A framework is a set of recognized best practices. Following one gives your security program structure and lets you measure progress. These four are the foundation of how we work.
NIST Cybersecurity Framework (CSF) 2.0
Published by: National Institute of Standards and Technology (NIST), February 2024. Cost: free and voluntary. Designed for organizations of every size and industry.
| Function | What it means for your business |
|---|---|
| Govern | Set cybersecurity roles, responsibilities, policies and risk priorities. |
| Identify | Know your devices, software, data, vendors and risks. |
| Protect | Put safeguards in place: access control, training, data security, patching. |
| Detect | Find and analyze possible attacks and suspicious activity. |
| Respond | Act on a detected incident: contain it, communicate and fix it. |
| Recover | Restore systems and operations, and learn from what happened. |
Why it matters: CSF gives a common language for evaluating where a business stands and what to improve next.
Official sources: NIST CSF 2.0 · NIST Small Business Quick-Start Guide (SP 1300)
CIS Critical Security Controls v8.1
Published by: Center for Internet Security (CIS), a nonprofit. 18 prioritized controls that turn strategy into specific technical safeguards. Implementation Group 1 (IG1) is the CIS-defined starting set of "essential cyber hygiene" safeguards for small and mid-sized organizations.
- 1Inventory and Control of Enterprise Assets
- 2Inventory and Control of Software Assets
- 3Data Protection
- 4Secure Configuration of Enterprise Assets and Software
- 5Account Management
- 6Access Control Management
- 7Continuous Vulnerability Management
- 8Audit Log Management
- 9Email and Web Browser Protections
- 10Malware Defenses
- 11Data Recovery
- 12Network Infrastructure Management
- 13Network Monitoring and Defense
- 14Security Awareness and Skills Training
- 15Service Provider Management
- 16Application Software Security
- 17Incident Response Management
- 18Penetration Testing
Why it matters: NIST CSF sets the strategy; CIS Controls tell you exactly what to implement and in what order. Our security baseline maps to these controls.
Official source: CIS Critical Security Controls
CISA cybersecurity guidance
Published by: Cybersecurity and Infrastructure Security Agency, part of the U.S. Department of Homeland Security. CISA is a guidance and alerting agency, not a compliance framework. It publishes:
- Cybersecurity alerts and advisories on current threats.
- The Known Exploited Vulnerabilities (KEV) catalog: flaws attackers are actively using, which should be patched first.
- #StopRansomware prevention and response guidance.
- Small business guidance on MFA, passwords, backups and incident response.
Official sources: CISA Cyber Guidance for Small Businesses · KEV Catalog · StopRansomware
ISO/IEC 27001:2022
Published by: International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC). An international standard for building and maintaining an Information Security Management System (ISMS): governance, risk assessment, access control, supplier management, incident management and continual improvement.
Why it matters: Larger customers and partners sometimes ask vendors to show formal security management. Organizations can align with ISO 27001 without being certified; certification requires an audit by an accredited certification body.
Official source: ISO/IEC 27001
"Aligned with" is not "certified in"
| Term | What it actually means |
|---|---|
| Aligned with / based on a framework | Practices follow the framework's guidance. No outside audit is implied. |
| ISO/IEC 27001 certification | An accredited certification body has audited the organization's ISMS. |
| SOC 2 report | An attestation examination performed by an independent CPA firm under AICPA standards. It is a report, not a certification. |
| HIPAA | There is no official government HIPAA certification. Organizations perform risk analyses and may hire outside assessors. |
| CMMC | A Department of Defense program. Depending on the contract, it requires a self-assessment or an assessment by an authorized third party. |
Our position: NexGenGuard aligns its practices and recommendations with NIST CSF 2.0 and the CIS Controls. NexGenGuard is not ISO 27001 certified and does not hold a SOC 2 report.
Last reviewed: October 2026. Laws and standards change; always confirm with the official source.
