shipping production AI · since 2026 NAICS 541330 / 541511 / 541512 / 541519  ·  CMMC-aware
Refinery Report / Cybersecurity / post · loyees
CybersecurityNIST CSF 2.0Security RoadmapSecurity Leadership

NIST CSF 2.0 Roadmap for 50 to 500 Employees

A four-quarter sequence for adopting NIST CSF 2.0 at mid-market scale: scoping the Profile, choosing a Tier honestly, and ordering the work so each quarter funds the next.

D
By the DSE practice team
Operator-led practice · how we research & review
July 19, 2026
12 min · 2,659 words

By the DSE practice team · published July 19, 2026 · reviewed July 19, 2026

Adopting NIST CSF 2.0 at 50 to 500 people fails in one of two ways. Either the organization tries to profile all six Functions at once and produces a 200-row spreadsheet nobody re-opens, or it treats the framework as a control checklist and skips the part that makes it useful — deciding what the target actually is. The framework is deliberately not a control list. CSF 2.0 is a taxonomy of outcomes that “does not prescribe how outcomes should be achieved,” which means the value is in the sequencing you supply.

This is the four-quarter sequence we run with mid-market teams, and the decisions that have to be made in each one.

What CSF 2.0 asks you to produce

Three artifacts, and only three.

A Current Profile — the Core outcomes the organization is currently achieving, honestly recorded. A Target Profile — the outcomes it has selected and prioritized. An action plan — the prioritized work that closes the gap, which NIST suggests can take the form of a risk register, a risk detail report, or a plan of action and milestones.

You can build the Current and Target profiles yourself, category by category, in our NIST CSF 2.0 current-vs-target profile workbook before you commission any assessment — it surfaces the largest gaps first.

NIST’s own five-step process is: scope the Profile, gather the information needed, create the Profile, analyze the gaps between Current and Target and create an action plan, then implement the plan and update the Profile. Note that steps one and two come before any assessment work — the failure mode above is almost always a team that started at step three.

The framework also offers Tiers to characterize the rigor of risk governance and management: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4). Tiers are not a maturity score to maximize. For most 50-to-500-person organizations, an honest current position is Tier 1 or Tier 2, and a realistic 12-month target is Tier 2 or Tier 3. Declaring Tier 3 as a target and staffing for Tier 1 is how roadmaps stop being believed internally.

Quarter 1 — Scope, GOVERN, and the inventory that everything depends on

Scope first, and scope small. NIST explicitly allows an organization to hold as many Profiles as it wants, each with a different scope — an entire organization, a set of financial systems, or, in NIST’s own example, countering ransomware threats and handling ransomware incidents involving those systems. At mid-market scale, one Profile scoped to the corporate IT estate plus the systems holding regulated or customer data is the right first bite. Write the scope statement down in a paragraph; it prevents the spreadsheet sprawl.

GOVERN is the quarter’s real deliverable. GOVERN was the Function added in CSF 2.0, and it is where mid-market programs have the least in place and get the most leverage. Concretely: a named accountable individual, a short written policy set with an approval date, a risk register that exists as a live document rather than an assessment appendix, a stated risk tolerance in business terms, and a decision about which supplier relationships matter. The supply-chain category GV.SC sits inside GOVERN for a reason — supplier risk is a governance decision before it is a review process.

IDENTIFY, minimally. Asset inventory, data inventory, and system ownership. Everything downstream inherits from this, and it is the item most likely to still be incomplete in Q3 if it is not forced in Q1. CISA’s Cyber Essentials — organized as six Essential Elements of a Culture of Cyber Readiness: Yourself, Your Staff, Your Systems, Your Surroundings, Your Data, and Your Crisis Response — puts “learn what is on your network” and “learn who is on your network” at the top of two elements, which matches what we see in practice.

Exit criterion for Q1: a written scope, a named owner, a live risk register, and an asset and data inventory that the IT lead will defend in a meeting.

Quarter 2 — PROTECT, starting at identity

PROTECT is the largest Function and the one where budget disappears fastest without sequencing. The order that produces the most risk reduction per dollar at this scale:

  1. Identity. MFA across every population including the awkward ones, privileged access reduced and reviewed, joiner-mover-leaver made reliable. This is where the highest-severity findings concentrate; the evidence list is in the Microsoft 365 security assessment checklist.
  2. Data protection and backup. Including PR.DS-11, the subcategory that requires backups to be created, protected, maintained, and tested — the last word being the one that is usually missing.
  3. Platform hygiene. Patch cadence for internet-facing systems first, endpoint standard, and removal of legacy protocols and unsupported systems.
  4. Awareness. Training that is specific to the workflows that lose money — payment changes, help-desk verification — rather than generic annual content.

Exit criterion for Q2: MFA coverage stated as a number with named exclusions, a documented restore test, and a patch cadence with an exception register.

Quarter 3 — DETECT and RESPOND, in that order

Detection is worth buying once there is a managed estate to detect on and someone empowered to act. The Q3 work:

The current NIST incident response guidance, SP 800-61r3, is itself a CSF 2.0 Community Profile, which makes it the natural companion document for this quarter — it maps the old four-phase life cycle onto the six Functions directly.

Exit criterion for Q3: a decision-rights table, a written plan, a completed tabletop with recorded findings, and a documented logging inventory.

Quarter 4 — RECOVER, third parties, and the re-profile

Exit criterion for Q4: an updated Profile pair, a vendor register, and a next-year action plan that leadership has funded.

Sizing the effort honestly

For a 200-person firm with a general IT function and no dedicated security staff, this sequence is realistic at roughly a quarter to a half of one full-time equivalent across the year, plus external support at the decision points — scoping, the Profile build and gap analysis, tabletop facilitation, and the annual re-profile — and plus whatever the remediation itself costs, which is the larger and more variable number. Organizations that try to run it as a side project of an already-full IT role usually complete Q1 and Q2 and stall at the DETECT boundary, where the work stops being configuration and starts being organizational.

The starting artifact for all of it is an honest Current Profile, which is the core output of a cybersecurity risk assessment — scoping statement, evidence register, Current and Target Profiles, severity-ranked findings, and the prioritized roadmap that becomes the Q1 action plan.

FAQ

How long does it take to adopt NIST CSF 2.0 at mid-market scale?

A realistic first cycle is four quarters: scope plus GOVERN and inventory in Q1, PROTECT led by identity in Q2, DETECT and RESPOND in Q3, and RECOVER plus third parties and the re-profile in Q4. For a 200-person firm with a general IT function, that is roughly a quarter to a half of one full-time equivalent across the year plus external support at the decision points, and separately whatever remediation costs.

What are the NIST CSF 2.0 Tiers, and which should we target?

CSF 2.0 defines four Tiers characterizing the rigor of cybersecurity risk governance and management: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4). They are not a maturity score to maximize. Most organizations of 50 to 500 people start honestly at Tier 1 or Tier 2, and a realistic twelve-month target is Tier 2 or Tier 3. Declaring a Tier the organization is not staffed to sustain undermines the roadmap.

What is the difference between a Current Profile and a Target Profile?

A Current Profile specifies the Core outcomes an organization is currently achieving. A Target Profile specifies the desired outcomes it has selected and prioritized. The gap analysis between the two produces the prioritized action plan — which NIST notes can take the form of a risk register, a risk detail report, or a plan of action and milestones.

Do we have to cover all six Functions in the first year?

Not at once. NIST explicitly allows multiple Organizational Profiles with different scopes, including a Profile scoped to a specific concern such as ransomware. Sequencing by Function across four quarters keeps the work fundable and keeps each quarter’s output usable, rather than producing one large assessment artifact that never converts into action.

Is NIST CSF 2.0 a compliance requirement?

No. CSF 2.0 is voluntary guidance and a taxonomy of outcomes; it does not prescribe how outcomes are achieved and there is no CSF certification. It is widely used as the organizing structure for security programs and as a shared vocabulary with customers, insurers, and boards, and other obligations may map onto it — but alignment to the framework is not compliance with any law or rule.

What this guide is / What it is not

What it is: A practitioner sequencing plan for adopting NIST CSF 2.0 in a 50-to-500-person organization, anchored to NIST CSWP 29 (February 26, 2024), the NIST CSF 2.0 quick start guides, NIST SP 800-61r3 (April 2025), NIST SP 800-161r1, and CISA’s Cyber Essentials. The quarter structure, effort estimate, and Tier targets are DSE practitioner judgment, not NIST prescriptions. What it is not: Legal advice, an audit, a certification, or an attestation. NIST CSF 2.0 is voluntary and has no certification regime; alignment to it is not compliance with any law, rule, or contract. Nothing here guarantees a security, examination, insurance, or diligence outcome. DSE prepares organizations for review and does not certify them.

The Bottom Line

Scope one Profile, not the whole company. Build GOVERN and the inventory before assessing anything, because every later Function inherits from them. Sequence PROTECT from identity outward, buy detection only once there is a managed estate and a named person who can authorize a response, and finish the year by re-profiling rather than by filing the assessment. Pick a Tier you are actually staffed to sustain — an honest Tier 2 that leadership funds beats a declared Tier 3 that nobody believes.

Next step · scope the first Profile

Thirty minutes to size your first four quarters.

Bring your headcount, your estate, and any obligations you already carry. We will tell you what to scope the first Profile to, which Tier is honest, and what Q1 should actually contain.

Key facts

Read next · AI Security & Governance

P
Founder · Principal Engineer
Data & AI engineer · 10+ yrs hands-on

Writes most of the long-form here. Lives in the codebase. Active on GitHub and LinkedIn.

§ Next step

Not sure which of these is you?

Tell us what's broken in a paragraph and a principal reads it directly — or walk the ladder from a low-commitment first engagement up to retained work.

One long-form a week. No marketing.

Subscribe to the Refinery Report. Practitioner deep-dives on AI engineering, security, and the realities of running production systems. Unsubscribe in one click.

~12 issues / quarter