Back to Blog
Insights10 min read

NIST Security Audit: CSF 2.0, 800-53 and 800-171 Explained

A

Founder and Principal Security Consultant - CISSP, CEH, CHFI, Mandiant

NIST Security Audit: CSF 2.0, 800-53 and 800-171 Explained

A NIST security audit is an assessment of your security programme against a NIST publication: usually the Cybersecurity Framework 2.0, the SP 800-53 control catalogue, or SP 800-171 if you handle controlled unclassified information for a federal agency. Which one applies is not a preference. It is decided by who you sell to and what is in your contract.

Most articles on this subject explain the five Functions of the Cybersecurity Framework and stop. That explanation has been out of date since 26 February 2024, when NIST published CSF 2.0 and added a sixth. This guide covers what changed, which publication actually binds you, what an audit costs, and what the fourteen days consist of.

The short version

If nobody has named a NIST publication in a contract, you want CSF 2.0, and it is voluntary. If you sell to a federal agency and touch CUI, you are looking at SP 800-171 and probably CMMC. If you operate a federal system, it is SP 800-53 with an SP 800-37 authorisation. Everything else in this article follows from that split.

🧮

The Framework

NIST CSF 2.0: the sixth Function most articles still miss

CSF 2.0 replaced the 2018 version on 26 February 2024. The most consequential change was the addition of GOVERN, which sits beneath the other five and decides how they are prioritised. If a consultancy hands you an assessment built on five Functions, it is auditing you against a superseded framework.

NIST CSF 2.0 GOVERN function: a cybersecurity policy being signed off by two executives
GOVERN is where a NIST security audit finds most gaps: risk ownership and policy that a person signed, not a tool generated.
NIST CSF 2.0Six Functions. GOVERN was added in version 2.0 and sits under the other five.IDENTIFYIDRisks understoodPROTECTPRSafeguards usedDETECTDEAttacks foundRESPONDRSAction takenRECOVERRCOperations restoredGOVERNGVStrategy, expectations and policy are established, communicated and monitored. It informs how the other five are prioritised.Source: NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0, 26 February 2024
The six Functions of NIST CSF 2.0, with GOVERN added in version 2.0

The definitions above are NIST's own wording from CSWP 29. GOVERN matters because it is where the questions live that no tool can answer for you: who owns cyber risk, what your risk appetite is, how supply chain risk is managed, and whether any of that is reviewed. In practice it is also where most organisations score worst, because the preceding version let them skip it.

Tiers and Profiles, in plain terms

CSF 2.0 gives you two instruments besides the Core. Tiers describe how rigorous your risk management is, from Partial (Tier 1) through Risk Informed, Repeatable and Adaptive (Tier 4). They are not a maturity score to chase; they describe posture. Profiles are the useful part: a Current Profile records the outcomes you are achieving now, a Target Profile records the ones you have chosen to reach, and the gap between them is your action plan.

CSF 2.0 Tiers: how rigorous your risk management isA posture description, not a score to chase. Nobody is required to reach Tier 4.Tier 1PartialAd hoc, reactive, rarely writtendownTier 2Risk InformedApproved by management, notorganisation-wideTier 3RepeatableFormally approved, expressed aspolicy, updatedTier 4AdaptiveOrganisation-wide, adapts fromlessons learnedSource: NIST CSWP 29, Section on CSF Tiers
The four CSF 2.0 Tiers from Partial to Adaptive
The five steps NIST sets out for an Organizational ProfileAn assessment that stops at step three has produced a document, not an outcome.1Scope the Profile2Gather information3Create the Profile4Analyse gaps, plan5Implement, updateSource: NIST CSWP 29, creating and using Organizational Profiles
The five NIST steps for creating and using an Organizational Profile

What that means for an audit

A NIST CSF audit is, concretely, the production of a Current Profile, an agreed Target Profile, and a prioritised plan to close the distance. NIST sets out five steps: scope the Profile, gather the information, create it, analyse the gaps and build the action plan, then implement and update. Any audit that ends at a score rather than an action plan has stopped one step early.

📌

Scope

Which NIST publication actually applies to you

NIST SP 800-171 obligation arriving through a highlighted contract clause on a desk
NIST SP 800-53 and SP 800-171 reach you through a contract clause, not through good intentions. Read the clause before scoping the audit.
Which NIST publication applies to youThey are not alternatives. Most organisations touch more than one.PUBLICATIONWHO IT IS FORSTATUSWHAT IT GIVES YOUNIST CSF 2.0Any organisationVoluntaryA common language for managing cyber riskNIST SP 800-53Federal systems and their contractorsMandatory in scopeThe control catalogue itselfNIST SP 800-171Anyone handling CUI for a federal agencyContractualRev 3 (May 2024): 17 families. Basis of CMMC Level 2NIST SP 800-37Federal systemsMandatory in scopeThe RMF process for authorising a system
Which NIST publication applies, and whether it is voluntary or contractual

This is the question most guides never answer. The honest version is that CSF 2.0 is voluntary for everyone and useful to almost everyone, while 800-53 and 800-171 arrive through a contract rather than through good intentions.

Check which revision your contract actually namesPublished guidance moves faster than procurement does. The gap is where disputes start.PUBLICATIONSUPERSEDEDCURRENTWHAT CHANGEDNIST CSF1.1 (2018)2.0 (26 Feb 2024)Six Functions. GOVERN added.SP 800-171Rev 2 (2021)Rev 3 (May 2024)Rev 3 has 17 families. Many contracts still cite Rev 2.SP 800-53Rev 4Rev 520 families. PT and SR are new in Rev 5.
Current versus superseded revisions of the main NIST publications
  • You sell software to a US federal agency. If you store, process or transmit CUI, the contract will carry DFARS 252.204-7012 or an equivalent and point at SP 800-171. Check which revision it names: Revision 3 superseded Revision 2 in May 2024 and reorganised the requirements into 17 families, while many live contracts and CMMC Level 2 still reference Revision 2 and its 110 requirements.
  • You operate a federal information system. SP 800-53 controls, selected by a FIPS 199 impact categorisation, authorised through the SP 800-37 Risk Management Framework.
  • You are a private company with no federal exposure. Nobody can compel you to do anything with NIST. CSF 2.0 is still the best-recognised vocabulary for answering a customer security review, and it maps cleanly onto SOC 2 and ISO 27001 evidence you may already hold.
📦

The Catalogue

Inside SP 800-53: twenty families, three baselines

SP 800-53 Revision 5 is not a checklist, it is a catalogue. Controls are grouped into twenty families, and you do not implement all of them. You implement a baseline selected by how bad it would be if the system were compromised.

NIST SP 800-53 Rev 5 control catalogue as a thick tabbed technical standard on a desk
SP 800-53 Rev 5 is a catalogue of over a thousand controls. You implement a baseline from it, never the whole book.
NIST SP 800-53 Rev 5: the 20 control familiesA full audit covers every family. Ask any firm which ones they skip.ACAccess ControlATAwareness & TrainingAUAudit & AccountabilityCAAssessment & AuthorizationCMConfiguration ManagementCPContingency PlanningIAIdentification & AuthIRIncident ResponseMAMaintenanceMPMedia ProtectionPEPhysical & EnvironmentalPLPlanningPMProgram ManagementPSPersonnel SecurityPTPII ProcessingRARisk AssessmentSASystem & Services Acq.SCSystem & Comms ProtectionSISystem & Info IntegritySRSupply Chain Risk
The twenty control families in NIST SP 800-53 Revision 5

Two families are worth singling out because they are recent and routinely skipped. PT covers personally identifiable information processing and transparency, and SR covers supply chain risk, which Revision 5 promoted into a family of its own after a decade of supply chain incidents made the case.

FIPS 199 low moderate and high impact baselines shown as three stacks of paper of increasing height
Low, moderate and high are not effort levels you choose. The FIPS 199 categorisation decides them, and the workload follows.
Control baselines are chosen by impact, not by budgetFIPS 199 categorises the system; the baseline follows from that categorisation.LOWLimited adverse effectMODERATESerious adverse effectHIGHSevere or catastrophic effectSource: FIPS 199 and NIST SP 800-53B
The low, moderate and high control baselines and what triggers each

FIPS 199 categorises the system as low, moderate or high impact against confidentiality, integrity and availability. The high-water mark across those three decides the baseline. The practical consequence is that a moderate system carries substantially more controls than a low one, so arguing your categorisation down is the single largest lever on the cost of compliance, and it has to be argued honestly.

The Engagement

What a NIST security audit actually consists of

NIST security audit evidence phase: an engineer checking configuration against a printed control checklist
The evidence phase is the difference between an audit and a questionnaire: configuration checked on the running system.
What a CSF audit actually produces: the gapCurrent Profile against Target Profile, by Function. The distance between the bars is the action plan. Illustrative shape, not benchmark data.CurrentTargetGOVERNgap 50IDENTIFYgap 30PROTECTgap 30DETECTgap 40RESPONDgap 40RECOVERgap 45
A CSF audit output: Current Profile versus Target Profile by Function
What a 14-day NIST security audit actually looks likeFour phases. The observation window for a Type II report is separate and cannot be compressed.1Days 1-2Scope and accessSystems agreed in writing,read-only access granted2Days 3-8Evidence and testingConfiguration reviewed onthe live environment3Days 9-11Gap analysisCurrent state measuredagainst your Target Profile4Days 12-14Report and walkthroughRanked findings with owners,effort and a price to close
The four phases of a 14-day NIST security audit

The phases above are how we run it. The parts that vary between firms, and that you should ask about directly, are these.

  • Is testing done on the live environment or from a questionnaire? A questionnaire audit records what people believe is configured. Only the first kind finds the service account with a password set in 2019.
  • Does every finding carry an owner, an effort estimate and a priority? A finding without those three is a sentence, not a plan.
  • Is the gap analysis expressed as a Target Profile? CSF 2.0 is built around that comparison. An audit that reports a percentage score has invented its own scale.
  • Who signs what? A NIST CSF assessment has no certificate. There is no such thing as NIST certified. Anyone offering one is selling something else.

There is no NIST certification

This trips up more buyers than any other point. NIST publishes frameworks and control catalogues; it does not accredit assessors and it issues no certificates. CMMC is the exception that proves it, and even there the certificate comes from a C3PAO, not from NIST. If a vendor offers to make you "NIST certified", that is a signal about the vendor.

💰

Budget

What it costs and how long it takes

Nobody publishes this, which is precisely why it belongs here. Ranges are for a company of twenty to two hundred staff, one to three environments.

What each engagement costs against how long it takesBar length is duration in weeks. The figure on the right is indicative cost for a 20 to 200 person company.0w4w8w12wCSF 2.0 gap assessmentfrom $5,000Our 20-domain auditfrom $5,000SP 800-171 readiness$15k to $45kSP 800-53, moderate baseline$30k to $90kRemediation is separate and is usually the longer half.
Duration in weeks and indicative cost for each NIST engagement type
EngagementTypical durationIndicative costWhat moves the number
CSF 2.0 gap assessment2 to 3 weeksFrom $5,000Number of environments, whether GOVERN evidence exists at all
SP 800-171 readiness4 to 8 weeks$15,000 to $45,000CUI scope, how much of the boundary you can shrink first
SP 800-53 assessment, moderate baseline6 to 12 weeks$30,000 to $90,000Baseline, system count, whether an SSP already exists
CMMC Level 2 certification assessmentSeparate, after readinessPaid to a C3PAOAssessor availability, scope, remediation cycles
Our 20-domain cybersecurity audit14 daysFrom $5,000 up to 50 staffEnvironments and frameworks mapped simultaneously
Reducing NIST 800-171 CUI scope shown as a painted boundary line across a facility floor
The largest saving on an 800-171 engagement is drawing a smaller boundary before anyone assesses it.

The cheapest lever is scope, not price

On an 800-171 engagement the largest saving available is shrinking the CUI boundary before anyone audits it. Moving CUI into a defined enclave rather than letting it live across the whole estate can remove more cost than any negotiation on a day rate. Do that first, then get quotes.

Failure Modes

Five ways NIST audits go wrong

NIST security audit deliverable: a ranked remediation plan being walked through at a table
The output of a NIST security audit is a ranked plan with owners and effort, walked through with your team. Not a score.
  • Auditing against the 2018 framework. Five Functions instead of six. GOVERN is skipped, which is the half the board actually cares about.
  • Buying the assessment before shrinking the scope. Especially with CUI. You pay to assess systems that never needed to be in scope.
  • Treating the catalogue as a checklist. 800-53 has over a thousand controls across its families. Implementing them without a baseline selection is how a two-month project becomes a two-year one.
  • Letting the firm that runs your IT also audit it. The assessment carries a conflict, and some auditors will say so in writing.
  • Stopping at the score. NIST's own process ends with an implemented action plan and an updated Profile, not with a number in a slide.

FAQ

Frequently asked questions

What is a NIST security audit?

An assessment of your security programme against a NIST publication. Most often that is the Cybersecurity Framework 2.0, which produces a Current Profile, a Target Profile and a prioritised plan to close the gap. It can also mean an assessment against the SP 800-53 control catalogue or the 110 requirements of SP 800-171, depending on what your contract requires.

How many Functions does NIST CSF 2.0 have?

Six: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER. GOVERN was added in version 2.0, published on 26 February 2024, and it covers the risk management strategy, expectations and policy that determine how the other five are prioritised. Guides that describe five Functions are describing the 2018 framework.

Can you get NIST certified?

No. NIST publishes frameworks and control catalogues; it does not accredit assessors or issue certificates. The closest thing is CMMC, where a certificate is issued by an authorised third-party assessment organisation rather than by NIST. Any vendor offering to make you NIST certified is describing something that does not exist.

What is the difference between NIST 800-53 and NIST 800-171?

SP 800-53 is the full control catalogue used by federal information systems, organised into twenty families with baselines selected by impact. SP 800-171 is a much smaller set derived from it, aimed at non-federal organisations that handle controlled unclassified information on behalf of an agency. Revision 3, published May 2024, organises them into 17 families; Revision 2, which many contracts still name, listed 110 requirements. If you are a contractor rather than an agency, 800-171 is almost certainly the one in your contract.

How much does a NIST audit cost?

A CSF 2.0 gap assessment starts around $5,000. SP 800-171 readiness typically runs $15,000 to $45,000. A full SP 800-53 assessment at the moderate baseline is usually $30,000 to $90,000. The largest variable is scope, and the cheapest way to reduce cost is to shrink the boundary before the assessment rather than negotiate the day rate afterwards.

How long does a NIST security audit take?

A focused CSF gap assessment runs two to three weeks. Our own 20-domain audit delivers in fourteen days from kickoff. SP 800-171 readiness is four to eight weeks. A full 800-53 assessment at moderate baseline is six to twelve weeks. Remediation is separate and is usually the longer half.

Does NIST CSF replace SOC 2 or ISO 27001?

No, and they are not competing. CSF 2.0 is a way of organising and communicating cyber risk. SOC 2 and ISO 27001 produce an attestation or a certificate that a customer can be given. Most of the evidence overlaps heavily, so an organisation with a mature CSF Profile is usually much closer to SOC 2 than it expects.

We are a private company with no government contracts. Is any of this relevant?

CSF 2.0 is, because it is the most widely recognised vocabulary for answering the question a customer asks during a security review. 800-53 and 800-171 are not, unless a contract names them. Do not adopt a federal control catalogue voluntarily; adopt the framework and map it to whatever your customers actually ask for.

🔗

Next Step

Where to start

If a customer, an insurer or a prime contractor has asked where you stand against NIST, the fastest useful answer is a gap assessment that produces a Current Profile and a ranked plan, not a programme. Our cybersecurity audit covers twenty domains across your live environment and delivers in fourteen days, mapped to NIST 800-53, SOC 2, ISO 27001, NIST 800-171, CMMC and HIPAA at the same time, so one engagement answers whichever framework is being asked about. The price is fixed in writing before we start and you read the full report before you pay. Prices are published.

Evidence you gather once and use four timesMost of a NIST audit is reusable. This is why one engagement can answer several frameworks at the same time.CSF 2.0SOC 2ISO 27001800-171Asset inventoryAccess reviewsIncident response planRisk assessmentVendor / supply chainBoard-level governanceCUI boundary definitionAuditor attestation
Which audit evidence is reusable across CSF 2.0, SOC 2, ISO 27001 and 800-171

If the requirement is specifically a customer attestation rather than a framework, start with SOC 2 readiness. If it is operational technology, the NIST SP 800-82 audit is the right publication for plant and ICS environments.

Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. CISSP, CEH, CHFI and Mandiant certified. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.

Connect on LinkedIn