Most organizations need one framework to organise the work and one certification only if a customer or regulator demands it. Everything beyond that is usually someone else's business model.
Here's how to tell which is which.
The short answer, by situation
| If you are | Start with | Add a certification only if |
|---|---|---|
| An individual or student | CIS Controls IG1 concepts; OWASP and ATT&CK for skills | Never — these are free learning tools |
| A small business | CIS Controls IG1 (56 safeguards, free) | You take card payments (PCI SAQ) |
| A B2B SaaS startup | NIST CSF 2.0 as structure, OWASP ASVS in development | Enterprise customers demand SOC 2 or ISO 27001 — and they will |
| A regulated company | Whatever your regulator mandates, mapped onto CSF 2.0 | It's not optional; the regulator decides |
| An enterprise | ISO 27001 plus a control catalogue derived from NIST SP 800-53 | International contracts require the certificate |
| Critical infrastructure or OT | CISA's Performance Goals to sequence, then IEC 62443 | Sector rules apply regardless |
If you're a small business and you read no further: CIS Controls Implementation Group 1 is 56 safeguards, free to download, explicitly designed as essential cyber hygiene, and it appears in most cyber-insurance questionnaires. Start there.
What each one actually is
NIST Cybersecurity Framework 2.0 (released February 2024, free, no certification). A risk framework organised into six functions: Govern, Identify, Protect, Detect, Respond, Recover. The 2024 revision added Govern and broadened scope explicitly from critical infrastructure to organizations of any size.
Think of it as the common language layer. It tells you what outcomes to aim for, not which controls to implement — so most organizations use CSF for structure and something else for the actual to-do list. It isn't law, but regulators including NYDFS and the FTC reference it as evidence of reasonable security.
CIS Controls v8.1 (June 2024, free). Eighteen controls and 153 safeguards, tiered into Implementation Groups. IG1 is the "essential cyber hygiene" floor. This is the most prescriptive, most actionable free framework available and the best answer to "what do we do first."
ISO/IEC 27001:2022 (paid standard, certifiable). A management-system standard with 93 controls in Annex A, audited by an accredited body on a three-year cycle. This is the strongest certification signal internationally and is frequently demanded in cross-border B2B contracts. Budget six to eighteen months of implementation and roughly $10,000–$50,000 in audit fees, plus internal effort.
Note: the transition window from the 2013 edition closed on 31 October 2025, so every valid certificate is now on the 2022 edition.
SOC 2 (attestation, not certification). A CPA firm reports on your controls against the Trust Services Criteria. Type I covers design at a point in time; Type II covers whether controls operated over a window of three to twelve months — and Type II is what enterprise buyers actually want. Audits commonly run $20,000–$100,000+.
The thing buyers misunderstand: SOC 2 uses criteria, not prescribed controls, so scope and rigour vary considerably by auditor. "We have SOC 2" is not a binary quality statement.
PCI DSS 4.0.1 (contractual, not law). Mandatory if you touch card data, flowing from card brands through your acquirer. Every requirement is now fully in effect — the roughly 51 future-dated requirements became mandatory on 31 March 2025, including payment-page script integrity and change detection.
Small merchants can keep scope minimal by outsourcing payments entirely, though the 2025 e-commerce requirements narrowed even that.
MITRE ATT&CK (free, not a compliance framework). A catalogue of attacker behaviours. No certification, no controls — you use it to map detection coverage and find gaps. Essential if you have a security operations function; conceptually useful for everyone.
OWASP (free). The Top 10 is an awareness document, updated to a 2025 edition. ASVS 5.0 (May 2025) is the actual verification standard — the one to use for security requirements and penetration-test depth. Most people cite the Top 10 when they mean ASVS.
How to choose, in four questions
1. Does anyone require something specific? A regulator, a major customer, a card brand, a contract. If yes, that's your answer and the rest of this page is academic. Regulated requirements come first because they aren't optional.
2. Do you sell to enterprises? Then a certification is a sales cost, not a security investment — and that's a legitimate reason to buy one. SOC 2 for North America, ISO 27001 for international. Many organizations eventually need both.
3. Do you know what to do next week? If not, you need CIS IG1, not a certification. A certificate obtained without the underlying hygiene is expensive theatre.
4. Are you in OT or critical infrastructure? Then start with CISA's Performance Goals, which were reissued as CPG 2.0 in December 2025 with cost, impact and ease ratings specifically so a resource-poor operator can sequence the work.
The thing nobody tells you about certification
Compliance is not security, and the gap has bitten well-known organizations.
Target was PCI-compliant weeks before its 2013 breach. Change Healthcare was HIPAA-covered and lacked multi-factor authentication on the portal attackers used to halt claims processing across much of US healthcare.
Frameworks are floors, sampled at a point in time by someone reviewing evidence you selected. That's genuinely useful — it forces documentation, review cadence, and executive attention that wouldn't otherwise exist. It just isn't the same thing as being difficult to attack.
The failure mode to avoid: treating the audit as the goal, so that the programme optimises for passing rather than for reducing risk. You can tell which kind of programme you have by asking whether anything changed operationally after the last audit.
Costs, roughly
| Document | Implementation | Audit/attestation | |
|---|---|---|---|
| NIST CSF 2.0 | Free | Weeks to months | None |
| CIS Controls IG1 | Free | Weeks | None |
| ISO 27001 | ~CHF 200 | 6–18 months | $10K–$50K + surveillance |
| SOC 2 Type II | Criteria available | 3–12 month window | $20K–$100K+ |
| PCI DSS | Free | Varies by scope | SAQ free; QSA assessment for Level 1 |
Compliance-automation platforms (Vanta, Drata, Secureframe and others) commonly run $8,000–$25,000 a year for startups. They compress audit preparation substantially. They do not replace the auditor's fee, and they don't do the underlying work.
A warning about dates
Frameworks changed unusually fast between 2024 and 2026 — CSF 2.0, CIS 8.1, ISO's transition deadline, PCI's future-dated requirements, OWASP's 2025 Top 10 and ASVS 5.0, ATT&CK v18.
Any framework guidance you read without a version number and a date is unreliable. That includes guidance about US federal requirements specifically, where several mandates established between 2021 and 2024 were rescinded or revised between 2025 and 2026. Check our regulation tracker (planned reference; not yet available) for current status before acting on anything.
What to do next: If nobody is requiring a certification of you right now, download CIS Controls IG1 and work the list. If a customer is asking, find out specifically which report they need before you scope anything — the answer is often narrower than the sales conversation implied.
Related: Regulation tracker (planned reference; not yet available) · Minimum viable security · Security maturity model · What security actually costs
Sources: NIST Cybersecurity Framework 2.0 (Feb 2024). CIS Controls v8.1 (Jun 2024). ISO/IEC 27001:2022 and accredited-body transition guidance. AICPA Trust Services Criteria — SOC 2. PCI Security Standards Council — PCI DSS 4.0.1 and the March 2025 future-dated requirements. OWASP Top 10:2025 and ASVS 5.0. MITRE ATT&CK. CISA Cybersecurity Performance Goals 2.0.