Verigo Global
//NIST CSF Toolkit
US Gov FoundationNIST CSF v2.0

The NIST CSF toolkit, ready to deploy.

A complete, practitioner-maintained document set — 14 policies, 12 procedures, and subcategory templates across all six CSF v2.0 functions — tailored to your organization so you implement the framework without starting from a blank page.

Inside the toolkit
14
Approval-ready policies
12
Operational procedures
106
CSF v2.0 subcategory templates
120+
Profiles, tier checklists & samples
Overview

All six functions covered — from Govern to Recover.

The Verigo NIST CSF v2.0 toolkit is the document backbone of a structured cybersecurity program. NIST CSF v2.0 added the Govern function as the sixth pillar — this toolkit covers all six, with subcategory templates across every outcome statement from GV.OC-01 to RC.CO-04.

Each artefact is tailored to your sector, scope, and target tier — embedded into how you operate, the Compliance by Design way, so your current profile generates evidence continuously.

Profile-driven

Built around current and target profiles — so your implementation roadmap comes straight from the gap between the two.

Multi-framework ready

Subcategories are mapped to ISO 27001, HIPAA, PCI-DSS, and FISMA so evidence is reused across programs.

v2.0 native

Fully aligned to NIST CSF v2.0, including the new Govern function and the updated subcategory structure.

Coverage

All six functions — across four implementation tiers

The toolkit covers every CSF v2.0 outcome from Govern to Recover, with profile templates and tier checklists for Tier 1 through Tier 4.

Four implementation tiers
tier1
Partial

Starting point — ad hoc practices, risk management not integrated.

tier2
Risk Informed

Risk-aware but inconsistent — practices vary across the organization.

tier3Target
Repeatable

Formal and consistent — risk management is org-wide policy.

tier4
Adaptive

Optimizing — continuous adaptation based on threats and business needs.

Six CSF functions · 106 subcategories
GV
Govern
31 subcategories
ID
Identify
21 subcategories
PR
Protect
22 subcategories
DE
Detect
11 subcategories
RS
Respond
13 subcategories
RC
Recover
8 subcategories
Toolkit contents

Browse the full set — and take it with you

Explore every policy, procedure, and subcategory in the toolkit. Download any list as a branded PDF.

Policy Library
The complete, CSF v2.0-aligned policy set — 14 approval-ready policies covering all six functions.
01
Cybersecurity Policy
Top-level cybersecurity mandate, objectives, and management commitment.
02
Organizational Risk Management Policy
How cybersecurity risk is identified, assessed, and treated.
03
Supply Chain Risk Management Policy
Cybersecurity requirements for suppliers, vendors, and partners.
04
Asset Management Policy
Inventory, classification, and lifecycle management of assets.
05
Vulnerability Management Policy
Identifying, prioritizing, and remediating technical vulnerabilities.
06
Identity & Access Management Policy
Authentication, access control, and identity lifecycle.
07
Data Security Policy
Protecting data in transit, at rest, and throughout its lifecycle.
08
Platform & Infrastructure Security Policy
Securing technology components and infrastructure.
09
Security Awareness & Training Policy
Role-based training and organizational cybersecurity culture.
10
Continuous Monitoring Policy
Ongoing detection of cybersecurity events and anomalies.
11
Incident Response Policy
Detecting, analyzing, containing, and recovering from incidents.
12
Business Continuity & Recovery Policy
Maintaining and restoring operations after disruption.
13
Cybersecurity Roles & Responsibilities Policy
Authorities, accountabilities, and reporting structures.
14
Third-Party & Partner Security Policy
Security requirements in external relationships.
Packages

Build without the evaluation

Start from the document toolkit at $1,495 and add exactly what you need — see your custom total update live, then download a quote.

Starter

The complete document toolkit, ready to deploy.

All 14 policies, 12 procedures & 106 subcategory templates
Editable source files (Word & Excel)
Current & target profile templates
Implementation tier checklists
Most popular
Professional

The toolkit tailored to you, with practitioner guidance.

Everything in Starter
Documents tailored to your scope & target tier
Current/target profile workshop
Online readiness self-assessment
Enterprise

End-to-end implementation, from profile to practice.

Everything in Professional
Hands-on implementation support
Full profile gap analysis & remediation
Regulatory mapping (HIPAA, FISMA, PCI)
Starts from $1,495 · add only what you need · live pricing
Online evaluation · tier-aware

Know where you stand across all six functions.

Our NIST CSF evaluation scores your current state across all six functions — and maps every gap straight to the toolkit subcategory that closes it.

01

Pick your target tier

Tier 1–4 — your choice shapes the evaluation depth and recommendations.

02

Get your readiness score

Instant maturity score across GV, ID, PR, DE, RS, and RC.

03

Build your target profile

Every gap maps to the subcategory template that closes it.