questions: “can you prove you run security properly?” and “how mature are we, and where do we go next?”

Which framework should I use?

Start with who is asking, and why. Use these rules of thumb:

  • A customer, tender or partner asks for a certificate. Choose ISO 27001. NIST CSF can’t give you a certificate, so it won’t satisfy that requirement.
  • The board wants a clear picture of maturity and progress. NIST CSF Profiles and Tiers are easy to explain, and the six Functions give a readable structure for board reporting.
  • You sell into the US, or to US-headquartered groups. NIST CSF is widely understood there, and questionnaires often follow its structure.
  • You supply UK central government. Cyber Essentials is the expected baseline for many contracts (see the NCSC Cyber Essentials overview). Add ISO 27001 or NIST CSF on top as your customers and risk profile require. Our guide on preparing for Cyber Essentials covers that step.
  • You need both. This is common for growing UK firms with international customers. Pick an anchor, then map.

How NIST CSF to ISO 27001 mapping works

NIST publishes CSF 2.0 Informative References that link CSF outcomes to other documents, including a mapping from ISO/IEC 27001:2022 to CSF 2.0. The mappings sit within NIST’s National Online Informative References (OLIR) Program, which provides a catalogue and tools for comparing references. NIST notes that it doesn’t test non-NIST mappings for correctness, and that listing one is not an endorsement. Treat any mapping as a starting point and validate it against your own controls.

In practice the mapping works like this:

  • Most Protect, Detect, Respond and Recover outcomes map to one or more Annex A controls, for example access control, logging and monitoring, incident management and backup.
  • The Govern Function maps mainly to ISO clauses 4 to 10, such as leadership, roles, risk assessment, management review and supplier relationships, rather than to Annex A.
  • Relationships are rarely one-to-one. A single Annex A control may support several CSF outcomes, and one outcome may need several controls.

Using both frameworks together: a step-by-step checklist

If you need ISO 27001 certification and NIST CSF reporting, this sequence avoids duplicated work:

  1. Agree scope and owner (week 1 to 2). Define the ISMS scope you expect to certify and name one accountable owner for both frameworks.
  2. Run a baseline assessment against both (weeks 2 to 4). Score your current state against ISO clauses and Annex A, and build a NIST CSF Current Profile from the same interviews and documents.
  3. Choose the anchor. Usually ISO 27001 if certification is required, because its management system requirements are stricter and auditable.
  4. Build one control library. Write each control once, tag it with Annex A and CSF references, and assign an owner and evidence source.
  5. Set a Target Profile. Use the CSF Target Profile to decide priorities and to explain the plan to the board.
  6. Close gaps by risk, not by framework. Fix the highest risks first, then update both your Statement of Applicability and your CSF Profile.
  7. Prove the management system works (typically 3 or more months of operation). Run internal audit and management review, and raise corrective actions before Stage 1.
  8. Certify, then re-measure. Go through Stage 1 and Stage 2 with an accredited certification body, then refresh the CSF Current Profile at least annually and report progress against the Target.

Key controls and evidence that serve both frameworks

A small set of well-run controls covers a large share of both frameworks. These are the areas where one piece of evidence usually satisfies an ISO auditor and supports a CSF outcome.

Controls and evidence that support both ISO 27001 and NIST CSF
Control areaTypical evidenceISO 27001:2022 linkNIST CSF 2.0 Function
Governance and rolesSecurity policy, RACI, board minutesClause 5, A.5.1–A.5.4Govern
Risk assessmentRisk methodology, risk register, treatment planClauses 6.1 and 8.2–8.3Govern, Identify
Asset inventoryHardware, software and data inventoriesA.5.9Identify
Access controlJoiner-mover-leaver records, access reviews, MFA configurationA.5.15–A.5.18, A.8.5Protect
Logging and monitoringLog sources, alert rules, review recordsA.8.15, A.8.16Detect
Incident managementIncident plan, exercise reports, incident logA.5.24–A.5.28Respond
Backup and continuityBackup policy, restore test results, continuity planA.5.29, A.5.30, A.8.13Recover
Supplier securitySupplier register, due diligence, contract clausesA.5.19–A.5.22Govern

Supplier risk is a shared area worth getting right. See our guide to third-party risk management.

Timeline and effort drivers

A first ISO 27001 certification commonly takes 6 to 12 months from gap assessment to certificate. Mature organisations with existing documentation are at the shorter end; those starting from scratch are at the longer end. After that, there are annual surveillance audits and a recertification audit every three years.

A NIST CSF Current and Target Profile can typically be produced in 3 to 6 weeks; the real work is the improvement programme that follows. For either framework, effort depends on the size of the scope (sites, cloud platforms, OT), how much practice is already documented, the availability of control owners, supplier dependencies and whether you maintain one control set or two. The last of these is the one you control most directly, and it is why mapping matters.

Common mistakes when comparing NIST CSF and ISO 27001

  • Claiming NIST certification. There is no official NIST CSF certificate. Be careful how you describe an assessment in sales material.
  • Treating Annex A as a checklist. ISO expects controls to be selected from a risk assessment, with justified inclusions and exclusions in the Statement of Applicability.
  • Ignoring Govern. Organisations moving from CSF 1.1 sometimes map only the original five Functions and miss the governance and supply chain outcomes added in 2.0.
  • Running two programmes. Separate ISO and NIST spreadsheets, owners and evidence folders double the effort and drift apart within months.
  • Trusting a mapping blindly. Published mappings show relationships, not equivalence. Check that your control actually achieves the CSF outcome.
  • Relying on an old certificate. Certificates to ISO/IEC 27001:2013 are no longer valid after the transition deadline. Check suppliers’ certificates, as well as your own.

How Anvay approaches NIST CSF and ISO 27001

We start from evidence, not from a framework preference. Our approach has four steps:

  1. GAPZe multi-framework assessment. A free GAPZe assessment screens your readiness against ISO/IEC 27001:2022, NIST CSF 2.0 and Cyber Essentials from one set of answers. It gives an indicative view based on what you report, not a certification or audit opinion.
  2. Choose your anchor framework. We use your customer requirements, contracts and risk profile to decide which framework leads.
  3. Build controls once, map to both. We help you create one control library tagged to Annex A and to CSF 2.0, with clear owners and evidence.
  4. Certify with ISO, measure with NIST. We prepare you for the independent certification audit, and use CSF Profiles to track and report maturity. Anvay does not issue certificates; certification is carried out by an accredited certification body you choose.
Anvay's four-step approach: 1. GAPZe multi-framework assessment; 2. Choose your anchor framework; 3. Build controls once, map to both; 4. Certify with ISO, measure with NIST
One assessment, one control library, two frameworks: certification evidence and maturity reporting from the same work.

One practical takeaway on NIST CSF vs ISO 27001

Don’t choose a framework in the abstract. Let your customers decide the anchor (certificate or not), let your board decide how you report (NIST Profiles work well), and make sure every control is written once and mapped to both. If you do only one thing this month, run a single baseline assessment against both frameworks so you can see where they already overlap in your organisation.

— Achal, Anvay

Anvay services for ISO 27001 and NIST CSF

Start with the free GAPZe assessment. It has live packs for ISO/IEC 27001:2022, NIST CSF 2.0 and Cyber Essentials, and includes a free PDF report and a free 30-minute 1:1. From there, our compliance and assurance service prepares you for ISO 27001 certification audits, and our GRC and risk service builds the risk register, control library and framework mapping. For broader context, our cyber assessments test how controls work in practice, and a fractional CISO can own the programme if you don’t have a security lead. If NIST CSF is your anchor, read our NIST CSF 2.0 implementation guide next.

Ready to see where you stand? Book your free GAPZe assessment and 1:1.

FAQ

NIST CSF vs ISO 27001: which is better?

Neither is better in general. ISO 27001 is the right choice when you need a certificate that customers and auditors recognise. NIST CSF 2.0 is better for measuring maturity, setting priorities and reporting to a board. Many organisations use ISO 27001 as the anchor and NIST CSF for reporting, mapped to one shared control set.

Can you get certified to NIST CSF?

No. NIST CSF 2.0 is a voluntary framework and NIST doesn’t offer a certification scheme. You can carry out a self-assessment or have an independent party assess you against it and report the result, but that isn’t a certificate. If a customer needs formal certification, ISO/IEC 27001:2022 or, in the UK, Cyber Essentials are the usual routes.

Does ISO 27001 cover everything in NIST CSF 2.0?

Much of it, but not identically. Annex A controls align closely with Protect, Detect, Respond and Recover, and clauses 4 to 10 cover much of Govern. The frameworks are structured differently and the relationships are often many-to-many. Use NIST’s published Informative References as a starting point and check your own controls against each outcome.

Which framework should I use for UK public sector contracts?

Start with Cyber Essentials, which is expected for many UK central government contracts. Above that baseline, ISO 27001 certification is often requested for higher-risk services or larger suppliers. NIST CSF is less commonly specified in UK public sector procurement, but it is useful internally for tracking maturity. Always check the specific tender requirements.

How long does ISO 27001 certification take compared with a NIST CSF assessment?

A first ISO 27001 certification typically takes 6 to 12 months, because the management system has to run for a period and pass Stage 1 and Stage 2 audits. A NIST CSF Current and Target Profile can typically be built in 3 to 6 weeks, although closing the gaps it reveals takes longer.

Sources

Primary references and standards: this article draws on NIST CSF 2.0, NIST’s Informative References and OLIR resources, ISO/IEC 27001:2022 and NCSC guidance on Cyber Essentials.

Back to all insights

Make your next step clearer.

Tell us what you are working on or where you feel unsure. We will talk it through with you and suggest practical support that fits.

Discuss your requirements