Skip to content
NEWSROOM

The Global Landscape of Cybersecurity Frameworks for Security Officers

11 June 2024·34 min read·Frameworks · Guide

LAST UPDATED ON 2025-07-20

Cybersecurity frameworks are foundational tools that help organizations manage and reduce cyber risks in a structured way . These frameworks consist of standards, guidelines, and best practices that serve as a roadmap for implementing security controls, assessing risk, and aligning security efforts across an organization . Adopting a recognized framework is not just about compliance or checking boxes – it demonstrates a long-term commitment to cybersecurity excellence and facilitates communication among security professionals, executives, and stakeholders . In today’s threat environment, any security officer (CISO, CIO, etc.) should be familiar with the major cybersecurity frameworks used around the world. This comprehensive guide presents the key global frameworks and notable regional standards (US, EU, Asia-Pacific), highlighting their differences and offering expert perspective on their adoption. It also compares the top frameworks side-by-side and reviews emerging frameworks since 2023, providing insight into which new developments warrant attention.

Major International Cybersecurity Frameworks

The following frameworks are widely adopted across industries and countries. They provide broad, well-established approaches to cybersecurity risk management and control implementation. These are considered “frameworks every security officer should know” due to their widespread use and influence.

NIST Cybersecurity Framework (CSF)

The NIST Cybersecurity Framework’s core functions now include a sixth “Govern” function, emphasizing governance alongside Identify, Protect, Detect, Respond, and Recover . The NIST CSF was first released by the U.S. National Institute of Standards and Technology in 2014 (updated to version 1.1 in 2018) as a voluntary framework to improve critical infrastructure cybersecurity. It quickly became a gold standard for assessing cybersecurity maturity, identifying gaps, and guiding risk management efforts . NIST CSF is organized into a set of core functions – Identify, Protect, Detect, Respond, Recover – which are further broken down into categories and subcategories of outcomes. This high-level structure helps organizations assess their current state and target state for cybersecurity across those functions.

In 2024, NIST released Cybersecurity Framework 2.0, the first major update in six years . Notably, CSF 2.0 added a sixth function, “Govern,” to underscore that cybersecurity must be managed at the governance level as part of enterprise risk management . The update also expands the framework’s scope beyond critical infrastructure, making it applicable to organizations of all sizes and sectors – from small nonprofits to large corporations – regardless of their cybersecurity expertise . CSF 2.0 places greater emphasis on supply chain risk and includes additional guidance and resources (such as profiles and implementation examples) to assist with adoption . The NIST CSF remains flexible and is meant to be adapted; it does not prescribe specific controls but rather references other standards. This flexibility, along with NIST’s effort to align CSF 2.0 with international standards , has led to global uptake. Many non-U.S. organizations use NIST CSF as a baseline framework for cybersecurity, customizing it to their needs. In the U.S. it is widely used in government and critical sectors, and often required by contractual obligations for federal suppliers . Expert perspective: NIST CSF is an excellent framework for establishing a common language and holistic view of cybersecurity risk. It is especially useful as a starting point or overarching framework because of its clarity and flexibility. However, since it’s not a certifiable standard, organizations often pair NIST CSF with more detailed control standards (like CIS or ISO) for implementation and assurance.

ISO/IEC 27001 (Information Security Management Standard)

ISO/IEC 27001 is the internationally recognized standard for establishing an Information Security Management System (ISMS). Published by the International Organization for Standardization, it provides a systematic, risk-based approach to securing information assets . Companies that implement ISO/IEC 27001 follow a structured process: defining security policies, conducting risk assessments, implementing controls, monitoring and improving continuously (the Plan-Do-Check-Act cycle). An annex (ISO 27001 Annex A, supported by ISO 27002) outlines dozens of specific security controls covering areas like access control, cryptography, physical security, supplier security, incident response and more . Unlike NIST CSF, ISO 27001 is a certifiable framework – organizations can be audited by accredited certification bodies and earn an ISO 27001 certificate if they meet the requirements. This certification is internationally accepted as proof of a mature cybersecurity program .

ISO 27001’s strength lies in its formal governance focus and global recognition. Over 70,000 organizations worldwide have been certified, spanning 150+ countries and many sectors . Achieving ISO 27001 demonstrates to boards, customers, and partners that a company follows industry best practices and is committed to keeping data secure . Expert perspective: ISO 27001 is ideal for organizations seeking a rigorous, audit-able framework that can provide external assurance. It requires significant effort and documentation, so it may be challenging for smaller firms, but it establishes strong security governance. Many companies use ISO 27001 certification as a competitive advantage or to meet client and regulatory expectations. One consideration is that ISO 27001 defines what must be done (and requires you to show how you do it), but it is technology-neutral – it doesn’t spell out specific technical configurations. Implementers often consult ISO 27002 for detailed guidance on controls. In practice, ISO 27001 can coexist with other frameworks; for example, you can map ISO controls to NIST CSF functions or vice-versa to get the benefits of both.

CIS Critical Security Controls

The CIS Critical Security Controls (formerly known as the SANS Top 20) are a set of prioritized, highly specific security actions published by the Center for Internet Security. This framework is more technical and prescriptive compared to NIST or ISO. The latest version (CIS Controls v8) contains 18 top-level controls and 153 specific safeguards, addressing areas like inventory of devices and software, secure configuration, vulnerability management, malware defenses, data protection, access control, logging, and incident response . The CIS Controls are often described as “essential cyber hygiene” – a minimum set of practices to thwart the most common attacks. Notably, version 8 of CIS Controls was updated to better cover modern environments (like cloud and hybrid infrastructure) and supply chain security considerations , reflecting evolving threats.

A unique aspect of CIS Controls is that they are divided into Implementation Groups (IG1, IG2, IG3) to help organizations prioritize. IG1 (basic cyber hygiene) is a smaller subset of controls suitable for small or low-risk enterprises; IG2 and IG3 progressively add more controls for larger or more security-critical organizations . This scaled approach makes CIS Controls accessible – you can start with the essentials and mature over time. Expert perspective: CIS Controls are valued for being actionable and specific. A security officer can hand the CIS Controls to technical teams and have them implement concrete measures (e.g., “Implement and test backups” or “Ensure secure configurations for all operating systems”). For organizations just beginning to build a cybersecurity program, CIS provides a clear checklist of “must do” items. However, on its own, the CIS framework doesn’t cover governance or risk management process – it’s primarily focused on technical safeguards. Many organizations therefore use CIS Controls to complement a broader framework: for instance, using NIST CSF or ISO 27001 to manage risk and strategy, while using CIS Controls as the tactical to-do list for IT teams . It’s also worth noting there’s no formal certification for CIS Controls, but organizations can self-assess or have consultants measure their implementation against this framework.

COBIT (Control Objectives for Information and Related Technology)

COBIT is an IT governance framework created by ISACA, often used to bridge the gap between business goals, IT processes, and security. While not solely a cybersecurity framework, COBIT includes significant security and risk management components. It provides a comprehensive set of best practices for governance and management of enterprise IT, organized into domains such as Plan and Organize, Acquire and Implement, Deliver and Support, and Monitor and Evaluate . COBIT helps ensure that information security is aligned with business objectives and integrated into overall IT management. It defines processes and controls for things like access management, data protection, incident management, and audit, within a broader governance model . Many large enterprises and financial institutions use COBIT alongside security-specific frameworks. For example, COBIT can operate at the governance layer (ensuring roles, policies, and oversight are in place) while a framework like CIS or ISO guides the detailed security controls.

Expert perspective: If you are in a leadership role, COBIT is useful for managing cybersecurity as part of enterprise governance. It’s particularly relevant for aligning security with compliance, audit, and strategic objectives. However, COBIT by itself is high-level; it won’t provide the same technical depth as frameworks like CIS. In practice, COBIT is often used in highly regulated industries or by organizations seeking to measure and improve the maturity of their IT processes (including security) in a holistic way. Even if a security officer doesn’t implement COBIT fully, familiarity with its governance principles is valuable.

Other Widely-Used Frameworks and Standards

Beyond the big frameworks above, there are several other important cybersecurity standards that security officers should know, especially as they often apply to specific industries or needs:

  • SOC 2 (System and Organization Controls 2): SOC 2 is an auditing framework developed by the American Institute of CPAs (AICPA). It isn’t a prescriptive security standard but rather a process by which an independent auditor evaluates an organization’s controls in areas called the Trust Services Criteria – Security, Availability, Processing Integrity, Confidentiality, and Privacy . A SOC 2 report attests that a service provider has appropriate controls to safeguard client data. This is particularly important for cloud and SaaS providers. SOC 2 is known to be rigorous: the audit can take months and requires extensive evidence of controls (policies, logs, test results, etc.) . Many companies that handle data on behalf of others (e.g., software vendors) pursue SOC 2 compliance to provide assurance to their customers. From a security officer’s perspective, SOC 2 can drive internal discipline (because you must document and prove your controls). However, it’s a point-in-time assessment – a snapshot via audit – so it should be combined with continuous monitoring internally .
  • PCI-DSS (Payment Card Industry Data Security Standard): PCI-DSS is a sector-specific standard mandated by the major credit card companies for any organization that processes or stores payment card data. It contains 12 core requirements covering network security, access control, data encryption, vulnerability management, monitoring, and testing . Compliance is enforced by regular audits or self-assessments, and non-compliance can result in fines or the revocation of card processing privileges. Even if you’re not directly handling credit cards, PCI-DSS is often regarded as a benchmark for strong security practices (especially in network and application security). The standard was updated to PCI-DSS version 4.0, which became mandatory in 2024 and introduced stronger requirements like mandating multi-factor authentication for all administrative access . Security officers in the retail or finance space absolutely need familiarity with PCI-DSS.
  • HITRUST CSF: The HITRUST Common Security Framework is a comprehensive framework tailored for the healthcare industry. It harmonizes requirements from many standards and regulations (including HIPAA, PCI, NIST, ISO, etc.) into a single overarching framework . Healthcare organizations often choose HITRUST certification to demonstrate compliance with HIPAA’s security rule and other healthcare regulations in one go. HITRUST is very detailed and comes with an assurance program similar to an audit. If you operate in healthcare or handle health data, HITRUST CSF is a key framework to know in addition to pure HIPAA rules.
  • NERC CIP: The North American Electric Reliability Corporation’s Critical Infrastructure Protection standards are a set of cybersecurity requirements for the electric power industry. NERC-CIP standards are mandatory in the U.S. and Canada for bulk electric system operators, aiming to protect critical power infrastructure from cyber attacks . They include controls on asset classification, personnel training, incident response, recovery planning, and third-party risk management in the utility sector . A security officer in the energy or utility sector will likely be working under the NERC-CIP framework to maintain regulatory compliance.
  • Other Sectoral Frameworks: Nearly every critical sector has its own cybersecurity guidelines or regulations. For example, the Federal Information Security Management Act (FISMA) governs U.S. federal agencies and contractors, requiring them to follow NIST 800-53 controls and risk management processes . In finance, regulators often require alignment with frameworks like NIST or ISO, and in some regions there are specific guidelines (for instance, the SWIFT security controls for interbank communications). Security officers should identify the frameworks or standards relevant to their industry and region, as these often must be layered onto the general frameworks described earlier.

Regional and National Cybersecurity Frameworks

Cybersecurity frameworks also exist at regional or national levels, sometimes as laws or regulations that organizations must follow. These often incorporate or reference the global standards above, but it’s important to understand the local landscape. Here we highlight key frameworks or regulations in the United States, European Union, and Asia-Pacific.

United States

The U.S. has been a frontrunner in developing cybersecurity frameworks, many of which have global influence. Aside from the NIST CSF described earlier (which originated in the US but is now international), notable U.S.-specific frameworks include:

  • CMMC (Cybersecurity Maturity Model Certification): This is a relatively new program (initiated by the Department of Defense) that will require all DoD contractors to adhere to certain cybersecurity practices. CMMC 2.0, announced in 2021 and finalized in late 2024, simplifies the model to 3 levels of maturity, each mapping to a set of NIST SP 800-171 security controls for protecting sensitive government data . In essence, depending on the sensitivity of information a contractor handles, they must implement a corresponding baseline of controls and undergo assessments (self-assessment at Level 1, third-party or government assessments at higher levels) . CMMC is expected to be phased into defense contracts through 2025 and beyond. For security officers in any company that sells to the DoD, CMMC compliance is becoming mandatory.
  • HIPAA Security Rule: In healthcare, the HIPAA law requires organizations dealing with protected health information (PHI) to implement administrative, physical, and technical safeguards. The HIPAA Security Rule is essentially a mini-framework by itself, outlining requirements for risk analysis, access controls, incident response, transmission security, etc. Compliance is legally mandatory in the U.S. healthcare sector . Unlike voluntary frameworks, HIPAA is enforceable by law (violations can incur heavy penalties). A security officer in healthcare must ensure that any chosen framework (be it NIST, ISO, or HITRUST) also satisfies HIPAA requirements.
  • State and Sectoral Regulations: Various U.S. states and regulators have their own cybersecurity requirements. For instance, the New York Department of Financial Services (NYDFS) has cybersecurity regulations for financial institutions; the SEC has proposed rules on cybersecurity risk management for public companies; and critical infrastructure sectors (energy, transportation, etc.) have guidelines from agencies like CISA or sector-specific bodies. While not “frameworks” in name, these regulations often reference established frameworks (NIST, ISO) or standards. For example, FISMA for federal agencies effectively forces use of the NIST Risk Management Framework and NIST 800-53 controls . As an expert, one strategy is to maintain a mapping of controls between frameworks and regulations – so if you comply with NIST 800-53, you can demonstrate how that meets a HIPAA or a state requirement.
  • SOC 2 and Contractual Standards: In the US tech industry, it’s extremely common for businesses to demand their vendors have SOC 2 reports or ISO 27001 certification. These are not government frameworks, but market-driven standards. A CISO operating in the US should be prepared to either pursue such attestations or at least answer to these frameworks when customers ask. The prevalence of SOC 2 (especially among cloud service providers) means it’s practically a de facto requirement in many B2B contracts.

In summary, the US landscape mixes voluntary frameworks (like NIST CSF) with mandatory regulations (like HIPAA, CMMC). Many American organizations voluntarily align with NIST or CIS controls, even if not required, because it’s considered best practice. The trend in recent years is toward more regulation – for example, critical pipeline operators now have cybersecurity directives after incidents – so staying agile with frameworks helps meet new rules as they come.

European Union

The European Union’s approach to cybersecurity has been through both broad regulations and targeted directives:

  • NIS 2 Directive: The Network and Information Security Directive 2 is the EU’s updated cybersecurity framework for critical infrastructure and digital services, replacing the original 2016 NIS Directive. NIS2 came into force in January 2023 and EU member states must transpose it into national law by October 2024 . This directive significantly expands the scope of covered entities (to include more sectors and medium-sized companies) and imposes higher security standards and reporting obligations across the EU. NIS2 emphasizes governance – holding senior management accountable for cybersecurity – and mandates risk management measures aligned with the state of the art . It essentially requires organizations in scope to implement a framework of security controls covering areas like incident response, business continuity, supply chain security, encryption, access control, etc., referencing European or international standards . Non-compliance can lead to penalties (up to €10 million or 2% of global turnover for essential entities) . For a security officer in the EU, NIS2 is a game-changer because it makes what was once guidance into law for a broad swath of companies. Aligning with frameworks like ISO 27001 or NIST CSF can help demonstrate compliance with NIS2’s requirements, since the directive encourages using recognized standards .
  • GDPR (General Data Protection Regulation): While primarily a data privacy law, GDPR has important cybersecurity components. It requires organizations to implement “appropriate technical and organizational measures” to protect personal data, essentially forcing a risk-based security framework for any personal data processing . GDPR also mandates breach notification within 72 hours and documentation of security measures. The penalties for data breaches or inadequate security under GDPR are infamous – up to 4% of global annual turnover or €20 million, whichever is higher . A security officer in an EU context must consider GDPR’s requirements when designing their security program. Many align their controls with ISO 27001 or similar and add specific data protection controls (like pseudonymization, data minimization) to address GDPR. GDPR doesn’t prescribe a specific framework, but it effectively nudges organizations to adopt one to manage compliance and be able to demonstrate due diligence.
  • Cyber Essentials (UK): In the United Kingdom (which, post-Brexit, is outside the EU but still often aligned on security practices), Cyber Essentials is a government-backed scheme defining a basic cybersecurity baseline. It focuses on five technical control areas: firewalls, secure configuration, access management, malware protection, and patch management . Organizations can get Cyber Essentials certified via self-assessment or a more rigorous Cyber Essentials Plus certification. It’s required for many UK government suppliers and has become a useful minimum standard for smaller businesses. While not as comprehensive as NIST or ISO, Cyber Essentials is a good starting checklist and ensures coverage of common threats.
  • Additional EU efforts: The EU Cybersecurity Act has established a framework for EU-wide cybersecurity certification of products and services, which is an evolving area. We also see sector-specific regulations like the Digital Operational Resilience Act (DORA) for financial services (coming into effect in 2025), which will enforce cybersecurity and ICT risk management requirements for banks and financial firms. ENISA (the EU Cybersecurity Agency) often publishes guidelines and mappings (for example, mapping NIST CSF to European context). A security officer operating in Europe should keep an eye on both EU-level directives and local country implementations. Often, aligning with international frameworks (ISO, etc.) puts you in a good position, but you must adjust for local law.

Asia-Pacific

The Asia-Pacific region does not have a single unified framework, but individual countries have introduced their own cybersecurity regulations and are increasingly aligning with global standards:

  • China – MLPS 2.0: China’s Multi-Level Protection Scheme (MLPS) is a unique national cybersecurity framework. It requires that companies operating in China classify their information systems into one of five security levels based on the potential impact of a security breach (ranging from Level 1 for minimal impact, up to Level 5 for systems critical to national security) . Each level comes with specific security requirements mandated by Chinese law – including controls around authentication, monitoring, data localization, and even national security reviews for higher levels. MLPS 2.0 (updated as part of China’s Cybersecurity Law) essentially forces organizations in China to implement controls proportional to the risk a system poses to national interests . For example, a basic corporate website might be Level 2, whereas a banking system might be Level 4 or 5, with very stringent requirements. Security officers working in China or with systems in China need to be aware of MLPS for compliance. While MLPS shares concepts with other frameworks (risk tiering, baseline controls), it is very country-specific in implementation.
  • Australia – Essential 8: Australia’s Cyber Security Centre (ACSC) created the Essential 8 – a set of eight essential mitigation strategies aimed at helping organizations protect Windows-based networks . This baseline includes practices like application whitelisting, patching applications and OS, restricting administrative privileges, and daily backups . The Essential 8 comes with a maturity model and is recommended (and in some cases required) for Australian government agencies and businesses. It’s somewhat analogous to the CIS Controls basic level, focusing on the most common threat vectors. Security officers in Australia often use Essential 8 as a starting point, then build on it with broader frameworks (the Australian Signals Directorate also publishes the broader ISM – Information Security Manual – which aligns with international standards).
  • Singapore and others: Singapore has a Cybersecurity Act (2018) focusing on critical information infrastructure protection, and the Monetary Authority of Singapore (MAS) has detailed Technology Risk Management (TRM) Guidelines that financial institutions must follow – these incorporate international best practices similar to NIST/ISO. Japan has its Cybersecurity Strategy and promotes adoption of the Information Security Management System (which is effectively ISO 27001 – Japan has many ISO-certified firms). India is working on an updated National Cyber Security Strategy and, in the interim, uses guidelines from its CERT and sector regulators (often leveraging ISO 27001 or PCI-DSS in banking). Many other Asian countries (Malaysia, Indonesia, South Korea, etc.) have national cybersecurity policies that encourage organizations to follow frameworks like ISO 27001 or NIST.

In summary, Asia-Pacific organizations often adhere to global standards but must also navigate local requirements. A common approach is dual compliance: e.g., a multinational might use ISO 27001 as a base across all branches, but ensure that in China they also meet MLPS specifics, in Australia they tick off the Essential 8, and in Singapore they follow MAS guidelines. The good news is there’s significant overlap – these regional frameworks generally don’t reinvent cybersecurity controls; they reinforce the same principles with local tweaks. As an expert, one should monitor regulatory developments in the countries where their organization operates, since new laws (like data protection acts or cyber laws) can introduce security obligations that map to existing frameworks.

Comparing NIST CSF, ISO 27001, and CIS Controls

Among the many frameworks, NIST CSF, ISO/IEC 27001, and CIS Controls are often considered the “big three” that security leaders choose from or combine. Each has a distinct philosophy and use-case. Here is a comparison of these three frameworks from an expert perspective:

  • Origin and Adoption: NIST CSF was developed by a U.S. government agency originally for critical infrastructure, but it’s now globally recognized and used in various industries (particularly popular in North America) . ISO 27001 is an international standard developed through global consensus, widely adopted in Europe, Asia, and worldwide (with formal certification in over 150 countries) . CIS Controls originated from a community of cyber experts (sans/CIS) as a grassroots technical guideline and have been embraced by organizations globally as a practical tool, especially in the U.S. and by smaller firms .
  • Scope and Level of Detail: NIST CSF provides a high-level framework for managing cyber risk – it outlines broad outcomes (like “detect malicious activity” or “restore services”) under its core functions, but does not dictate specific controls. This makes it flexible and applicable to any environment, but it requires translation into concrete measures (often by using it in tandem with detailed control catalogs like NIST SP 800-53 or CIS) . ISO 27001 is moderately detailed – it has specific clauses you must follow for your ISMS (risk assessment process, asset management, etc.) and provides a menu of controls (Annex A), but many controls are described at a high level (e.g., “ensure secure system engineering principles are applied”) which you have to interpret . CIS Controls are very detailed and prescriptive –they tell you exactly what to do (e.g., “Implement anti-malware on all systems and configure automatic updates”) and thus leave little ambiguity on technical safeguards. However, CIS focuses on controls only and doesn’t guide you on overarching governance or risk management process.
  • Flexibility vs. Certifiability: NIST CSF is voluntary and flexible; there is no formal “compliance” or certification for it. Organizations can self-declare alignment or use it as a maturity model, customizing sections as needed. ISO 27001 is formal; it has a fixed set of requirements and an external audit process for certification. This means ISO is less flexible – you either meet the requirements or you don’t – but it provides the benefit of an independent certification which can be shown to stakeholders . CIS Controls are voluntary like NIST, with no official certification (though some auditors or cybersecurity firms might offer CIS evaluations). CIS is often seen as a practical baseline to implement quickly, but not something you get a certificate for; instead, success is measured by reduced incidents or improved security metrics.
  • Use Case and Organizational Fit: NIST CSF is often recommended for organizations that want a comprehensive risk management framework without immediately diving into an audit. It’s great for building a security program from the top down, especially if you need to communicate with executives or comply with a broad mandate (many U.S. government-linked contracts refer to NIST CSF) . ISO 27001 is suitable when an organization needs to prove its security to external parties – for example, a company processing sensitive data for clients in multiple countries might pursue ISO 27001 to meet various customer and regulatory expectations at once . It’s also a strong choice if the culture is inclined towards formal processes and continuous improvement via audits. CIS Controls are ideal for quick wins and technical focus – for a smaller enterprise or one just starting in cybersecurity, CIS gives a clear priority list (start with IG1 controls) that significantly reduces risk from common attacks. It’s also useful for very tech-driven discussions (e.g., a security engineer’s playbook). Many mid-sized organizations in fact use a hybrid approach: use NIST CSF or ISO as the management framework, and use CIS Controls as a practical implementation guide. This layered approach covers strategy and execution.
  • Maintenance and Evolution: All three frameworks are periodically updated. NIST CSF saw a major update to 2.0 in 2024 (introducing the Govern function and other improvements) . ISO 27001 was last revised in 2022, aligning its control set with the updated ISO 27002:2022 (for example, consolidating some controls and adding new ones for threat intelligence and cloud security). CIS Controls update more frequently; version 8 was released in 2021 to address cloud and remote work, and we can expect further updates as technology changes . For a security officer, this means whichever framework you use, you must plan to stay current. Framework updates often integrate emerging best practices (for instance, NIST CSF 2.0’s added emphasis on governance and supply chain risk reflects recent lessons ). Adapting to a new version usually requires a gap assessment and tweak to your program, but it ensures your security practices remain effective against evolving threats.

In summary, NIST CSF vs ISO vs CIS is not an either/or choice – it’s about selecting the right tool for the job. NIST CSF and ISO 27001 largely overlap in intent (risk-based approach to security) but differ in formality; CIS is a complementary piece that delivers technical depth. As an expert, my view is: if you need external validation, go for ISO 27001; if you want flexibility or are working across a broad ecosystem, NIST CSF is excellent; if you need to quickly uplift your defenses, start with CIS Controls. Most mature organizations eventually use elements of all three. For example, you might get ISO certified, use NIST CSF for internal assessments, and check your IT operations against CIS benchmarks – leveraging each framework’s strengths.

Emerging Frameworks and Trends (2023–2025)

The cybersecurity landscape never stands still. New frameworks emerge and existing ones evolve to address emerging technologies and threats. Since January 2023, several noteworthy frameworks or updates have appeared. Here we highlight these and discuss whether security officers should take them into consideration:

  • NIST Cybersecurity Framework 2.0 (2024): As discussed earlier, NIST CSF’s latest version 2.0 was published in February 2024 . This update is definitely worth attention. If your organization uses NIST CSF 1.1, you will want to transition to 2.0 to incorporate its new Govern function and expanded guidance. The changes stress the role of governance (cybersecurity as an enterprise risk, with board-level visibility) and supply chain risk management . NIST also provided new profiles and implementation examples, making CSF 2.0 easier to adopt for various sectors. Consideration: Yes – NIST CSF 2.0 should be on your radar. Even if you operate outside the U.S., CSF 2.0’s concepts align with global best practices and will likely influence other standards. It’s also backward-compatible in spirit; upgrading from 1.1 to 2.0 is more evolutionary than a complete overhaul, but it’s important to fill any gaps (for instance, ensure you have governance structures corresponding to the new function).
  • EU NIS2 Directive (2023): NIS2 is effectively in force now and EU countries are implementing it into law . If you operate in the EU or provide services into the EU, absolutely consider NIS2. This may mean performing a readiness assessment against NIS2 requirements (many consultancies offer mappings of NIS2 Article 21 measures to frameworks like ISO 27001 or NIST). Given that NIS2 affects an estimated 160,000 companies in the EU , it’s likely that even if you are not directly covered, your business partners or supply chain might be – which in turn could flow down expectations to you. The directive’s focus on accountability and supply chain security means security officers should strengthen those areas (e.g., get executive buy-in and integrate cybersecurity into vendor risk management). In short, NIS2 raises the bar for cybersecurity in Europe; it should be treated as both a compliance obligation (if in scope) and a signal of best practice (even if not strictly required, following NIS2 guidelines is prudent).
  • CMMC 2.0 (2024/2025 rollout): For companies in the defense industry supply chain, CMMC 2.0 is a huge development. By 2025, new DoD contracts will start to include CMMC requirements, and by 2028 virtually all defense contracts will require a certain CMMC level . Security officers at DoD vendors should already be aligning their controls with NIST SP 800-171 (which is the basis for CMMC Level 2). Even outside the defense realm, CMMC is influential: it represents a trend of maturity-based certification that could expand to other sectors (imagine a future where suppliers in critical industries need cybersecurity certifications to win contracts). Consideration: Yes, if you have any business in defense or plan to, CMMC is mandatory. If not, you may not implement CMMC per se, but it’s wise to note the trend – other regulators might borrow the concept. We see echoes of this in proposed EU schemes and even in private sector (some big tech companies are asking vendors to fill out detailed security questionnaires or adhere to frameworks). Thus, the idea of “prove your cybersecurity maturity” is becoming commonplace.
  • ISO/IEC 27001:2022 and related standards: ISO 27001 received a minor but important update in 2022. The core structure of the ISMS remains, but the control set in Annex A was updated (aligned to ISO 27002:2022) – some controls were merged, some new ones added (like Threat Intelligence, ICT readiness for business continuity, and cloud security). Organizations certified on ISO 27001:2013 will need to migrate to the 2022 version by the end of 2025 as per ISO rules. This is a relatively straightforward update for those already compliant, but new certifications are now against the 2022 version. Additionally, we have new complementary standards like ISO 27701 (privacy extension to 27001), and ISO 27017/27018 for cloud security and cloud privacy. Consideration: Yes, for those already invested in ISO, stay updated on 27001:2022 changes. For those not using ISO, this doesn’t change the landscape drastically – it basically refreshes ISO’s relevance by including modern topics. It remains a top framework to consider for formal security assurance.
  • Artificial Intelligence Risk Management Framework (AI RMF) 1.0: In January 2023, NIST released the AI Risk Management Framework 1.0 – a framework for managing risks of AI systems . While not directly a “cybersecurity” framework, it addresses a growing area of concern that overlaps with security (e.g., integrity of AI models, privacy of data, etc.). It provides principles for trustworthy AI (accuracy, explainability, etc.) and a process to map, measure, manage, and govern AI risks. Consideration: For most security officers, AI RMF is something to be aware of, especially if your organization is deploying AI/ML solutions. It’s not a mandatory standard, but following it could become important to demonstrate responsible use of AI. The EU is also working on an AI Act which will impose some risk-management requirements. So while AI RMF is emerging and niche, it’s analogous to how privacy frameworks started – optional at first, then increasingly essential. If your cybersecurity program is expanding to include AI systems (e.g., machine learning models in products), then looking at AI RMF (and other guidance like OECD AI principles) is recommended.
  • Zero Trust Architecture (ZTA) frameworks: In the last couple of years, “Zero Trust” went from a buzzword to formal strategies. NIST SP 800-207 (2020) defined zero trust principles, and in 2023 many organizations (spurred by the U.S. Executive Order on Cybersecurity) have been implementing Zero Trust models. While Zero Trust is more of an architectural approach than a governance framework, it has spawned maturity models and reference frameworks (for example, CISA’s Zero Trust Maturity Model was updated in 2023). Consideration: Security officers should consider zero trust guidelines as part of their strategy. If you haven’t already, familiarize yourself with the core tenets (verify explicitly, use least privilege, assume breach) and assess your environment against them. This is not a separate compliance framework you get certified in; rather, it complements existing frameworks by focusing on identity-centric and granular access controls. Given the momentum behind zero trust (especially in government and large enterprises), incorporating its principles will likely be expected as a best practice.
  • Product Security and Supply Chain Frameworks: Post-2023, there’s increasing focus on supply chain security and product security. The EU’s proposed Cyber Resilience Act will require manufacturers of digital products to ensure certain cybersecurity requirements (essentially a framework for secure product development and lifecycle). In the U.S., the SEC’s 2023 rules require disclosure of cybersecurity governance and incidents for public companies, indirectly compelling a framework for governance. Also, initiatives like the Software Bill of Materials (SBOM) requirements and supply chain standards (e.g., NIST’s Secure Software Development Framework) have gained traction. Consideration: For CISOs, supply chain and product security frameworks are becoming as important as internal IT security frameworks. If your organization develops software or hardware, adopting frameworks like BSIMM or OWASP SAMM (for software security) could be wise. If you rely on a lot of vendors, aligning with supply chain risk management frameworks (like NIST SP 800-161 or ISO 27036) will help address emerging requirements. These might not yet be as universally adopted as NIST CSF or ISO 27001, but they are rapidly moving from niche to mainstream due to high-profile supply chain attacks.

In evaluating emerging frameworks, a good rule is to weigh relevance and longevity. Not every new guideline will become a must-have; some are experimental or apply only to specific tech. For example, AI RMF is crucial if you’re in AI, but if not, it can be a lower priority. On the other hand, something like NIS2 or CMMC, once in law, instantly jumps to high priority if it affects you. As an expert, I recommend maintaining a watchlist of new frameworks and updates. Engage in professional networks or working groups to stay informed. Often, emerging best practices eventually get folded into the major frameworks – for instance, supply chain security was an emerging concern a few years ago, and now it’s explicitly addressed in NIST CSF 2.0 and ISO 27002:2022. By paying attention early, you can proactively strengthen your program rather than play catch-up when regulations hit.

Final Thoughts

Cybersecurity frameworks are vital guideposts for any organization aiming to manage risk and protect its digital assets . A security officer today must navigate a complex landscape of frameworks and regulations – from global standards like NIST CSF and ISO 27001, to industry-specific requirements and regional laws. This complexity can be daunting, but it also presents an opportunity: by leveraging well-established frameworks, you don’t have to start from scratch. They provide structured knowledge accumulated from industry experts and lessons learned from countless cyber incidents.

In practice, no single framework will cover everything. The most robust cybersecurity programs often integrate multiple frameworks. For example, an organization might use NIST CSF as a high-level management tool, ISO 27001 for certification and formalism, CIS Controls for day-to-day operations, and then layer on any required compliance frameworks (HIPAA, PCI, NIS2, etc.) to meet specific demands. Rather than seeing this as redundant, think of it as using the right tool for each aspect: governance, technical controls, assurance, and compliance each might call for a different framework. The good news is many frameworks map to each other. As an expert tip, maintain a mapping document or matrix that cross-references controls and requirements across frameworks – this turns the burden of “many frameworks” into a more manageable alignment exercise, showing how one effort satisfies multiple criteria.

It’s also important to remember that frameworks are a means to an end, not the end itself. The ultimate goal is to reduce cyber risk and protect the organization. A framework helps identify gaps and structure your approach, but it will be effective only if you tailor it to your organization’s context. As an expert, I’ve seen organizations mechanically implement a framework but miss the spirit – for example, getting ISO 27001 certified yet still suffering breaches because they treated it as a checklist, not a living risk management process. My advice: use the framework as a living tool. Continuously improve upon it, go beyond minimum requirements where it makes sense, and foster a culture that understands the why behind the what.

Finally, keep an eye on the horizon. Cybersecurity is evolving – threats like ransomware, supply chain attacks, and AI-driven threats are prompting new guidelines. We discussed emerging frameworks since 2023; by 2026 there will be others. A good security officer is both well-grounded in fundamentals and adaptable to new developments. The established frameworks (NIST, ISO, CIS, etc.) provide an enduring foundation that has stood the test of time. If you have those fundamentals right, integrating new elements like Zero Trust or AI risk management becomes far easier. In contrast, if you chase every new framework without a strong base, you risk initiative fatigue and fragmentation.

In conclusion, treat this article as a reference tool. We presented the major cybersecurity frameworks in use globally, outlined regional nuances, compared top frameworks, and flagged what’s new on the scene. Use it to guide discussions with your team and leadership: Are we using the right framework for our needs? Should we certify to a standard to gain trust? How do we comply with new regulations? And importantly, how do all these efforts tie together into a coherent security strategy? By answering these questions, you as a security expert can ensure that your organization not only checks the compliance boxes but truly builds resilience against cyber threats. Remember, a framework is effective only through diligent implementation and continuous commitment – but with the right framework as a foundation, you are far better equipped to handle whatever cyber challenges come your way.