NIST CSF 2.0 · Cyber Governance Benchmark

NIST CSF 2.0RUN ALL SIX FUNCTIONS AS A MANAGED PROGRAM

Assess, score, remediate, and prove NIST CSF 2.0 — Govern, Identify, Protect, Detect, Respond, Recover — with a deterministic gap engine, a 5-stage POA&M, and cross-framework linkage into your unified posture score.

NIST CSF 2.0 IN 60 SECONDS

Six Functions, full subcategory catalog

NIST CSF 2.0 organizes cybersecurity into Govern, Identify, Protect, Detect, Respond, and Recover — with the full subcategory catalog pre-loaded so you assess, score, and remediate against the framework the industry treats as the common language.

Govern is now a first-class Function

CSF 2.0 elevates governance to a peer of Protect and Detect — turning board oversight, roles, policy, and supply chain into scored outcomes your executives, regulators, and buyers can see.

The de facto cyber benchmark

Insurers, regulators, federal contracts, and enterprise vendor questionnaires all anchor to NIST CSF — and the same buyers now expect AI governance evidence in the same review.

THE CSF PROBLEM NOBODY WARNED YOU ABOUT

These are the gaps that stall CSF programs — and quietly burn budget before auditors, insurers, or buyers even arrive.

Problem 1

CSF assessments live in slide decks

Teams score CSF once a year in a spreadsheet, present a heatmap, then lose the trail — so next year's assessment starts from scratch and nobody can prove movement.

Problem 2

Gaps never become work

A red cell on the heatmap doesn't become a tracked remediation item with an owner, due date, and evidence — so identified gaps drift for quarters.

Problem 3

AI and cyber score in silos

CSF lives in security. AI governance lives somewhere else. Buyers and regulators now expect one unified posture story — and disconnected scores fail the room.

WHAT YOU GET WITH RAIC

Buyer outcomes first. Every value below ties to a CSF Function your auditor, insurer, or enterprise customer already plans to test.

Full CSF 2.0 catalog with the Govern Function built in

All six Functions and their subcategories ship pre-loaded, with Govern as a first-class peer — no spreadsheet to maintain, no framework version to reconcile.

Deterministic gap engine, not a guess

The Gap Heatmap runs a deterministic engine on your live answers and evidence so results reproduce across assessors, tenants, and re-assessments — the number your board sees is the number your auditor gets.

5-stage POA&M lifecycle that actually closes

Identified → Assigned → In Progress → Validated → Closed — every gap becomes a tracked remediation item with owner, due date, evidence, and validation before it counts as done.

Snapshots and trend reporting

Capture posture snapshots to show period-over-period movement across Functions and subcategories — the artifact executives, insurers, and auditors expect.

Cross-framework linkage from one control

The Compliance Workbench adapter maps one CSF answer to ISO 42001, NIST AI RMF, SOC 2, CIS Controls v8.1, and C2M2 at the same time — no double work, no reconciliation.

WHAT'S INSIDE THE CSF MODULE

Every capability produces the artifact your auditor, insurer, or board will request — with cross-framework linkage built in.

CSF Hub & Assessment Wizard

One workspace at /governance/nist-csf covering all six Functions — Govern, Identify, Protect, Detect, Respond, Recover — with the full subcategory catalog and a guided assessment wizard.

Gap Heatmap with deterministic engine

Per-assessment heatmap at /governance/nist-csf/gap/:id that runs the deterministic gap engine on your evidence so scores reproduce and defend themselves.

POA&M Register (5-stage lifecycle)

Track remediation at /governance/nist-csf/poams through Identified, Assigned, In Progress, Validated, and Closed — with owners, due dates, and validation gates.

Evidence upload per subcategory

Attach evidence to individual subcategories through the evidence wizard — every artifact tied to the exact CSF outcome it supports.

Snapshots for trend reporting

Freeze posture at any point in time to show period-over-period Function and subcategory movement to executives, insurers, and auditors.

Compliance Workbench + canonical POA&M adapter

Cross-framework linkage so a CSF answer satisfies ISO 42001, NIST AI RMF, SOC 2, CIS, and C2M2 — and CSF gaps flow into the unified remediation roadmap.

Route guard + admin toggle

NistCsfGuard gates the CSF workspace behind a feature flag and an OrgAdmin toggle so rollout is controlled per tenant, per stage.

Starter fits SMBs, Pro/Enterprise scale up

Pro and Enterprise unlock the full 5-stage POA&M lifecycle; Starter collapses POA&M to a single Approval stage so smaller teams can still run a real CSF program.

PRICING THAT MATCHES YOUR CSF PROGRAM STAGE

Starter runs a real CSF program with a simplified approval flow. Pro and Enterprise unlock the full 5-stage POA&M lifecycle and cross-framework roadmap.

Starter

CSF 2.0 Hub, assessment wizard, gap heatmap, evidence uploads, and a simplified single-stage Approval workflow for POA&M items.

Professional

Adds the full 5-stage POA&M lifecycle (Identified → Assigned → In Progress → Validated → Closed), snapshots for trend reporting, and cross-framework crosswalks.

Enterprise

Adds Aslan AI Copilot, canonical POA&M adapter into the unified roadmap, and MSP multi-tenant rollups across the Partner Portal.

WHY MOVE NOW

Insurers, regulators, and enterprise buyers already anchor to NIST CSF 2.0 — and the same buyers now demand AI governance evidence alongside it. RAIC delivers both from one pane of glass.

  • NIST CSF 2.0 elevated Govern to a first-class Function — board oversight, roles, and supply chain are now scored outcomes, not footnotes.
  • Cyber-insurance underwriters and enterprise vendor questionnaires anchor to CSF — vague answers cost premium dollars and stall deals.
  • Federal contracts, state safe-harbor statutes, and sector regulators cite CSF as the recognized benchmark — adoption is a shield, not a checkbox.
  • Buyers now expect AI governance and cyber posture in one story — CSF answered in isolation fails the review.
All six Functions with the full subcategory catalog
Deterministic gap engine + 5-stage POA&M
Crosswalks to ISO 42001, NIST AI RMF, SOC 2, CIS, C2M2
NEW · In-platform assessment

NIST CSF 2.0 Framework Assessment

Run a scored NIST CSF 2.0 readiness assessment inside RAIC and export the results — plus the underlying evidence — as an audit-ready download. Stop rebuilding the same gap analysis in spreadsheets.

Scored assessment

Question-by-question readiness scoring with maturity bands, owner assignment, and re-assessment cadence.

Mapped to the standard

Every item maps to all six Functions — Govern, Identify, Protect, Detect, Respond, Recover — with the full subcategory catalog — so a single answer drives both the score and the evidence trail.

Downloadable evidence

Export a branded DOCX report plus a ZIP of the underlying evidence (RhindonCyber_NIST-CSF-Assessment_*.docx + .zip) — ready to hand to your auditor.

Framework Assessment + downloadable evidence is available on ISO 42001, NIST AI RMF, EU AI Act, SOC 2, CIS Controls v8.1, and HIPAA.

TAKE THE NEXT STEP

Three doors. One team. Pick the one that fits where your CSF program is today.