NIST CSF
Readiness
NIST CSF is not something you pass - it is a way to describe where your security programme is and where you have decided it should be. We run CSF readiness when you need a credible, board-legible picture of your posture without an auditor attached.
Who this is for
Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.
Companies whose board or insurer has asked for a structured view of security maturity
Organisations choosing a security strategy and needing a defensible baseline to plan against
Teams whose customers ask for a framework position but not a specific certificate
Companies preparing for a certifiable framework later and wanting the gap picture now
What the engagement does
Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.
- Build the Current Profile - what is actually in place across Govern, Identify, Protect, Detect, Respond and Recover
- Agree the Target Profile with you, based on your risk and your obligations rather than an aspiration to score highly
- Identify and prioritise the gaps between the two
- Map the work to whatever certifiable framework is coming next so nothing is wasted
- Produce a roadmap with owners and sequencing
- Give you the reporting a board can read without translation
What you walk away with
A Current and Target Profile, a prioritised gap list, and a roadmap. CSF 2.0 added the Govern function, which is usually where the honest findings are - not because the technology is missing, but because nobody owns it.
How it runs
Four phases. You always know which one you are in and what is outstanding.
Scoping call
We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.
Assessment
We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.
Remediate and evidence
We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.
Hand off to your assessor
You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.
What the assessment covers
The control areas we walk for NIST CSF. Each breaks down into individual controls carrying status, owner and evidence in Talon.
There is no CSF certification. The framework is deliberately descriptive. Readiness produces a defensible profile and a plan, which is what CSF is designed to give you.
It runs in Talon, not in a spreadsheet
Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.
- Control-by-control status, kept current by the people doing the work
- Evidence filed against the control it satisfies, with expiry dates tracked
- The auditor request list, so nothing is chased over email
- A readiness view that shows what an assessor would see
Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.
Our partnersAsked on almost every NIST CSF call
No, and that is by design. CSF describes outcomes rather than prescribing controls, so there is nothing to certify against. What you can have is a documented profile and an independent assessment of it.
The Govern function was added, making governance, roles, policy and supply chain risk first-class rather than implied. In most assessments, Govern is where the weakest scores land.
As a planning layer, yes. CSF gives you the strategic picture and the sequencing; SOC 2 gives you the report a buyer accepts. Doing CSF first tends to make the SOC 2 gap list shorter and less surprising.
Tiers describe how rigorous and integrated your risk management practices are, from Partial to Adaptive. They are not maturity levels to be maximised - the right Tier is the one that matches your risk.
Rarely run alone
Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.
NIST CSF readiness, on your timeline
A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.