NIST CSF 2.0 readiness | Firemind
NIST CSF 2.0

Scored subcategory by subcategory.With a verdict and the evidence for each.

The framework most boards recognise, mapped onto technical evidence that already lives in your cloud accounts.

CSF 2.0 subcategories
Pinned verdict rules
Read-only on production
Evidence per subcategory
Manual review named, not guessed
First report within days
The problem

The framework the board recognises, and the evidence sits in the cloud accounts.

CSF 2.0 subcategories map cleanly onto technical evidence. What is inventoried, what is encrypted, what is logged, what is backed up, what is patched.

The IT Operations Engine gathers that evidence read-only across your accounts and scores each in-scope subcategory as implemented, exception or manual review.

What a readiness report has to do

  • Score each in-scope subcategory as implemented, an exception, or something a human must judge
  • Use pinned verdict rules, so the same evidence always scores the same way
  • Attach the evidence to the verdict rather than asserting the verdict
  • Make no changes to production while it assesses
  • Produce a percentage that means something because it moves between reports
What we do

Evidence, verdict, and an honest line where judgement is needed.

The engine reads identity, encryption, certificates, secrets, backup, audit logging, configuration recording, threat detection, vulnerability findings, systems management, networking and tagging, and returns a verdict per subcategory with the evidence attached. Governance subcategories that live in policy rather than configuration are surfaced for manual review rather than scored automatically.

Identity and secrets
Encryption and certificates
Backup and logging
Threat detection
Vulnerability findings

Find, fix, keep green

    • Find - The engine assesses the focused technical subcategories of CSF 2.0 against read-only evidence from identity, encryption, certificates, secrets, backup, audit logging, configuration recording, threat detection, vulnerability findings, systems management, networking and tagging. Each subcategory returns a verdict with the evidence attached, using pinned verdict rules so the same evidence always scores the same way. The report states what is implemented, what is an exception, and what a human needs to judge. On production accounts it makes no changes.
    • Fix - Every exception carries a remediation path, executed under your authority model or raised as a pull request.
    • Keep green - The assessment runs as a cadence. A readiness percentage that moves between reports is what a board can act on.

Want a readiness number your board can act on?

One production account, read-only. The first report is usually available within days.

Scope a pilot →
How it starts

One production account, read-only.

The first report is usually available within days of access being granted.

  • Read-only access

    One production account. The engine reads the evidence and changes nothing, which is what makes running this against production acceptable.

    • No changes on production accounts
    • Evidence read from what is actually configured
    • First report usually within days
  • Verdict per subcategory

    Each in-scope subcategory comes back as implemented, an exception, or something needing human judgement, with the evidence attached and pinned verdict rules behind it.

    • The same evidence always scores the same way
    • Governance subcategories surfaced, not guessed
    • Evidence attached to every verdict
  • A percentage that moves

    Exceptions carry a remediation path, and the assessment runs again. The trend between reports is what a board can act on.

    • Configuration fixes under your authority model
    • Code fixes as pull requests
    • The second report is the useful one
What stays with you

The governance subcategories that live in policy and people.

The engine scores what it can evidence technically and says clearly where a human judgement is needed.

You gain:

  • This is not the full framework. The engine scores the subcategories with technical evidence in cloud accounts.
  • Governance and policy subcategories are surfaced for manual review rather than scored automatically.
  • Pinned verdict rules mean two runs over the same evidence do not disagree with each other.

FAQ

Questions.

The engine scores the subcategories with technical evidence in cloud accounts. Governance and policy subcategories are surfaced for manual review rather than scored automatically.

Start with one production account, read-only.

The first report is usually available within days, with a verdict and the evidence behind each in-scope subcategory.

Your benefits:

  • Board-recognised - the framework they already ask about.
  • Pinned rules - the same evidence always scores the same way.
  • Read-only - safe to run against production.
  • Honest gaps - manual review named rather than guessed.

What happens next?

Talk.

A focused discussion about which subcategories are in scope for you.

Score.

One production account, read-only, with the first report within days.

Trend.

Exceptions closed, the assessment repeated, the percentage moving.

No obligation. Just a focused discussion about your CSF position.

We'll only use your details to respond to your enquiry. No newsletters unless you ask for them.