Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Governance, Risk & Compliance

NIST CSF 2.0 is a conversation with your board, not a control list.

A NIST CSF consultant in India is most often brought in to answer a question that sounds simple and is not: how good is our security, compared with how good it needs to be? The Cybersecurity Framework is built for exactly that question. It is outcome-based rather than prescriptive, which is its great strength and the reason it is so often misused as a checklist.

Version 2.0, published in February 2024, added a sixth function, Govern, and widened the framework's audience beyond critical infrastructure to organisations of any size. That addition matters more than it sounds. It moved roles, policy, risk appetite and supply-chain oversight from something implied across the other functions to something assessed in its own right, which is usually where the honest gaps turn out to be.

There is no such thing as being certified against NIST CSF, and anyone offering you a certificate is selling something the framework does not issue. What it produces is a Current Profile, a Target Profile and the distance between them, expressed as a prioritised plan. If you also need a certifiable standard, ISO 27001:2022 is the usual companion and the two map cleanly onto each other.

Why you need it

01 / 06

Why this framework and not another.

01

It is the language boards and regulators already speak.

Identify, Protect, Detect, Respond, Recover and now Govern are six words a non-technical director can hold in their head. A roadmap expressed in those terms survives the journey to a board paper without needing translation into and out of control numbers.

02

Govern is where most organisations actually fail.

The 2.0 addition covers organisational context, risk strategy, roles and authorities, policy, oversight and supply-chain risk management. These are the outcomes that are hardest to buy and easiest to defer, and they are the ones that decide whether the rest holds together.

03

Tiers are not a maturity score, and treating them as one misleads.

The four tiers describe how rigorously risk management practices are governed and integrated, not how many controls you have. An organisation can be Tier 2 with excellent tooling, and the framework says that is a legitimate choice if it matches your risk appetite.

04

It maps to everything else you are being asked for.

NIST publishes informative references from CSF subcategories to SP 800-53, ISO 27001 and others. One assessment can therefore feed several obligations, which is the argument for starting here when you have more than one framework in your future.

Instrument

02 / 06

One assessment, several obligations.

The overlap between CSF outcomes and the frameworks you are probably also being asked for, before you scope two programmes that were always one.

What we deliver

03 / 06

What we deliver.

01

Current Profile

An honest assessment against the subcategories that apply to you, evidenced by interview, configuration review and document sampling rather than by a self-scored spreadsheet. The number that comes out is the one we can defend.

02

Target Profile

Where you actually need to be, agreed with you against your sector, your regulatory position, your risk appetite and your customers’ expectations. Not every organisation needs every outcome at the same level, and pretending otherwise produces a plan nobody funds.

03

Tier assessment

Where your risk-management practices sit across the four tiers, function by function, with the specific practices that would move a function up one, and an opinion on whether moving it is worth the money.

04

Gap analysis and prioritised roadmap

The distance between Current and Target, sequenced by risk reduced per unit of effort, with owners and indicative timelines. Written so it can go to a board without a covering translation.

05

Organisational Profile and governance artefacts

The Govern function made concrete: cybersecurity roles and authorities, risk appetite statements, policy hierarchy, and the supply-chain risk management practices the 2.0 revision expects.

06

Reassessment

A repeat of the Current Profile on the same method after the roadmap has run, so movement is measured rather than asserted. The comparison is only meaningful if the method did not change, which is why we keep it.

How we run it

04 / 06

The engagement, step by step.

  1. 01

    Scope and context

    Which parts of the organisation, which systems, and what the business actually depends on. The Govern function starts here, because organisational context is its first category.

    Week 1
  2. 02

    Evidence gathering

    Interviews across security, IT, engineering and the business, configuration review, and sampling of the documents that are supposed to exist.

    Weeks 2-4
  3. 03

    Current Profile

    Score every applicable subcategory with the evidence behind it, and flag where the evidence was thin rather than quietly averaging it away.

    Weeks 4-5
  4. 04

    Target Profile workshop

    Agree the target with you, function by function. This is a decision about risk appetite and budget, so it is made in a room with the people who own both.

    Week 6
  5. 05

    Roadmap

    Sequence the gaps into a plan with owners, effort estimates and dependencies, and present it to the board or audit committee if that is where it needs to land.

    Weeks 7-8
  6. 06

    Reassess

    Re-run the Current Profile on the same method once the roadmap has had time to bite, and show the movement.

    Month 9-12

Key benefits

05 / 06

What changes afterwards.

A security budget with an argument behind it

A funding request framed as the distance between an assessed Current Profile and an agreed Target Profile is a very different conversation from a list of products, and it tends to survive the budget round intact.

One assessment that feeds several obligations

Because CSF subcategories map to SP 800-53, ISO 27001 and the questionnaires customers send, the same evidence answers several demands instead of being gathered separately each time.

Governance that is written down

Roles, authorities, risk appetite and supply-chain oversight stop being understood and start being documented, which is what makes the rest of the programme durable when people change.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Framework

  • NIST Cybersecurity Framework 2.0
  • NIST CSF 2.0 Informative References
  • NIST SP 800-53 Rev 5

Assessment

  • CSF 2.0 Organizational Profile templates
  • Structured interview protocol
  • Configuration and document sampling

Technical validation

  • Nessus
  • BloodHound
  • AphelioNYX AD Pen-Test

Mapping

  • NIST OLIR references
  • AphelioNYX Frameworks Hub

Reporting

  • Board-level profile comparison
  • Prioritised roadmap with owners

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

Asked often enough to answer here.

Can we be certified against NIST CSF?
No. There is no certification scheme for the Cybersecurity Framework and NIST does not issue one, so any organisation offering you a NIST CSF certificate is offering something the framework does not recognise. What you can have is an assessed Current Profile, an agreed Target Profile and independent verification that the gap was closed. If a customer or regulator needs a certificate, ISO 27001:2022 is the standard that provides one, and the two map onto each other well enough that the work is largely shared.
What did 2.0 change from version 1.1?
The most significant change is the addition of Govern as a sixth function, covering organisational context, risk management strategy, roles and authorities, policy, oversight and cybersecurity supply-chain risk management. The framework also dropped its critical-infrastructure framing to apply to organisations of any size and sector, restructured and clarified many subcategories, and added implementation examples and quick-start guides. If you assessed against 1.1, the Govern function is where your new gaps will be.
How is a tier different from a maturity score?
A tier describes how rigorous and integrated your risk-management practices are (Partial, Risk Informed, Repeatable, Adaptive) not how many controls you have deployed. It is entirely coherent to be at Tier 2 by deliberate choice because that matches your risk appetite and budget. Treating tiers as a maturity ladder to be climbed leads organisations to spend money proving a number rather than reducing a risk, which is the opposite of what the framework is for.
Is NIST CSF relevant for an Indian organisation?
Yes, and for two reasons. First, it is sector-agnostic and jurisdiction-agnostic by design. It describes outcomes, not legal requirements, so nothing in it is specific to the United States. Second, it is the framework most commonly referenced by multinational customers and insurers when they ask how you manage cyber risk, so an assessed profile answers a question you are likely to be asked anyway. It also sits comfortably alongside DPDP Act obligations rather than competing with them.
How long does an assessment take?
Six to eight weeks for the first full assessment of a mid-sized organisation, from scoping to a roadmap presented. The variable is evidence gathering: organisations with documentation already in place move quickly, while those where most of the answer lives in people’s heads need more interview time. The reassessment at nine to twelve months is much shorter, typically two to three weeks, because the method and the scope are already established.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.