Quick answer

OptiTech loads CSF 2.0 as a framework with its six functions and categories as the catalog, maps your existing controls onto the outcomes, and presents your posture per function as a live view: Govern through Recover, each scored from actual control status. You define a target profile, and the gap between current and target becomes a prioritized plan, the same delta mechanics as any other framework, just tier-based instead of pass-fail.

Profiles as the working model

CSF adoption is profile work, and the platform makes profiles concrete:

  • Current profile: computed from your live controls, not a workshop's self-assessment. If Detect looks strong in the workshop but your logging checks fail continuously, the dashboard says Detect is weak, which is the truth you want.
  • Target profile: set per category based on your risk appetite (an outcome your board should endorse, which is very much a Govern activity).
  • The roadmap: gaps between profiles become owned tasks, and progress is visible as the function scores trend toward target on the dashboard.

Govern gets real teeth

The 2.0 Govern function maps naturally onto platform features: policy machinery with review cycles, documented roles via control ownership, supply chain risk through the supplier register, and board oversight through generated reporting. Govern stops being a binder and becomes the operating layer over everything else.

One control set under many maps

Because the CSF is a superstructure, its value multiplies with cross-mapping: the same MFA control that scores your Protect function also serves ISO 27001, NIS 2, and SOC 2. Organizations that report in CSF terms externally (insurers, US partners, federal-adjacent customers referencing NIST 800-53) get that reporting from the same workspace that runs their certifications.

See OptiTech in action

Get a personalized walkthrough of automated compliance for your team. No commitment required.