NIST CSF 2.0 Software
NIST CSF 2.0, included with your ISO 27001 ISMS.
Track all six CSF 2.0 Functions and their 22 Categories in the same system as your ISO 27001 controls, risks and audits. Plain-English guidance for each Category, a status and evidence for each, and a readiness view by Function. Included with GapLedger Core at no extra charge.
14-day trial · no card required · $500/mo after trial, NIST CSF 2.0 included · pricing
All six Functions, Govern through Recover
CSF 2.0 added Govern to the original five Functions. GapLedger covers all six, broken into the 22 Categories, each written in plain English with a hint of what evidence usually shows it is in place.
GV
Govern
Context, risk strategy, roles, policy, oversight and supply chain.
ID
Identify
Asset management, risk assessment and improvement.
PR
Protect
Access control, awareness and training, data security, platform security, resilience.
DE
Detect
Continuous monitoring and adverse event analysis.
RS
Respond
Incident management, analysis, reporting and mitigation.
RC
Recover
Recovery plan execution and communication.
Beside ISO 27001, not in a separate tool
Most of what CSF 2.0 asks for, an ISO 27001 ISMS already does. GapLedger maps 17 of the 22 CSF Categories to the matching Annex A controls. When a control is implemented and has its evidence attached, one action copies that status and evidence to the matching CSF Category, with a note of where it came from. You decide when it applies; nothing is marked done behind your back.
The rest of the ISMS works across both frameworks: one risk register linked to the controls that treat each risk, one evidence library, recurring tasks with reminders, and internal audits and management reviews that cover the whole scope.
What you get
- ✓ All 6 Functions and 22 Categories of NIST CSF 2.0
- ✓ Plain-English guidance and evidence hints for each Category
- ✓ Status, owner notes, due dates and evidence per Category
- ✓ Readiness by Function and for the whole scope
- ✓ Crosswalk to ISO 27001 Annex A for 17 of the 22 Categories
- ✓ Shared risk register, tasks, audits and management reviews
What it does not do (yet)
- • It tracks the 22 Categories, not the 106 Subcategories.
- • There is no Current and Target Profile or Implementation Tier report.
- • It is not a scanner or agent; evidence is what you upload and record.
- • NIST CSF comes with Core, so you are buying the ISO 27001 ISMS too.
$500/mo flat. NIST CSF 2.0 included.
Core is the full ISO 27001:2022 ISMS with unlimited users, and NIST CSF 2.0 comes with it at no extra charge. Or $5,400/yr and save 10%. Cancel anytime.
Frequently asked questions
Is NIST CSF 2.0 extra?
No. NIST CSF 2.0 is included with Core at no extra charge. Add it to your ISMS scope from the scope's Edit page.
Can I use GapLedger only for NIST CSF?
You can run a scope with only NIST CSF in it, but GapLedger is ISO 27001 software first: NIST CSF comes with the Core plan, which includes the full ISO 27001 ISMS. If you will never need ISO 27001, a NIST-only tool may suit you better.
Does it cover the Subcategories?
Not yet. GapLedger tracks NIST CSF 2.0 at the Category level: 22 Categories across the six Functions, each with guidance and evidence. Subcategory-level detail is a planned refinement.
Does it reuse my ISO 27001 evidence?
For the 17 Categories that map to Annex A controls, yes, when you choose to apply it. The crosswalk copies status and evidence from an implemented control to the matching Category and records where it came from. The other 5 Categories you complete directly.
Does GapLedger certify or assess us?
No. GapLedger is compliance management software. NIST CSF is a voluntary framework with no certification, and ISO 27001 certification decisions rest with your accredited auditor.
See it in the live demo first
The demo is a fictional company a few months into ISO 27001. No sign-up, no email. When you are ready, the trial needs no card.