There is no certification against the NIST Cybersecurity Framework. No accreditation body, no certificate, no auditor who can issue one. This CSF 2.0 documentation pack is built for what you can actually do: run the Framework properly, assess yourself against all 106 outcomes, and hold evidence a customer or a regulator will accept.
On this page:
- Most CSF packs are a policy library with a spreadsheet bolted on
- What is inside the CSF 2.0 documentation pack
- Implementation Tiers, scored the way NIST actually defines them
- Who the CSF 2.0 documentation pack is written for
- What the CSF 2.0 documentation pack does not do
- Frequently asked questions
- Related toolkits
Most CSF packs are a policy library with a spreadsheet bolted on
The assessment tool is the product here, and the policies sit around it rather than the other way round. The assessment workbook carries all 106 Subcategories with NIST own outcome wording, a five-point scale, an evidence reference against every score, a target score, a calculated gap and automatic roll-ups by Function and by Category. It is an Excel file. It opens, it works, and it needs no login.
Around it sit six more pre-loaded workbooks: Current Profile, Target Profile, Profile Gap Analysis, Action Plan and Improvement Roadmap, Executive Reporting Dashboard, and the CSF 2.0 Core Reference carrying NIST Implementation Examples and Informative References in full. Fourteen workbooks in total ship seeded rather than empty, so the assessment starts when you open the file rather than after a week of typing.
A note on the count, because it is the first thing a careful buyer checks. Download NIST own CSF 2.0 reference file and count the Subcategory rows and you get 185. That file carries 79 withdrawn CSF 1.1 entries alongside the live Core. 106 plus 79 is 185. The correct number of current outcomes is 106, and this CSF 2.0 documentation covers all of them.
What is inside the CSF 2.0 documentation pack
The CSF 2.0 documentation pack is 164 editable documents – 118 Word and 46 Excel – organised by the six Functions, with every document naming the outcomes it answers.
- GOVERN – the Function added in 2.0 and the largest one, covering organisational context, risk management strategy, roles, policy, oversight and cybersecurity supply chain risk management.
- IDENTIFY – asset management, risk assessment and improvement, including the asset and data inventories the rest of the Framework depends on.
- PROTECT – identity and access, awareness and training, data security, platform security and technology resilience.
- DETECT – continuous monitoring and adverse event analysis.
- RESPOND – incident management, analysis, reporting and mitigation.
- RECOVER – recovery plan execution and communication.
- Assessment and maturity tool – all 106 outcomes, five-point scale, evidence column, target, gap and roll-ups.
- Profiles – Current Profile, Target Profile and the gap analysis between them, which is how the Framework is actually meant to be used.
- Implementation Tiers – scored on both axes separately, with NIST own characterisation of each Tier on each axis.
- Crosswalks – with coverage stated on the face of each, rather than implied.

Implementation Tiers, scored the way NIST actually defines them
This is the detail nearly every Tier assessment on the market gets wrong. CSWP 29 Table 2 scores Tiers across two separate axes: cybersecurity risk governance, which is the GOVERN Function, and cybersecurity risk management, which is the other five.
An organisation can sit at Tier 3 on management and Tier 1 on governance – capable operational practice with no organisational risk strategy behind it. That is a real and common result, and a single overall Tier number erases exactly the finding a board needs to see. The Tier workbook in this CSF 2.0 documentation scores both axes separately, with an evidence column and a selection sheet recording current Tier, target Tier and the reasoning.
Tiers are also not maturity levels and not a certification. NIST presents them as a notional illustration. The pack says so on the page, because a toolkit that lets you believe otherwise has sold you a problem you will meet later in front of an assessor.
Who the CSF 2.0 documentation pack is written for
- Organisations aligning to CSF 2.0 because a customer, an insurer or a contract asks them to.
- Security teams that need a defensible self-assessment across all 106 outcomes rather than a maturity opinion.
- Federal contractors and suppliers using CSF as the umbrella above SP 800-171 or CMMC work.
- Anyone who has been asked for a Current Profile and a Target Profile and has not produced one before.
What the CSF 2.0 documentation pack does not do
It does not certify you, because nothing does. Anyone selling certification against the Framework is not selling what they say.
It does not replace SP 800-171 or CMMC work where a contract requires those. CSF sits above them; the crosswalks show where they meet.
It does not implement controls. The CSF 2.0 documentation is the written layer and the assessment structure; operating the practices is your work.
Frequently asked questions
Can we get certified against CSF 2.0?
No. There is no certification, no accreditation body and no auditor who can issue one. The correct phrase is aligned to CSF 2.0, and that is what the documents say.
Why 106 outcomes and not 185?
NIST own reference file includes 79 withdrawn CSF 1.1 entries. 106 is the count of current Subcategories, in 22 Categories across 6 Functions.
Do the workbooks need macros or a subscription?
No. They are plain Excel files with formulas. They open, calculate and print without any add-on.
Does it cover the GOVERN Function properly?
Yes. GOVERN is the largest Function in 2.0 and it gets a full section rather than a few policies retrofitted from a 1.1 pack.
Related toolkits
It is commonly bought with the NIST SP 800-53 toolkit for the control detail, the NIST SP 800-171 toolkit where CUI is in scope, and the ISO 27001 toolkit where a certificate is needed as well. NIST publishes the Framework free at nist.gov/cyberframework.
Implementing for clients? The Consultant Package licenses all 86 toolkits and assessment tools on this site for unlimited client engagements, under one firm-wide licence. One payment of $1,399, no subscription and no per-client fee.
Delivery, format and licence
The CSF 2.0 documentation pack downloads immediately after checkout as native Microsoft Word and Excel files. Nothing is locked, nothing is a PDF you cannot edit, and no add-on or portal login is needed to open it. Every organisation-specific value is marked as a placeholder so you can see what still has to be decided.
One payment, no subscription and no annual renewal. The source files behind the CSF 2.0 documentation pack are yours to adapt for your own organisation for as long as you need them, including future revisions of your own documents.




Reviews
There are no reviews yet.