Skip to content
All posts
Compliance10 min read

NIST Cybersecurity Framework Explained: A Practical Guide

What the NIST CSF actually asks of you, how its six functions map to awareness training, and how to use it without turning it into a documentation exercise.

ClickSafe Team

Security awareness · ClickSafe ·

The NIST Cybersecurity Framework is the most widely adopted security framework in the world and one of the most frequently misread. It is not a certification, there is no audit to pass, and nothing in it is legally binding on its own.

It is a common vocabulary for describing what your security programme does and how mature each part of it is. Used well, that is genuinely valuable. Used badly, it becomes a spreadsheet nobody reads.

The structure

The framework is organised into functions, each containing categories, each containing subcategories that describe specific outcomes.

Govern (added in version 2.0, 2024) covers organisational context, risk strategy, roles and responsibilities, policy, and oversight. Its addition was a deliberate correction: most programme failures are governance failures, not technical ones.

Identify covers knowing what you have and what threatens it: asset management, risk assessment, supply chain risk.

Protect covers safeguards: access control, data security, platform hardening, and awareness and training.

Detect covers noticing that something is happening: monitoring, and analysis of anomalies.

Respond covers incident management, analysis, communication, and mitigation.

Recover covers restoration of capability and the communications that go with it.

Where awareness training sits

Training lives primarily under Protect, in the PR.AT category, Awareness and Training. Version 2.0 keeps this deliberately short. The outcomes are that personnel are provided with awareness and training so they possess the knowledge and skills to perform relevant tasks, and that individuals in specialised roles receive training appropriate to those roles.

Two things follow from the wording that are easy to miss.

"Knowledge and skills to perform" is a capability statement. Completion records do not evidence it. Simulation results, report rates, and time-to-report do.

"Specialised roles" means role-differentiated content is expected. A single company-wide course does not satisfy the intent for finance, executives, or administrators.

Awareness also touches other functions, which is where most self-assessments under-credit themselves:

  • Detect (DE.CM, DE.AE): your employees are a detection control. Report rate is a detection metric.
  • Respond (RS.CO): whether people know how to report, and do so quickly, is part of response capability.
  • Govern (GV.RR): whether responsibilities are understood across the organisation.

Implementation tiers are not maturity levels

The four tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how integrated your risk management practice is. They are not a grading scale, and Tier 4 is not the goal for everyone. A fifty-person company operating deliberately at Tier 2 with clear reasoning is in better shape than one performing Tier 4 paperwork it cannot sustain.

Using it without drowning in documentation

Build a current profile before a target profile. Score honestly against the subcategories that apply to you. Optimistic self-assessment produces a useless plan.

Scope down aggressively. Not every subcategory applies to every organisation. Recording why something is out of scope is itself good governance.

Pick a small number of gaps per quarter. A profile identifying forty gaps produces paralysis. Three, with owners and dates, produces progress.

Store evidence as you go. The difference between a manageable assessment and a miserable one is entirely whether evidence was collected continuously or reconstructed afterwards.

What evidence for training looks like

For PR.AT, an assessor is looking for:

  • A defined curriculum with role differentiation, not one course for everybody
  • Delivery records showing frequency, not a single annual date
  • Evidence of effectiveness: simulation results over time, report rates, remedial training triggered by outcomes
  • Governance: a named owner, a documented cadence, results reported to leadership

Notice how much of that is trend data rather than a point-in-time attestation. A programme designed only to produce an annual certificate will struggle to evidence the middle two.

The common failure

Organisations treat the CSF as a compliance object rather than a planning tool. The framework is deliberately outcome-based and technology-neutral precisely so it can guide decisions rather than generate paperwork. If your CSF profile lives in a document that is opened twice a year, it is not doing the job it was designed for.


Related: how to calculate ROI on security awareness training covers presenting the resulting programme to a budget holder, and our security section sets out our own compliance posture.

ShareShare on LinkedIn#nist#compliance#framework

Find out what your click rate actually is

We will run a baseline campaign against your own team and show you the real number, not the one you hope for. Most teams are surprised.

20 minutes · Live product · No obligation