Compliance frameworks can feel like separate mountains: CMMC for defense work, NERC CIP for electric utilities, TSA directives for pipelines, plus insurer questionnaires and customer requirements. Smaller companies are often subject to a few of these at once, or to none of them but still want a sensible way to organize their security work. The NIST Cybersecurity Framework 2.0 is a useful common language for that purpose.
CSF is voluntary and flexible. It does not tell you which technical controls to buy. It organizes outcomes you should be able to demonstrate, which helps you see gaps and talk to leadership, insurers and customers in consistent terms.
The six functions
Version 2.0 of the framework was released by NIST in 2024 and organizes outcomes into six functions.
- Govern: establish and monitor your cybersecurity strategy, expectations, roles and policy.
- Identify: understand your assets, risks, suppliers and business context.
- Protect: put safeguards in place to manage risk.
- Detect: find possible attacks and compromises.
- Respond: take action when an incident is detected.
- Recover: restore capabilities after an incident.
Govern is the addition in 2.0, and it matters especially for smaller organizations, where security often lacks a clear owner or decision-making structure.
What each function looks like in a small company
Govern
- An executive owns cybersecurity risk and approves priorities and budget.
- Basic written policies exist, such as acceptable use, access, incident response and vendor management.
- Roles are assigned, including who leads during an incident.
- Legal and contractual obligations are listed.
Identify
- An inventory of devices, software, cloud services and data locations.
- A list of critical systems and how long you can be without them.
- A list of key suppliers, including IT providers and software vendors, and what access they have.
- A short risk list ranking what could hurt the business most.
For operators with control systems, include operational technology in the inventory.
Protect
- Multi-factor authentication and strong account management.
- Patching and secure configuration.
- Email and endpoint protection.
- Backups that are protected from tampering.
- Security awareness training.
- Network segmentation, especially between business and operational networks.
Detect
- Monitoring and alerting for endpoints, email and sign-ins.
- Logging of remote access and administrator actions.
- A clear route for staff to report suspicious activity.
Respond
- A written incident response plan with contacts, decision authority and communication steps.
- Defined reporting duties to customers, regulators and insurers.
- Practice through tabletop exercises.
Recover
- Tested restoration procedures with recovery priorities.
- A plan to communicate with employees and customers.
- A process to learn from incidents and improve.
Use profiles to set goals
CSF suggests creating a current profile, which describes where you are, and a target profile, which describes where you want to be. For a small company, that can be a simple spreadsheet listing each outcome, your current status and a target date. It becomes a roadmap and a reporting tool.
Scoring yourself on a basic scale, such as not started, partial or in place, is enough. Be honest and tie each rating to evidence.
Map to the obligations you actually have
Frameworks overlap. Many requirements in NIST SP 800-171, which underlies CMMC Level 2, correspond to CSF outcomes around access control, incident response, and system protection. NERC CIP and TSA directives address related themes for covered operational systems. Use CSF as an umbrella and note where a specific obligation requires more detail. This avoids building separate programs for every request, while still honoring the exact wording of the rules that bind you.
Use it with leadership and insurers
The six functions give executives a simple way to see strengths and weaknesses. A one-page summary showing progress in each function communicates better than a list of tools. Insurers and customers also tend to ask questions that fit within these categories, so organized answers save time.
Keep it practical
- Start with Govern and Identify, because the rest depends on them.
- Focus first on the few outcomes that reduce the most risk: MFA, backups, patching, email protection and incident planning.
- Revisit the profile at least twice a year.
- Do not chase perfect scores. Aim for steady, documented progress.
Where Ironfield Cyber fits
Ironfield Cyber helps contractors and energy companies use CSF as a roadmap, then align it with obligations like CMMC and NERC CIP context. If you would like a one-page current and target profile for your company, we can build it with you in a short working session.