NIST CSF 2.0 · Evidence & Implementation Kit
A board, a customer, or a regulator wants your NIST CSF posture. Show it across all six Functions without building the Framework from scratch.
Every Subcategory of the Cybersecurity Framework 2.0 handed to you as an adopt-ready control, with the exact evidence an assessor examines and the finding they most often note. You personalize it, attach your evidence, and you have a defensible Profile.
A defensible CSF posture in a weekend, not a quarter.
Here is the honest situation. NIST CSF 2.0 is now the common language executives, customers, insurers, and regulators use to ask about your cybersecurity. The problem is producing a real posture: a control and evidence position for every Subcategory across Govern, Identify, Protect, Detect, Respond, and Recover, a current-versus-target Profile, and proof each outcome is met. A consultant charges thirty to seventy-five thousand dollars to build it. Doing it yourself is months while the questions keep coming.
This Kit removes the build. It is the complete CSF 2.0 control set and evidence guide, already written, that you personalize in a weekend.
What you get, the moment you buy
106
Subcategories as adopt-ready controls. Every outcome across all six Functions, written as real program language. Personalize the placeholders and you are done.
106
Evidence-they-examine checklists. For each Subcategory, the exact artifacts an assessor requests to confirm the outcome, plus the finding they most often note.
1
CSF Control Matrix, pre-built. Every Subcategory by Function and Category in a working spreadsheet, ready to record your implementation, in-place status and evidence location. This is your Profile.
1
Gap & Readiness Assessment. Score each Subcategory and the workbook tells you your posture as a single percentage, and exactly what to fix next.
Organized by the six Functions and their Categories, so you can present a current Profile to the board and a target Profile to your team. Editable Word and Excel files, current to CSF 2.0.
Built around the new Govern Function
CSF 2.0 added Govern: strategy, policy, roles, oversight, and cybersecurity supply chain risk management. It is where board-level and third-party questions now land, and where most programs are thinnest. This Kit gives Govern the same depth as the technical Functions, so your leadership and supplier story holds up.
What one control looks like
This is ID.AM-01, hardware asset inventory, in the Identify Function. All 106 are built to this depth.
ID.AM-01 Inventories of hardware are maintained IDENTIFY
Adopt this control
[Organization] maintains a complete and current inventory of all hardware assets it manages in a [CMDB or asset register], recording owner, location, network address, and business criticality. The inventory is populated through [automated discovery], reconciled [quarterly], and covers on-premises, cloud, remote, and mobile devices. Assets absent from the inventory are investigated and either enrolled or removed.
Evidence an assessor examines
- An export of the hardware inventory with owner, location, and criticality populated
- The discovery tool configuration and its most recent scan results
- A reconciliation record showing the last review and any exceptions
- The procedure defining inventory scope, frequency, and ownership
Common finding they note: the inventory covers servers and laptops but omits cloud instances, contractor devices, and network appliances, so it is not complete.
Why this is not another template pack
- The evidence is the point. Generic templates give you words. This tells you exactly what an assessor examines, and the finding they note, for every Subcategory. That is what makes your Profile defensible.
- All six Functions, including Govern. Complete coverage of the 2.0 structure, not a repackaged 1.1 with Govern bolted on.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. The controls you document here already count toward SOC 2, ISO 27001, and more, and the mappings show you where.
Who buys this
Security leaders and CISOs building or defending a program, GRC teams producing a CSF Profile for the board or a customer, and consultants running assessments. Whether you are adopting CSF for the first time or moving from 1.1 to 2.0, you save weeks and present a posture that holds up to scrutiny.
By the end of the weekend you will have
✓ A control mapped to every Subcategory
✓ A completed CSF Profile in the matrix
✓ A clear evidence list an assessor examines
✓ The new Govern Function properly covered
✓ A readiness percentage and a fix list
✓ The common findings closed before assessment
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Does this certify me? CSF is a framework, not a certification. This makes you assessment-ready and gives you a defensible Profile: the controls, the matrix, and the exact evidence a reviewer examines.
Does it cover CSF 2.0 or 1.1? 2.0, including the new Govern Function and the current Category and Subcategory structure.
Is it current? Yes, aligned to CSF 2.0. Updates included.
What if it is not for me? A 30-day money-back guarantee.
Do not let the next board or customer question catch your program short.
A consultant is thirty thousand dollars and months. The Kit is instant, and it is guaranteed.
Add it to your cart and have a defensible CSF posture this weekend.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com