NIST CSF 2.0 Starter Compliance
A curated subset of the 15 most critical NIST Cybersecurity Framework 2.0 subcategories, designed by MyCISO to help organisations begin adopting the framework with focused, high-impact actions.
Overview
NIST CSF 2.0 Starter selects 15 critical subcategories spanning all six NIST CSF functions.
It is a MyCISO derivative framework designed as a practical entry point to NIST CSF adoption.
The selection ensures balanced coverage of Govern, Identify, Protect, Detect, Respond, and Recover.
Implementation typically takes four to eight weeks with progress tracked in the MyCISO platform.
Starter is step one in a progression path toward full NIST CSF 2.0 implementation.
Key Areas
- GV.OC-01 - Organisational context and mission are understood
- GV.RM-01 - Risk management objectives are established
- ID.AM-01 - Inventories of hardware and software assets are maintained
- ID.RA-01 - Vulnerabilities in assets are identified
- PR.AA-01 - Identities and credentials are managed
- PR.AA-03 - Users are authenticated
- PR.AT-01 - Security awareness training is provided
- PR.DS-01 - Data at rest is protected
- PR.PS-01 - Configuration management practices are established
- DE.CM-01 - Networks and network services are monitored
- DE.CM-09 - Computing hardware, software, and services are monitored
- DE.AE-02 - Potentially adverse events are analysed
- RS.MA-01 - Incident response plan is executed
- RS.CO-02 - Internal and external stakeholders are notified of incidents
- RC.RP-01 - Recovery plan is executed
Who It's For
- Organisations exploring NIST CSF as their primary cybersecurity framework
- US-based or US-regulated organisations that need NIST alignment
- Critical infrastructure operators beginning their NIST CSF adoption
- Small to mid-size organisations that find the full framework overwhelming
- Security teams that want a balanced starting point across all cybersecurity functions
Core Requirements
- Policies and Governance
- Establish organisational context (GV.OC-01) by documenting the organisation's mission, stakeholder expectations, and legal/regulatory requirements. Define risk management objectives (GV.RM-01) that align with business goals.
- Risk Management
- Maintain asset inventories (ID.AM-01) and identify vulnerabilities (ID.RA-01) through regular scanning or assessment. These two subcategories provide the foundation for risk-informed decision-making.
- Security Controls
- Implement identity management (PR.AA-01), multi-factor authentication (PR.AA-03), data protection (PR.DS-01), and configuration management (PR.PS-01). Provide security awareness training (PR.AT-01) to all staff.
- Incident Response
- Execute the incident response plan (RS.MA-01) when incidents occur and notify stakeholders (RS.CO-02). Maintain a recovery plan (RC.RP-01) that can be activated after significant events.
- Evidence and Reporting
- Track maturity against each of the 15 subcategories in the MyCISO platform. Maintain evidence of asset inventories, vulnerability assessments, training records, and incident response activities.
Implementation Steps
- Establish context - Document your organisational context and define risk management objectives. This sets the foundation for all subsequent activities and aligns security with business priorities.
- Asset visibility - Build inventories of hardware and software assets. You cannot protect what you do not know you have. This step feeds directly into vulnerability identification.
- Protect fundamentals - Implement identity management, authentication, data protection, and configuration management. Deliver security awareness training to all staff.
- Detection capability - Establish network and system monitoring. Define what constitutes an adverse event and how detected events are analysed and escalated.
- Response and recovery - Document and test your incident response plan. Define stakeholder notification procedures. Establish a basic recovery plan for critical systems.
- Review and expand - Assess maturity across all 15 subcategories. When comfortable, progress to NIST CSF 2.0 Essentials to expand coverage across the full framework.
Frequently Asked Questions
- Is NIST CSF 2.0 Starter an official NIST product?
- No. It is a derivative framework created by MyCISO that selects key subcategories from NIST CSF 2.0. It is designed as a practical on-ramp to the full framework.
- How were the 15 subcategories selected?
- MyCISO selected subcategories that cover all six NIST CSF functions, address the most common risk areas, and provide the greatest security uplift. The selection balances governance, protection, detection, and response capabilities.
- Can I use Starter for regulatory compliance?
- Starter is not a compliance certification. However, demonstrating structured adoption of NIST CSF-aligned practices can support regulatory discussions, particularly in industries that reference NIST CSF.
- What is the difference between NIST CSF Starter and ISO 27001 Starter?
- Both are MyCISO derivatives with 15 controls. NIST CSF Starter follows the six-function structure (Govern, Identify, Protect, Detect, Respond, Recover) while ISO 27001 Starter follows the four-theme structure of Annex A. Choose based on which full framework you plan to adopt.
Why It Matters
- NIST CSF is the most widely adopted cybersecurity framework globally, but its breadth can be a barrier to adoption for smaller organisations. Starter makes the framework accessible by focusing on the subcategories that matter most.
- By covering all six NIST CSF functions from the outset, Starter gives organisations a balanced view of cybersecurity rather than over-investing in one area. This is a key principle of the NIST CSF approach.
- Organisations that adopt NIST CSF Starter build familiarity with the framework's language and structure, making the progression to the full framework natural rather than disruptive.
Common Challenges
- Defining organisational context too narrowly, missing key stakeholder expectations or regulatory obligations
- Building asset inventories that quickly become outdated without automated discovery tools
- Implementing monitoring tools without the processes or skills to analyse alerts effectively
- Treating incident response planning as a document rather than a practiced capability
- Neglecting the Recover function because it seems less urgent than Protect and Detect