Updated September 2026. Cybersecurity frameworks give organizations a shared language for risk, controls, and accountability. Instead of inventing a program from scratch, teams use proven models to decide what to protect, how to prioritize work, and how to show progress to executives, customers, and auditors.
No single framework covers every industry or obligation. Most mature programs combine one strategic model (often NIST CSF), a prioritized control set (often CIS Controls), and whatever certifiable or regulatory overlays their sector requires (ISO/IEC 27001, PCI DSS, HIPAA, FedRAMP, and others). This guide summarizes the frameworks that matter most in 2026, when each is typically used, and how to pick or stack them without drowning in paperwork.
How to choose (and combine) frameworks
- Start with outcomes, not logos. Map business-critical systems, data types, and threat scenarios first. Then pick the model that helps you govern and communicate those risks.
- Separate strategy from control catalogs. NIST CSF 2.0 is excellent for executive alignment. CIS Controls and NIST SP 800-53 tell teams what to implement. ISO 27001 structures an auditable management system.
- Use Implementation Groups or profiles to scope. CIS IG1 and CSF Organizational Profiles keep small teams from attempting an enterprise catalog on day one.
- Add sector rules last, then map back. PCI DSS, HIPAA, NERC CIP, NYDFS, and FedRAMP are obligations—not optional “nice to have” frameworks. Map them onto your core program so you are not running three disconnected checklists.
- Prefer current versions. Treat CSF 1.1, CIS Controls v7, and ISO/IEC 27001:2013 as historical unless a contract still names them during a documented transition.
Core program frameworks
NIST Cybersecurity Framework (CSF) 2.0
NIST CSF 2.0 (finalized February 2024) is the default risk-management language for many U.S. and multinational organizations. It organizes cybersecurity outcomes into six concurrent Functions:
Know what matters before your first meeting.
Weekday mornings. Five minutes. What changed in security, why it matters.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
- Govern — strategy, roles, policy, oversight, and cybersecurity supply-chain risk management (new as a top-level Function versus CSF 1.1)
- Identify — assets, risks, and improvement
- Protect — safeguards for identities, data, platforms, and infrastructure
- Detect — continuous monitoring and adverse-event analysis
- Respond — incident management, analysis, communication, and mitigation
- Recover — restoration and recovery communications
When to use it: Board and CISO reporting, program roadmaps, gap analysis, and crosswalks to other standards. CSF does not prescribe exact tools; it links outcomes to informative references (including CIS, ISO, and 800-53 series mappings).
Migration note: Organizations still on CSF 1.1 should treat the move to 2.0 as more than a rename—Govern elevates work that used to sit mostly under Identify, and Categories/Subcategories were reorganized. NIST publishes transition aids on the CSF site.
Official: nist.gov/cyberframework · CSF 2.0 (CSWP 29)
CIS Critical Security Controls (v8 / v8.1)
The Center for Internet Security publishes the CIS Critical Security Controls—a prioritized, practitioner-oriented set of defenses. The current generation is CIS Controls v8, with v8.1 as the latest published revision. It organizes work into 18 Controls and 153 Safeguards (not the older v7 set of 20 Controls).
Prioritization uses three cumulative Implementation Groups:
- IG1 — essential cyber hygiene (baseline for every enterprise)
- IG2 — adds safeguards for more complex environments
- IG3 — full set, for organizations facing sophisticated threats or higher impact
When to use it: Building or refreshing a technical security baseline, especially for mid-market teams that need a clear “do these things first” list. CIS Controls also map well as an on-ramp toward PCI DSS, HIPAA-oriented programs, and NIST CSF outcomes.
Official: cisecurity.org/controls
ISO/IEC 27001:2022 and ISO/IEC 27002:2022
ISO/IEC 27001:2022 is the international, certifiable standard for an Information Security Management System (ISMS). It requires a risk-based process, leadership commitment, continual improvement, and a Statement of Applicability for controls. The 2022 edition aligns Annex A with a reference set of 93 controls grouped into four themes (organizational, people, physical, technological)—replacing the older 2013 structure of 114 controls across 14 domains.
ISO/IEC 27002:2022 provides the detailed control guidance (purpose, attributes, implementation advice). Organizations certify to 27001, not to 27002; most ISMS programs use both together.
When to use it: Customer or partner contracts that require an accredited certificate, global market credibility, and a formal management system that integrates with other ISO management standards.
Official: ISO/IEC 27001 overview · ISO/IEC 27001:2022 · ISO/IEC 27002:2022
NIST SP 800-53 Revision 5
NIST Special Publication 800-53 Rev. 5 is a detailed security and privacy control catalog. Federal agencies use it (with the Risk Management Framework) to meet FISMA obligations; contractors, cloud providers, and highly regulated private organizations often adopt it as a deep control library even when they communicate upward with CSF.
When to use it: Federal systems, FedRAMP-aligned clouds, and environments that need granular, assessable controls beyond a high-level framework.
Official: SP 800-53 Rev. 5
Attestation, governance, and sector overlays
SOC 2 (AICPA Trust Services Criteria)
SOC 2 is an attestation engagement for service organizations, based on the AICPA Trust Services Criteria (security is required; availability, processing integrity, confidentiality, and privacy are optional). Buyers of SaaS and managed services commonly request a Type II report covering a period of operation.
When to use it: Cloud/SaaS vendors selling to enterprises that need independent assurance—not as a substitute for an internal control catalog like CIS or 800-53.
More: AICPA SOC 2 topic
PCI DSS v4.0.1
The Payment Card Industry Data Security Standard protects account data. As of 2026 assessments, PCI DSS v4.0.1 is the active version supported by the PCI Security Standards Council (v4.0 retired at the end of 2024). Requirements are organized under twelve requirement groups covering network security, secure configurations, data protection, access control, logging, testing, and security governance.
When to use it: Any organization that stores, processes, or transmits cardholder data—or that is contractually required to validate compliance. Map PCI controls into your broader program rather than treating them as a parallel silo.
Official: pcisecuritystandards.org
COBIT 2019
ISACA’s COBIT 2019 focuses on IT governance and management—aligning stakeholder needs, enterprise goals, and IT-related objectives. Security teams use it when board-level governance, process ownership, and assurance over IT decisions matter as much as technical controls.
Official: isaca.org/resources/cobit
COSO Internal Control — Integrated Framework
COSO is an enterprise internal control framework (control environment, risk assessment, control activities, information and communication, monitoring) with 17 principles. It is not a cybersecurity control catalog, but finance and audit leaders often expect cyber risk to fit inside COSO-style governance.
Official: coso.org
HITRUST CSF
The HITRUST CSF provides a certifiable, risk-based control framework that maps many regulatory and industry requirements—widely used in healthcare and other regulated sectors that want a single assessed framework covering overlapping obligations.
Official: hitrustalliance.net/hitrust-csf
U.S. federal, healthcare, and critical infrastructure
FISMA and the NIST Risk Management Framework
The Federal Information Security Modernization Act (FISMA) requires U.S. federal agencies (and applicable contractors) to implement risk-based security programs. In practice, that means categorizing systems, selecting and implementing controls (commonly from NIST SP 800-53), authorizing systems, and continuously monitoring—via NIST’s Risk Management Framework.
CISA overview: FISMA (CISA)
FedRAMP
FedRAMP standardizes security assessment, authorization, and continuous monitoring for cloud products used by U.S. federal agencies. Baselines map to NIST SP 800-53. Cloud providers that sell to government typically pursue FedRAMP authorization rather than reinventing agency-by-agency packages.
Official: fedramp.gov
HIPAA Security Rule
The HIPAA Security Rule sets national standards to protect electronic protected health information (ePHI) through required and addressable administrative, physical, and technical safeguards—plus risk analysis and risk management. It is a regulation, not a voluntary “best practices” framework; covered entities and business associates must comply.
Official: HHS HIPAA Security Rule
23 NYCRR Part 500 (NY DFS)
New York’s Department of Financial Services cybersecurity regulation applies to covered financial entities under NYDFS supervision. It expects a documented cybersecurity program, policies, access controls, monitoring, incident response, and (for many entities) a Chief Information Security Officer and annual certification—among other requirements that have been strengthened over time. Always check the current Part 500 text and amendments.
Official: dfs.ny.gov
NERC CIP
NERC Critical Infrastructure Protection (CIP) standards apply to entities that operate or support the North American bulk electric system. They cover topics such as electronic security perimeters, system security management, incident response, recovery, and supply-chain risk for applicable cyber systems. Treat CIP as mandatory reliability standards, not optional guidance.
Official: nerc.com
Privacy and regional baselines
GDPR (security of processing)
The EU General Data Protection Regulation is a privacy law. Article 32 requires appropriate technical and organizational measures for security of processing—risk-based, not a fixed control list. Organizations often evidence GDPR security expectations using ISO 27001, CIS Controls, or sector standards, plus privacy-specific processes (lawful basis, DPIAs, breach notification).
Reference: GDPR Article 32
UK NCSC 10 Steps and Cyber Essentials / IASME
The UK National Cyber Security Centre’s 10 Steps to Cyber Security remains a practical executive-oriented guide. For SME assurance in the UK, Cyber Essentials (often delivered with IASME involvement) is the widely recognized baseline certification path; IASME also offers related governance products aimed at smaller organizations that need lighter-weight assurance than a full ISO 27001 certification.
NCSC: 10 Steps to Cyber Security · Cyber Essentials: NCSC Cyber Essentials
Zero Trust architecture (NIST and CISA)
Zero Trust is an architecture approach—never trust by network location alone; continuously verify identity, device, and context. NIST SP 800-207 defines Zero Trust Architecture tenets. CISA’s Zero Trust Maturity Model Version 2.0 (April 2023) helps organizations (especially federal civilian agencies) stage progress across five pillars—Identity, Devices, Networks, Applications and Workloads, and Data—plus cross-cutting visibility/analytics, automation/orchestration, and governance capabilities, from Traditional through Optimal maturity.
When to use it: As a multi-year architecture roadmap layered on top of CSF/CIS/800-53 programs—not as a replacement for them.
Official: CISA Zero Trust Maturity Model · NIST SP 800-207
Practical stacking patterns
- Mid-market SaaS: NIST CSF 2.0 for roadmap + CIS Controls IG1/IG2 for hygiene + SOC 2 Type II for customers; add ISO 27001 when enterprise deals demand it.
- Healthcare: HIPAA Security Rule as the legal floor + HITRUST and/or NIST CSF for structure; map technical work to CIS or 800-53 as needed.
- Card payments: PCI DSS v4.0.1 scoped tightly; reuse the same asset inventory, logging, and access controls already driven by CIS/CSF.
- Federal / gov cloud: RMF + 800-53 Rev. 5 + FedRAMP for cloud; communicate program status with CSF 2.0 including Govern.
- Critical infrastructure: Sector standards (e.g., NERC CIP) first; align governance language to CSF 2.0 so executives see one story.
What this update left behind
Earlier versions of this article listed older NIST special publications (such as SP 800-12, 800-14, and 800-26), SCAP as if it were an organizational framework, and CIS Controls v7 as current. Those materials still have historical or niche value, but they are not the primary frameworks organizations should adopt for a 2026 program. Prefer CSF 2.0, CIS Controls v8.x, ISO/IEC 27001:2022, and the sector rules that actually apply to you.
Sources
- NIST — Cybersecurity Framework · CSF 2.0 (CSWP 29) · SP 800-53 Rev. 5 · SP 800-207
- CIS — Critical Security Controls · Implementation Groups
- ISO — ISO/IEC 27001 · 27001:2022 · 27002:2022
- PCI SSC — PCI Security Standards · PCI DSS v4.0.1 announcement
- CISA — Zero Trust Maturity Model · FISMA
- HHS — HIPAA Security Rule
- FedRAMP — fedramp.gov
- ISACA — COBIT
- NCSC — 10 Steps · Cyber Essentials
FAQ
Which framework should we implement first?
If you are U.S.-centric, NIST CSF 2.0 is the practical map. Pair it with CIS Controls for prioritized safeguards.
Do frameworks replace compliance audits?
No. Frameworks organize risk work; ISO 27001, SOC 2, HIPAA, and PCI still need evidence for their own scopes.
How often should a control baseline be refreshed?
Annually, or after a major architecture change. Threats move weekly — that is why frameworks alone are not enough.
Where do Zero Trust and CSF fit together?
Zero Trust is an architecture pattern; CSF is the program language. Use CSF to govern, Zero Trust to redesign access.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
27 Top Cybersecurity Tools for 2026
Updated September 2026. A polished roundup of 27 cybersecurity tools for 2026—plus the EDR/XDR, SIEM/SOAR, PAM, ZTNA/SASE, and CNAPP categories security teams...
Cybersecurity Checklist: 22 Items to Review in 2026 (Mapped to NIST CSF 2.0)
A 22-item cybersecurity checklist covering policies, passwords and MFA, email, website and network security, updated for 2026 and mapped to NIST CSF...
The Quick and Dirty History of Cybersecurity: From Early Hacks to 2026
From Creeper and the Morris worm to SolarWinds, Colonial Pipeline, Log4Shell, MOVEit, Zero Trust, and NIST CSF 2.0—a quick, readable history of...
Friday’s brief: forgotten servers on a seven-country advisory, then Splunk, Bricksforge and exposed dashboards
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.