Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

What Is NIST CSF? A Plain-Language Guide

NIST CSF (the NIST Cybersecurity Framework) is a voluntary set of best practices from the U.S. National Institute of Standards and Technology that helps organizations identify, manage, and reduce cybersecurity risk. It is not a certification and not a law. It is a common language, built around six functions, that lets a company describe its current security posture, set a target posture, and build a roadmap to close the gap.

What NIST CSF Actually Is (and Isn't)

NIST CSF 2.0, released in early 2024, organizes cybersecurity activity into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern is the newest addition, and it matters, because it forces leadership and the board to own risk decisions instead of leaving them entirely to IT.

What it is not: a checklist you complete once and file away. It is not equivalent to SOC 2, ISO 27001, or PCI DSS, and it does not issue a certificate you can hand to a customer. There is no "NIST CSF certified" badge, no matter what a vendor's marketing implies. What you get instead is a documented, defensible security program and a maturity score you can track over time.

Who Actually Needs a NIST CSF Assessment

NIST CSF shows up most often for three kinds of buyers:

  • Vendors selling into U.S. federal supply chains or critical infrastructure, where a prime contractor or agency asks for evidence of alignment to the framework.
  • Boards and executive teams who need a plain-language way to talk about cyber risk without drowning in technical jargon, since Govern maps directly to fiduciary duty.
  • Canadian companies building a security program from scratch who want a structured starting point before they decide whether SOC 2, ISO 27001, or something else is the right next step.

We see the third case constantly with Canadian B2B SaaS companies. A founder in Toronto or Waterloo gets asked "what's your security posture" by a US enterprise prospect, has no framework at all, and needs something credible fast. NIST CSF is often the right first move because it is free to adopt, flexible in scope, and respected internationally, including by security teams in Ottawa's government-adjacent tech sector and Vancouver's cloud-native scene.

What a NIST CSF Assessment Actually Involves

A proper assessment is not a survey you fill out in an afternoon. It typically runs through these stages:

1. Scoping and current profile

You define what's in scope (which products, which environments, which data) and document where you stand today against each of the six functions. This is the "as-is" profile.

2. Target profile and gap analysis

You decide where you need to be, based on customer requirements, industry norms, and risk tolerance, then map the gap between current and target state function by function.

3. Risk-informed roadmap

Gaps get prioritized by risk and effort, not addressed alphabetically. A missing incident response runbook usually outranks a nice-to-have logging enhancement.

4. Implementation and re-measurement

You execute the roadmap, then re-score. NIST CSF is designed to be iterative, so most companies reassess annually or after a major change like a new product line or acquisition.

A structured NIST CSF assessment does this work with an outside set of eyes, which matters because internal teams tend to score their own maturity generously.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself. Talk to us

How Long Does a NIST CSF Assessment Take

For a small to mid-size company, a focused assessment against the six functions typically runs two to four weeks: workshops with engineering and leadership, document and control review, then a written report with the gap analysis and roadmap. Companies with multiple products, cloud environments, or subsidiaries take longer. The roadmap itself, meaning the work to actually close gaps, is separate from the assessment and can run anywhere from a few months to over a year depending on maturity and headcount.

This is different from something like SOC 2, where the observation period alone is three to twelve months. NIST CSF assessment and remediation planning move faster because there's no auditor sign-off requirement, just a documented, evidence-backed posture.

Common Misconceptions About NIST CSF

"We can get NIST CSF certified"

No such certification exists. What exists is a maturity assessment and a documented posture. Anyone selling you a "NIST CSF certificate" is selling something NIST does not offer.

"It's only for U.S. government contractors"

NIST CSF is used well beyond federal supply chains. Private-sector companies worldwide, including plenty in Calgary's energy tech and Montreal's fintech and AI clusters, adopt it because it is free, well-documented, and maps cleanly to other frameworks.

"It replaces the need for PIPEDA compliance"

NIST CSF is a security framework, not a privacy law. Canadian companies still need to meet PIPEDA obligations, and Quebec-based companies still need to comply with Law 25, regardless of where they land on the CSF maturity scale. The two are complementary, not interchangeable.

"One assessment and we're done"

Threats, tooling, and business scope change. NIST CSF is built as a living program, reassessed periodically, not a one-time project.

NIST CSF vs. SOC 2 and ISO 27001

A quick way to think about it: NIST CSF describes what good security looks like across your whole organization. SOC 2 and ISO 27001 are formal, auditable standards that prove you meet a defined bar, usually because a customer contract requires it. Many companies use NIST CSF as the foundation, then layer a formal certification on top once a customer or market demands it. If you're not sure which order makes sense for your stage, that's exactly the kind of question our compliance advisory work is built to answer.

Getting Started With NIST CSF in Canada

Whether you're a SaaS company in Toronto trying to unblock a US enterprise deal, a scale-up in Waterloo building security into the product from day one, or an established firm in Ottawa or Vancouver formalizing a program that grew organically, the starting point is the same: an honest current-state assessment against the six functions, followed by a roadmap prioritized by actual risk, not by what's easiest to fix first. TrazTech runs NIST CSF 2.0 posture assessments and roadmaps for Canadian companies, built by a team led by a published security researcher, not a generic audit template. If you want a clear picture of where you stand and what to do next, get in touch and we'll walk you through it.

Tiers and Profiles: The Part Everyone Gets Backwards

CSF 2.0 has two mechanisms that get confused constantly. Profiles describe what you do, function by function and subcategory by subcategory, in a current state and a target state. Tiers describe how you make risk decisions, on a scale from Tier 1 Partial through Tier 2 Risk Informed and Tier 3 Repeatable to Tier 4 Adaptive. Tiers apply to your governance and risk management approach as a whole. They are not per-control maturity scores, and they are not a ladder you are supposed to climb to the top of.

The most common error in self-run assessments is a spreadsheet that assigns a tier to each of the hundred-odd subcategories, averages them, and reports "we are a 2.4". That number cannot be defended to a board, cannot be compared to last year because the weighting changed, and hides the finding that matters, which is usually that one function is far weaker than the average implies. Detect is almost always the weakest function in a company under a hundred people, and averaging is the operation that conceals it.

Score the profile per subcategory with a simple, stated scale, and state a single organizational tier separately with the reasoning behind it. Then a board conversation becomes possible: here is where we are, here is where we intend to be by the end of the fiscal year, and here is what that costs.

Evidence, Not Opinion: How to Score Honestly

An assessment is only as good as what sits behind each score. The test for any subcategory is whether you can produce an artifact and a date. "We have an asset inventory" is a claim. A CMDB export from last Tuesday showing 214 hosts, with the reconciliation note explaining why cloud tagging says 231, is evidence. Anyone can pass the first test and almost nobody passes the second on the first attempt.

Two traps recur. A written policy gets scored as a control that operates, when nobody has run it in eighteen months. A purchased product gets scored as a capability, though the agent is deployed on sixty percent of endpoints and nobody reads its alerts. Both produce a flattering score and a program that fails on contact with a real incident.

The correction is dull and effective: for every subcategory scored above the floor, name the artifact, the owner, and the last date it was exercised. Keep that record in one place and next year's reassessment takes days rather than weeks, with the same evidence serving an auditor later. Our free traztech Workspace exists mainly because clients were keeping this in three disconnected spreadsheets.

Reusing CSF Work for SOC 2 and ISO 27001

CSF publishes informative references mapping its subcategories to other standards, which is what makes it useful as a foundation rather than a detour. The reuse is genuine but partial, and it helps to know where. Access control, asset management, logging, vulnerability management, incident response and vendor risk map across almost everything, so work done once counts three times. What does not carry over is the formal apparatus each standard adds on top: SOC 2 needs a defined observation period and an auditor's testing of operating effectiveness, and ISO 27001 needs a management system, meaning an internal audit programme, a management review, a risk treatment plan and a Statement of Applicability against the 93 Annex A controls plus clauses 4 to 10.

Practically, a company that has done a real CSF assessment and closed its high-risk gaps is well into an ISO 27001 implementation and into SOC 2 readiness, with the remaining effort sitting in documentation and evidence discipline. Companies that treat the assessment as a report to file rather than a backlog to work do not get that head start.

When a CSF Assessment Is the Wrong Purchase

If a customer contract names SOC 2 or ISO 27001 with a date attached, do that instead. A CSF assessment in front of it delays the thing that unblocks revenue, and nothing in the assessment is required by either standard. Start the readiness work and let the framework mapping happen inside it.

If you are under about twenty-five people with one product and no security function at all, you can get most of the value without paying anyone. Run yourself against the CIS Critical Security Controls Implementation Group 1, which is a concrete list of things to configure rather than an abstraction, and revisit CSF once you have someone whose job includes security. An assessment that tells a five-person team it is at Tier 1 has spent money to confirm something everybody already knew.

And if you have an internal security lead who is already running a risk register and a roadmap, do not buy an assessment to validate them unless a board or an insurer specifically wants the outside opinion. Buy the specialist capability they lack instead, whether that is testing or an incident response retainer, and leave the framework work where it is.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.

Talk to usOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on NIST CSF. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.