Compliance guide

Operate NIST Cybersecurity Framework 2.0 in PurpleWASP

Create Organizational Profiles, assess Current and Target outcomes across the complete CSF 2.0 Core, reuse PurpleWASP Controls, analyse gaps, plan improvements, record Implementation Tiers and report progress.

Security Manager, Compliance Manager, Risk Manager or authorised contributor Ongoing cybersecurity-improvement programme Updated 18 September 2026

What PurpleWASP NIST CSF 2.0 supports

PurpleWASP implements the complete CSF 2.0 Core with 6 Functions, 22 Categories and 106 Subcategory outcomes. The workspace uses Organizational Profiles to compare the organisation's Current and Target position, connects applicable outcomes to shared PurpleWASP Controls and assurance records, and turns gaps into owned improvement work.

WorkspacePurpose
Profile & ScopeCreate multiple Organizational Profiles and define the business/system/service/custom boundary.
Current & TargetRecord applicability, Current state, Target state, priority and management notes for CSF outcomes.
CSF CoreBrowse/search Govern, Identify, Protect, Detect, Respond and Recover down to the 106 outcomes.
Gap AnalysisIdentify applicable outcomes where Target is above Current and review mapped-Control context.
Improvement PlanCreate owned, dated actions linked to one or more Profile outcomes.
Implementation TiersRecord Current/Target Tier 1–4 with rationale and evidence summary.
ReportsPresent Profile context, Function roll-ups, gaps, assurance drivers, Tiers and improvement actions.

1. Create an Organizational Profile and define scope

Create a Profile for the organisation, business unit, system, service or other bounded context you want to assess. PurpleWASP supports multiple Profiles so different environments do not need to be forced into one enterprise-wide view.

  • Record owner, description and lifecycle state.
  • Capture mission/business, regulatory/contractual, and threat/risk context.
  • Include relevant business processes and Assets/systems from the shared PurpleWASP records.
  • Add custom scope objects when the boundary cannot be expressed with an existing record type.

When a Profile is created, PurpleWASP seeds the CSF outcomes so the assessment starts from the full Core rather than a manually assembled list.

2. Assess the Current and Target Profile

For each applicable Subcategory, record the organisation's Current state, Target state, priority and notes. Use the Target Profile to express the desired outcome rather than simply marking every item as 100%.

Current and Target are management assessments. They are not automatically changed when an improvement action is closed. Reassess the Profile outcome explicitly after the underlying operating state changes.

3. Navigate the CSF Core

The CSF Core browser organises the complete outcome set under the six Functions: Govern, Identify, Protect, Detect, Respond and Recover. Use search/filter to locate a requirement and then review the selected organisation-Control coverage and Profile context.

4. Reuse Controls and assurance from Control Management

NIST does not create a second copy of the organisation's Controls. PurpleWASP uses the shared canonical/control-mapping architecture so a Control that already supports ISO 27001, SOC 2 or another framework can also support the relevant NIST outcome.

The Current & Target workspace can surface:

  • organisation-selected NIST Control mappings;
  • canonical mapping suggestions for adopted Controls;
  • implementation status;
  • assessments and current evidence;
  • test definitions and passed test runs;
  • linked governance documents and Risks;
  • open issues and active exceptions.

The NIST workspace does not silently create or rewrite organisation Controls. Control Management remains authoritative.

5. Use Gap Analysis

Gap Analysis focuses on applicable outcomes where the Target state is above the Current state. Use priority and assurance context to distinguish strategic gaps from outcomes that are already supported by strong Controls but have not yet been reassessed.

6. Build the Improvement Plan

Create improvement actions directly from identified gaps or from the Improvement Plan workspace. Assign owner, priority, due date, status, expected benefit and notes, and link each action to the outcomes it is intended to improve.

Completing an action does not automatically complete the NIST outcome. Reassess Current state after the implementation/evidence has actually changed.

7. Record Implementation Tiers separately

Record the Current and Target Implementation Tier with rationale, governance notes, risk-management notes and evidence summary. PurpleWASP keeps the four Tiers—Partial, Risk Informed, Repeatable and Adaptive—separate from the Profile percentage visualisation.

8. Use reports and Drivers / Improve Score

The dashboard and report views summarise Current/Target Profile state by Function and show operational drivers such as outcomes with no selected Controls, Controls not fully implemented, missing current evidence and open Control issues. Use those drivers to navigate back to the records that need work.

NIST score and certification boundary

NIST CSF 2.0 is not treated as a certification scheme inside PurpleWASP. The Current/Target percentages are PurpleWASP internal visualisations of the Profile assessment states; they are not NIST compliance, certification, conformance or maturity scores. Implementation Tiers are also not converted into percentages.

Implementation guides

Use the first-time handbook for organisations adopting NIST CSF 2.0 and the technical guide for PurpleWASP developers, administrators and implementation partners.

Download the NIST CSF 2.0 first-time implementation handbook

Download the NIST CSF 2.0 technical implementation guide

Common problems

An outcome has no selected organisation Control

Review the canonical suggestions and the organisation's existing Controls. If an appropriate Control exists, explicitly map it; otherwise use Control Management to determine whether a new/adopted Control is needed.

Current Profile looks low even though Controls are implemented

Current state is an explicit Profile assessment. Review the Control assurance context, then update the outcome assessment when management concludes the outcome is being achieved.

The gap disappeared after I changed the Target

Gap Analysis compares Current with Target. Confirm the Target represents the desired cybersecurity outcome rather than changing it only to remove a gap.