NIST Security Audit: CSF 2.0, 800-53 and 800-171 Explained
Founder and Principal Security Consultant - CISSP, CEH, CHFI, Mandiant

A NIST security audit is an assessment of your security programme against a NIST publication: usually the Cybersecurity Framework 2.0, the SP 800-53 control catalogue, or SP 800-171 if you handle controlled unclassified information for a federal agency. Which one applies is not a preference. It is decided by who you sell to and what is in your contract.
Most articles on this subject explain the five Functions of the Cybersecurity Framework and stop. That explanation has been out of date since 26 February 2024, when NIST published CSF 2.0 and added a sixth. This guide covers what changed, which publication actually binds you, what an audit costs, and what the fourteen days consist of.
The short version
If nobody has named a NIST publication in a contract, you want CSF 2.0, and it is voluntary. If you sell to a federal agency and touch CUI, you are looking at SP 800-171 and probably CMMC. If you operate a federal system, it is SP 800-53 with an SP 800-37 authorisation. Everything else in this article follows from that split.
The Framework
NIST CSF 2.0: the sixth Function most articles still miss
CSF 2.0 replaced the 2018 version on 26 February 2024. The most consequential change was the addition of GOVERN, which sits beneath the other five and decides how they are prioritised. If a consultancy hands you an assessment built on five Functions, it is auditing you against a superseded framework.

The definitions above are NIST's own wording from CSWP 29. GOVERN matters because it is where the questions live that no tool can answer for you: who owns cyber risk, what your risk appetite is, how supply chain risk is managed, and whether any of that is reviewed. In practice it is also where most organisations score worst, because the preceding version let them skip it.
Tiers and Profiles, in plain terms
CSF 2.0 gives you two instruments besides the Core. Tiers describe how rigorous your risk management is, from Partial (Tier 1) through Risk Informed, Repeatable and Adaptive (Tier 4). They are not a maturity score to chase; they describe posture. Profiles are the useful part: a Current Profile records the outcomes you are achieving now, a Target Profile records the ones you have chosen to reach, and the gap between them is your action plan.
What that means for an audit
A NIST CSF audit is, concretely, the production of a Current Profile, an agreed Target Profile, and a prioritised plan to close the distance. NIST sets out five steps: scope the Profile, gather the information, create it, analyse the gaps and build the action plan, then implement and update. Any audit that ends at a score rather than an action plan has stopped one step early.
Scope
Which NIST publication actually applies to you

This is the question most guides never answer. The honest version is that CSF 2.0 is voluntary for everyone and useful to almost everyone, while 800-53 and 800-171 arrive through a contract rather than through good intentions.
- You sell software to a US federal agency. If you store, process or transmit CUI, the contract will carry DFARS 252.204-7012 or an equivalent and point at SP 800-171. Check which revision it names: Revision 3 superseded Revision 2 in May 2024 and reorganised the requirements into 17 families, while many live contracts and CMMC Level 2 still reference Revision 2 and its 110 requirements.
- You operate a federal information system. SP 800-53 controls, selected by a FIPS 199 impact categorisation, authorised through the SP 800-37 Risk Management Framework.
- You are a private company with no federal exposure. Nobody can compel you to do anything with NIST. CSF 2.0 is still the best-recognised vocabulary for answering a customer security review, and it maps cleanly onto SOC 2 and ISO 27001 evidence you may already hold.
The Catalogue
Inside SP 800-53: twenty families, three baselines
SP 800-53 Revision 5 is not a checklist, it is a catalogue. Controls are grouped into twenty families, and you do not implement all of them. You implement a baseline selected by how bad it would be if the system were compromised.

Two families are worth singling out because they are recent and routinely skipped. PT covers personally identifiable information processing and transparency, and SR covers supply chain risk, which Revision 5 promoted into a family of its own after a decade of supply chain incidents made the case.

FIPS 199 categorises the system as low, moderate or high impact against confidentiality, integrity and availability. The high-water mark across those three decides the baseline. The practical consequence is that a moderate system carries substantially more controls than a low one, so arguing your categorisation down is the single largest lever on the cost of compliance, and it has to be argued honestly.
The Engagement
What a NIST security audit actually consists of

The phases above are how we run it. The parts that vary between firms, and that you should ask about directly, are these.
- Is testing done on the live environment or from a questionnaire? A questionnaire audit records what people believe is configured. Only the first kind finds the service account with a password set in 2019.
- Does every finding carry an owner, an effort estimate and a priority? A finding without those three is a sentence, not a plan.
- Is the gap analysis expressed as a Target Profile? CSF 2.0 is built around that comparison. An audit that reports a percentage score has invented its own scale.
- Who signs what? A NIST CSF assessment has no certificate. There is no such thing as NIST certified. Anyone offering one is selling something else.
There is no NIST certification
This trips up more buyers than any other point. NIST publishes frameworks and control catalogues; it does not accredit assessors and it issues no certificates. CMMC is the exception that proves it, and even there the certificate comes from a C3PAO, not from NIST. If a vendor offers to make you "NIST certified", that is a signal about the vendor.
Budget
What it costs and how long it takes
Nobody publishes this, which is precisely why it belongs here. Ranges are for a company of twenty to two hundred staff, one to three environments.
| Engagement | Typical duration | Indicative cost | What moves the number |
|---|---|---|---|
| CSF 2.0 gap assessment | 2 to 3 weeks | From $5,000 | Number of environments, whether GOVERN evidence exists at all |
| SP 800-171 readiness | 4 to 8 weeks | $15,000 to $45,000 | CUI scope, how much of the boundary you can shrink first |
| SP 800-53 assessment, moderate baseline | 6 to 12 weeks | $30,000 to $90,000 | Baseline, system count, whether an SSP already exists |
| CMMC Level 2 certification assessment | Separate, after readiness | Paid to a C3PAO | Assessor availability, scope, remediation cycles |
| Our 20-domain cybersecurity audit | 14 days | From $5,000 up to 50 staff | Environments and frameworks mapped simultaneously |

The cheapest lever is scope, not price
On an 800-171 engagement the largest saving available is shrinking the CUI boundary before anyone audits it. Moving CUI into a defined enclave rather than letting it live across the whole estate can remove more cost than any negotiation on a day rate. Do that first, then get quotes.
Failure Modes
Five ways NIST audits go wrong

- Auditing against the 2018 framework. Five Functions instead of six. GOVERN is skipped, which is the half the board actually cares about.
- Buying the assessment before shrinking the scope. Especially with CUI. You pay to assess systems that never needed to be in scope.
- Treating the catalogue as a checklist. 800-53 has over a thousand controls across its families. Implementing them without a baseline selection is how a two-month project becomes a two-year one.
- Letting the firm that runs your IT also audit it. The assessment carries a conflict, and some auditors will say so in writing.
- Stopping at the score. NIST's own process ends with an implemented action plan and an updated Profile, not with a number in a slide.
FAQ
Frequently asked questions
What is a NIST security audit?
An assessment of your security programme against a NIST publication. Most often that is the Cybersecurity Framework 2.0, which produces a Current Profile, a Target Profile and a prioritised plan to close the gap. It can also mean an assessment against the SP 800-53 control catalogue or the 110 requirements of SP 800-171, depending on what your contract requires.
How many Functions does NIST CSF 2.0 have?
Six: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER. GOVERN was added in version 2.0, published on 26 February 2024, and it covers the risk management strategy, expectations and policy that determine how the other five are prioritised. Guides that describe five Functions are describing the 2018 framework.
Can you get NIST certified?
No. NIST publishes frameworks and control catalogues; it does not accredit assessors or issue certificates. The closest thing is CMMC, where a certificate is issued by an authorised third-party assessment organisation rather than by NIST. Any vendor offering to make you NIST certified is describing something that does not exist.
What is the difference between NIST 800-53 and NIST 800-171?
SP 800-53 is the full control catalogue used by federal information systems, organised into twenty families with baselines selected by impact. SP 800-171 is a much smaller set derived from it, aimed at non-federal organisations that handle controlled unclassified information on behalf of an agency. Revision 3, published May 2024, organises them into 17 families; Revision 2, which many contracts still name, listed 110 requirements. If you are a contractor rather than an agency, 800-171 is almost certainly the one in your contract.
How much does a NIST audit cost?
A CSF 2.0 gap assessment starts around $5,000. SP 800-171 readiness typically runs $15,000 to $45,000. A full SP 800-53 assessment at the moderate baseline is usually $30,000 to $90,000. The largest variable is scope, and the cheapest way to reduce cost is to shrink the boundary before the assessment rather than negotiate the day rate afterwards.
How long does a NIST security audit take?
A focused CSF gap assessment runs two to three weeks. Our own 20-domain audit delivers in fourteen days from kickoff. SP 800-171 readiness is four to eight weeks. A full 800-53 assessment at moderate baseline is six to twelve weeks. Remediation is separate and is usually the longer half.
Does NIST CSF replace SOC 2 or ISO 27001?
No, and they are not competing. CSF 2.0 is a way of organising and communicating cyber risk. SOC 2 and ISO 27001 produce an attestation or a certificate that a customer can be given. Most of the evidence overlaps heavily, so an organisation with a mature CSF Profile is usually much closer to SOC 2 than it expects.
We are a private company with no government contracts. Is any of this relevant?
CSF 2.0 is, because it is the most widely recognised vocabulary for answering the question a customer asks during a security review. 800-53 and 800-171 are not, unless a contract names them. Do not adopt a federal control catalogue voluntarily; adopt the framework and map it to whatever your customers actually ask for.
Next Step
Where to start
If a customer, an insurer or a prime contractor has asked where you stand against NIST, the fastest useful answer is a gap assessment that produces a Current Profile and a ranked plan, not a programme. Our cybersecurity audit covers twenty domains across your live environment and delivers in fourteen days, mapped to NIST 800-53, SOC 2, ISO 27001, NIST 800-171, CMMC and HIPAA at the same time, so one engagement answers whichever framework is being asked about. The price is fixed in writing before we start and you read the full report before you pay. Prices are published.
If the requirement is specifically a customer attestation rather than a framework, start with SOC 2 readiness. If it is operational technology, the NIST SP 800-82 audit is the right publication for plant and ICS environments.

Alexander Sverdlov
Founder of Atlant Security. CISSP, CEH, CHFI and Mandiant certified. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.
Connect on LinkedIn