Skip to content
๐ŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
Framework comparison

NIST CSF vs CIS Controls vs ISO 27001

Three names that get used interchangeably and should not be. One frames risk, one is a prioritised checklist, one is a certifiable standard. Here is how NIST CSF 2.0, the CIS Controls v8.1 and ISO/IEC 27001:2022 actually differ, and how mature programmes use all three together.

NIST CSF 2.0

A flexible risk framework organised around outcomes.

Structure
Six Functions: Govern, Identify, Protect, Detect, Respond, Recover.
Size
6 Functions
Certification
No formal certification โ€” a voluntary framework.
Best for
Communicating risk to a board and aligning a programme around outcomes.

The NIST Cybersecurity Framework 2.0 (2024) adds Govern to the original five Functions, pulling strategy, roles and supply-chain risk to the top. It describes outcomes, not prescriptive controls, so it maps onto almost any environment and pairs well with a control set like CIS underneath it.

How they fit together

Frame the programme and the board conversation with NIST CSF 2.0. Implement the concrete safeguards underneath with the CIS Controls, starting at Implementation Group 1. When a customer or regulator needs independent proof, certify the management system against ISO/IEC 27001. They layer; they do not compete.

TL;DR

The three frameworks in five lines

  • NIST CSF 2.0 is an outcome-based risk framework with 6 Functions (Govern, Identify, Protect, Detect, Respond, Recover). It is not certifiable.
  • CIS Controls v8.1 is a prioritised checklist of 18 Controls and ~153 Safeguards, grouped into 3 Implementation Groups. Also not certifiable.
  • ISO/IEC 27001:2022 certifies a management system and carries 93 Annex A controls across 4 themes. It is the one you can hold a certificate for.
  • They are not rivals: most mature programmes use NIST CSF to frame risk, CIS Controls as the safeguards underneath, and ISO 27001 when a customer needs a certificate.
  • Blueprint controls against a regime on an infinite canvas in the PlayCISO Architecture Studio.

Frequently asked questions

What is the difference between NIST CSF, CIS Controls and ISO 27001?

NIST CSF 2.0 describes security outcomes across six Functions and is best for framing and communicating risk; it prescribes no specific controls and offers no certificate. CIS Controls v8.1 is a prioritised, prescriptive list of 18 Controls and roughly 153 Safeguards, grouped into three Implementation Groups so it scales from small business to enterprise. ISO/IEC 27001:2022 certifies an Information Security Management System and lists 93 Annex A controls in four themes; it is the one you can be independently audited and certified against.

Which framework should I use?

Use NIST CSF 2.0 to structure your programme and talk to the board, CIS Controls v8.1 as the concrete safeguards you actually implement (start at Implementation Group 1), and pursue ISO/IEC 27001 certification when customers, partners or regulators need independent proof. They layer together rather than competing.

Is NIST CSF certifiable like ISO 27001?

No. NIST CSF 2.0 and the CIS Controls are voluntary frameworks with no accredited certification. Only ISO/IEC 27001 offers a formal, third-party certificate of your management system, which is why customers tend to ask for ISO 27001 specifically.

How many controls are in ISO 27001:2022?

The 2022 revision of ISO/IEC 27001 has 93 controls in Annex A, reorganised into four themes: Organizational (37), People (8), Physical (14) and Technological (34). The earlier 2013 version had 114 controls across 14 domains.

NIST CSF vs CIS Controls vs ISO 27001 โ€” Compared ยท PlayCISO