Verigo Global
//NIST
US Gov FoundationCSF 2.0 · RMF

NIST CSF & RMF, built into how you operate.

The control language and risk discipline beneath US government compliance — and a common framework the whole market trusts. Verigo takes you from a CSF Profile and risk picture through the RMF lifecycle to an Authorization to Operate and continuous monitoring.

At a glance
Authority
NIST (US Dept. of Commerce)
CSF 2.0
6 Functions · 4 Tiers
RMF
7-step lifecycle to ATO
Control catalog
SP 800-53 · 800-171
6CSF 2.0 Functions
4CSF Implementation Tiers
7RMF lifecycle steps
ATOThe RMF endpoint
Why NIST matters

The foundation beneath the compliance landscape.

NIST does not sell certifications — it publishes the control catalogs and risk language that nearly everything else is built on. CMMC inherits its controls from NIST; ISO 27001 and SOC 2 map cleanly to it. Get NIST right and the rest gets dramatically easier.

The two pillars do different jobs. The CSF communicates and prioritizes risk in language a board understands; the RMF operationalizes it into a system that earns an Authorization to Operate. Together they cover strategy and execution.

For federal agencies the RMF is mandatory; for everyone else the CSF has become the vendor-neutral common language of cyber risk.

Why it carries weight

Build it once, reuse it everywhere.

Because NIST is the source the other frameworks reference, control evidence developed for NIST is highly reusable — the same work that earns an ATO can accelerate CMMC, ISO 27001, and SOC 2. NIST is the highest-leverage place to start.

CSF

Cybersecurity Framework — six Functions and four Tiers for understanding and communicating cyber risk.

RMF

Risk Management Framework — the seven-step process that takes a system to an Authorization to Operate.

The two pillars

CSF to communicate. RMF to operate.

Our NIST practice centers on the two frameworks most organizations actually need — the Cybersecurity Framework for risk strategy, and the Risk Management Framework for system authorization.

CSF 2.0

Cybersecurity Framework

Voluntary · risk communication

A flexible, outcome-based framework for understanding, managing, and communicating cybersecurity risk in plain language. Organized into six Functions, it gives leadership and technical teams a shared way to talk about posture — and a Profile to express where you are and where you want to be.

Six Functions, Categories & Subcategories
Current and Target Profiles
Four Implementation Tiers
Maps to 800-53, CSF, ISO 27001 & more
RMF

Risk Management Framework

Mandated · authorization process

The disciplined, seven-step process (SP 800-37) for building security and privacy into federal information systems and granting them an Authorization to Operate. Where the CSF communicates risk, the RMF operationalizes it — categorize, select, implement, assess, authorize, and monitor.

Seven-step lifecycle (SP 800-37)
Control selection from SP 800-53
Assessment under SP 800-53A
Drives the Authorization to Operate (ATO)
Coverage · CSF Core

Six Functions, one shared language.

The CSF organizes all cybersecurity outcomes into six Functions. Govern wraps the other five — making risk a leadership responsibility, not just a technical one.

New in 2.0
GV

Govern

Establish and monitor the cybersecurity risk strategy, expectations, roles, and policy. New in CSF 2.0.

ID

Identify

Understand the assets, data, suppliers, and risks that make up your environment.

PR

Protect

Put safeguards in place to manage risk and limit the impact of potential events.

DE

Detect

Find and analyze possible attacks and compromises in a timely way.

RS

Respond

Take action on a detected incident to contain and mitigate its effect.

RC

Recover

Restore assets and operations affected by an incident and return to normal.

CSF Implementation Tiers

Four tiers of risk-management rigor.

The CSF describes how disciplined your risk management is on a four-tier scale. You climb deliberately — the right tier is the one that reduces risk cost-effectively, not the highest one.

TIER 1
Partial
Ad hoc, reactive
TIER 2
Risk Informed
Aware, not org-wide
Typical target
TIER 3
Repeatable
Formal, organization-wide
TIER 4
Adaptive
Adaptive, continuous
Increasing rigor
1Partial

Risk is managed in an ad hoc, sometimes reactive way. There is limited awareness of cyber risk at the organizational level.

2Risk Informed

Risk-management practices are approved but may not be established organization-wide. Awareness exists but is inconsistent.

3Repeatable

Formal policies are defined and practiced consistently across the organization, with regular updates as risk changes — a common target.

4Adaptive

The organization adapts practices in near real time from lessons learned and predictive indicators, continuously improving.

The RMF lifecycle

Seven steps to an Authorization to Operate.

Where the CSF describes risk, the RMF (SP 800-37) acts on it — a repeatable lifecycle from preparation through authorization and into continuous monitoring.

1

Prepare

Ready the organization to manage security and privacy risks.

2

Categorize

Categorize the system and information by impact level (FIPS 199).

3

Select

Select an appropriate control baseline from SP 800-53.

4

Implement

Deploy the selected controls and document how they are applied.

5

Assess

Test the controls for effectiveness under SP 800-53A.

6

Authorize

A senior official accepts residual risk and grants the ATO.

7

Monitor

Continuously monitor controls and risk posture over time.

Monitor feeds back into the lifecycle — the RMF is continuous, not a one-time pass.
Who it applies to

Mandatory for some, invaluable for all.

NIST is the law of the land for federal systems — and the framework of choice for everyone who needs a credible, vendor-neutral way to manage cyber risk.

Federal agencies

For federal information systems, the RMF and an Authorization to Operate are mandated under FISMA — NIST is not optional, it is the law of the land.

Federal contractors & supply chain

Organizations handling federal data inherit NIST obligations — SP 800-171 for Controlled Unclassified Information, and the control language beneath CMMC.

Critical infrastructure operators

Energy, water, healthcare, and financial operators adopt the CSF to manage and communicate risk across sectors where disruption has outsized consequences.

Private-sector organizations

CSF 2.0 was broadened explicitly for organizations of every size and sector — a common, vendor-neutral language for cyber risk that boards and partners understand.

The roadmap to adoption

From risk picture to authorization.

A clear, sequenced path through NIST — profiling risk with the CSF and driving systems to authorization with the RMF. Durations are indicative for a mid-market organization.

2–3 wks
Scope & frame
Decide CSF, RMF, or both; define the systems, organizational scope, and risk context that frame the work.
3–5 wks
Current Profile / categorize
Build a CSF Current Profile and, for RMF, categorize systems by impact to set the right control baseline.
2–4 wks
Target Profile & control selection
Define the Target Profile and tier, and select the SP 800-53 controls that close the gap to it.
3–9 mo
Implement & remediate
Deploy controls, write policies, and build the evidence and System Security Plan the framework expects.
4–8 wks
Assess
Independently assess control effectiveness under SP 800-53A and resolve findings into a POA&M.
4–8 wks
Authorize & monitor
Support the ATO decision and stand up the continuous-monitoring program that keeps the authorization alive.
Adopting NIST

If you’re adopting NIST, start here.

NIST rewards clarity of intent. Decide what you are trying to achieve, categorize honestly, and instrument from the start — and the framework becomes a steady engine rather than a paperwork exercise. These are the three things to get right first.

Decide CSF, RMF, or both

They solve different problems. The CSF communicates and prioritizes risk in plain language; the RMF authorizes a system to operate. Many organizations need both — CSF to set direction, RMF to satisfy a federal mandate. Naming the goal first keeps the effort focused.

Categorize before you select controls

In the RMF, impact categorization drives everything downstream — get it wrong and you either over-control a low-impact system or under-protect a high-impact one. We anchor the baseline to a defensible categorization so control selection is right-sized from the start.

Build monitoring in, not on

An ATO is not a finish line — it is sustained by continuous monitoring. The organizations that renew cleanly are the ones that instrument evidence from day one. We design the monitoring program alongside the controls, not as an afterthought.

Outputs

What you walk away with.

Every NIST engagement produces the concrete artifacts an Authorizing Official and an auditor expect — and a program that keeps producing them as your risk evolves.

Current & Target Profiles

CSF Profiles that document where your cybersecurity posture stands today and where it needs to be — the gap, prioritized and made legible to leadership.

Categorization & control baseline

A defensible system impact categorization (FIPS 199) and the tailored SP 800-53 control baseline selected to match it.

System Security Plan (SSP)

The authoritative document describing your system, its boundary, and how each selected control is implemented — the backbone of any authorization package.

Assessment report & POA&M

A Security Assessment Report on control effectiveness plus a Plan of Action & Milestones tracking every gap to a named owner and date.

Authorization (ATO) support

A complete authorization package and the risk narrative an Authorizing Official needs to make — and defend — the decision to grant an ATO.

Continuous-monitoring program

The metrics, cadence, and tooling that keep your controls effective and your authorization current long after assessment day.

Client voices

Trusted across the NIST journey.

A few words from the security and risk leaders we’ve guided through CSF adoption and RMF authorization. Illustrative of typical engagements.

Verigo ran our RMF authorization end to end — categorization through ATO — and made the System Security Plan something our Authorizing Official could actually read. We received our authorization without a single blocking finding.

GO
Grace Okafor
CISO · Federal systems integrator

We adopted the CSF to get our board and our engineers speaking the same language about risk. The Current and Target Profiles Verigo built turned a vague worry into a funded, prioritized plan everyone understood.

DW
Daniel Whitfield
Director of Security · Regional energy utility

As a private fintech we weren’t mandated to use NIST, but our partners expected it. Verigo mapped the CSF to controls we already had and showed us exactly where the real gaps were — no boilerplate, no busywork.

SM
Sofia Mendez
VP of Risk · Payments platform
NIST questions

Good to know before we start.

Questions on CSF Profiles, Implementation Tiers, or the RMF and ATO process? A senior practitioner will walk you through it.

They serve different purposes. The Cybersecurity Framework (CSF) is a voluntary, outcome-based framework for understanding, prioritizing, and communicating cyber risk — a common language for leadership and technical teams. The Risk Management Framework (RMF) is a prescriptive, seven-step process for building security into systems and granting them an Authorization to Operate, and it is mandated for federal systems. Many organizations use the CSF to set direction and the RMF to satisfy a compliance obligation.

The foundation of trust

Ready to put NIST to work?

Tell us your systems, your obligations, and who you answer to. We'll confirm whether you need the CSF, the RMF, or both — and lay out a clear path from risk picture to authorization and continuous monitoring.