What a cybersecurity framework is, and what it is not
A cybersecurity framework is a structured set of practices for managing cyber risk. It tells you what to do and roughly in what order, so you are not guessing which control matters most.
What a framework is not is a certification, and the distinction matters commercially. Some frameworks are voluntary guidance you adopt because it is sensible. Others are legal obligations that apply to your industry whether you like them or not. A third group are certifications that a customer or regulator can require you to hold and prove. Confusing the three is how businesses end up claiming compliance they do not have, which is worse than claiming nothing.
![]()
Think your IT is in good shape?
Take the free 3-minute readiness quiz
What changed recently
Three things have moved in the past two years that most guidance on this topic has not caught up with.
NIST CSF 2.0 arrived in February 2024, the first major revision since 2014. It added a sixth Function, Govern, alongside Identify, Protect, Detect, Respond and Recover. Govern covers the organizational side: who is accountable, how risk decisions get made, how supply chain risk is managed. It also formally broadened the framework beyond critical infrastructure to organizations of every size. If you read that CSF is for power plants, you are reading pre-2024 material.
NIST SP 800-61 Revision 3 landed in April 2025, restructuring incident response guidance around those same CSF 2.0 Functions and superseding the four-phase lifecycle.
CMMC became contractually real on 10 November 2025, when the DFARS rule took effect and Phase 1 of a three-year rollout began.
The frameworks worth knowing
NIST Cybersecurity Framework 2.0
The most widely adopted voluntary framework in the United States, and the usual starting point for a business that has no regulatory obligation forcing a particular choice.
Six Functions: Govern, Identify, Protect, Detect, Respond, Recover. It is deliberately outcome-based rather than prescriptive, which makes it adaptable but also means it will not hand you a checklist. Free, published by NIST.
CIS Critical Security Controls v8.1
Eighteen controls, ordered by priority, grouped into three Implementation Groups so a small business can start with IG1 and grow into the rest. Where CSF tells you what outcomes to aim for, CIS tells you what to do on Tuesday morning. For most SMBs it is the more actionable of the two, and the two map to each other cleanly.
ISO/IEC 27001
An international standard for an information security management system, and one you can be formally certified against by an accredited body. That certification is the reason it comes up: enterprise customers and international partners often ask for it contractually. The current version is the 2022 revision. Achieving it is a substantial program of work, not a configuration exercise.
HIPAA Security Rule
A legal obligation for covered entities and their business associates, not a voluntary framework. It requires administrative, physical and technical safeguards for electronic protected health information.
Worth being precise here, because a lot of published material currently is not. HHS issued a notice of proposed rulemaking on 27 December 2024 proposing significant strengthening of the Security Rule. That proposal is not final. The existing Security Rule remains in force. Content asserting that HIPAA now mandates multi-factor authentication is describing a proposal, not current law. Healthcare organizations should prepare for the direction of travel while complying with what is actually in effect.
PCI DSS
Required contractually by the payment card brands for any business that stores, processes or transmits cardholder data. Not a government regulation, but enforceable through your merchant agreement, and the fastest route to reducing scope is usually to stop handling card data directly.
CMMC
The Department of Defense program verifying that contractors protect controlled unclassified information. The DFARS rule took effect on 10 November 2025, starting a three-year phase-in, and CMMC requirements now appear in solicitations.
Level 1 covers basic safeguarding with annual self-assessment. Level 2 aligns to NIST SP 800-171 and, for most contracts, requires assessment by an accredited third party. Level 3 adds requirements for the highest-priority programs. If you are anywhere in the defense supply chain, this stopped being theoretical.
SOC 2
An attestation report produced by an independent CPA firm, commonly requested by enterprise buyers of software and services. Not a certification and not a government standard, but frequently the thing standing between a vendor and a large contract.
How to choose
Work through it in this order.
First, what is compulsory? Healthcare means HIPAA. Card payments mean PCI DSS. Defense contracting means CMMC. These are not choices.
Second, what do your customers demand? Enterprise buyers may require ISO 27001 or a SOC 2 report regardless of what regulators say. That is a sales requirement, and it belongs in the sales budget.
Third, what does your insurer expect? Cyber insurance applications increasingly ask about specific controls, and answers are treated as warranties. This is one of the more common places businesses discover a gap.
Finally, what improves your actual security? If nothing above binds you, start with CIS Controls IG1 and use CSF 2.0 to organize the conversation with leadership. That combination gives you a prioritized list of work and a language for reporting progress.
Most SMBs end up with one compulsory framework and one voluntary one, and that is a reasonable place to be. Adopting four frameworks properly is harder than adopting one, and a framework adopted badly is documentation rather than security.
Which framework fits which situation
A rough guide, and the reason most businesses need fewer frameworks than they fear.
A 30-person professional services firm with no regulatory obligation. CIS Controls Implementation Group 1, organized and reported through CSF 2.0. Nothing else is required, and doing those two properly puts you ahead of most of your peers.
A medical practice. HIPAA Security Rule is compulsory. CIS Controls give you the practical implementation detail the rule does not, since HIPAA tells you to be secure without telling you how.
A manufacturer selling into the defense supply chain. CMMC, at the level your contracts specify, built on NIST SP 800-171. Start early, because Level 2 third-party assessment is not a short process.
A software company selling to enterprises. SOC 2 first, because your buyers will ask for the report. ISO 27001 if you sell internationally or a specific contract demands it.
Anyone taking card payments. PCI DSS, and the first question worth asking is how to reduce scope by not handling card data directly.
What adoption actually involves
Choosing is the easy part, and it is where most articles stop.
Assess honestly. Compare what you do now against the framework and write down the gaps without softening them. A flattering assessment produces a plan that fixes nothing.
Prioritize by risk, not by effort. The temptation is to close the easy gaps first so the chart looks better. The gaps worth closing first are the ones an attacker would use.
Assign ownership with names. Controls owned by “IT” are owned by nobody.
Produce evidence as you go. The difference between being compliant and proving you are compliant is documentation, and reconstructing a year of it retrospectively is far harder than capturing it as you work.
Reassess on a schedule. Environments change, staff change, and controls decay quietly. A framework adopted once and never revisited describes a business that no longer exists.
Frequently asked questions
Which framework should a small business start with?
CIS Controls Implementation Group 1, unless a regulator or a customer has already decided for you. It is prioritized, practical, and achievable for a business without a security team.
Is NIST CSF a certification?
No. It is voluntary guidance, and there is no body that certifies you against it. You can say you align to it. You cannot be certified in it.
Does following a framework make us compliant?
Not automatically. Frameworks and regulations overlap but are not the same thing. CIS Controls will improve your HIPAA position substantially without being HIPAA compliance in itself.
How long does ISO 27001 certification take?
For most small and mid-sized organizations, a year is a realistic planning assumption from start to certificate, and it is a management-system program rather than a technical project.
Do we need more than one framework?
Most businesses end up with one compulsory obligation and one voluntary framework for structure. Adopting four properly is harder than adopting one, and a framework adopted badly is documentation rather than security.
Does CMMC apply to us if we are a subcontractor?
Frequently yes. Requirements flow down through the supply chain, so if controlled unclassified information reaches you, the obligation typically does too. Check your contracts rather than assuming.
A note on what we can and cannot claim
Corporate Technologies helps clients meet their own obligations under these frameworks. That is a different statement from Corporate Technologies holding a given certification, and any provider who blurs the two is worth a follow-up question. If a control matters to your compliance position, ask specifically who holds what, and get it in writing.
Where a managed provider helps
Frameworks fail in implementation, not selection. The gap is rarely knowing that MFA is required. It is enforcing it across every account, keeping it enforced as people join and leave, and being able to demonstrate it a year later to an auditor or an insurer.
We map your obligations, implement and enforce the controls, and produce the evidence when someone asks for it. Contact us or call 1-866-363-4628.
Sources
This page is general guidance and not legal, regulatory or insurance advice. Standards, rules and reporting obligations change, and the requirements that apply to your business depend on your sector, your contracts and your location. Corporate Technologies helps clients meet their own obligations and does not represent that it holds any particular certification unless stated. Confirm current requirements with your legal, compliance and insurance advisers.

