NIST CSF
A risk-based programme across Govern, Identify, Protect, Detect, Respond and Recover, with a costed roadmap and target maturity by quarter rather than a scored spreadsheet.
Assess NIST maturity- Frameworks
- ISO · NIST · NIS2 · GDPR · PDPL
- Output
- Audit-ready evidence
- Reporting
- Arabic and English
Why organisations get stuck
Compliance programmes stall when documents are written for auditors rather than for the people who have to follow them. Our NIST CSF programme produces a management system your own teams can operate after we leave.
What the programme covers
Each area below is a defined part of the engagement, with an owner, an output and a date.
Govern
Roles, policy and oversight for the cybersecurity programme.
Identify
Asset, supplier and risk understanding as the basis for every other function.
Protect
Safeguards across identity, data, platform and awareness.
Detect
Monitoring and detection tuned to the threats you actually face.
Respond
Planned, exercised response with defined authority to act.
Recover
Restoration capability that has been tested, not just documented.
Roadmap
A costed, sequenced plan with target maturity by quarter.
How the work runs
The same sequence on every engagement, so you know what happens next.
Assess
A gap assessment against the standard, showing what already passes as well as what does not.
Design
Scope, risk method, policy framework and control set agreed with your management team.
Implement
Documents written with the people who will follow them, and controls embedded in existing processes.
Audit
Internal audit and management review run properly, producing the records the certification body expects.
Sustain
Ongoing operation of the management system, or handover to your team with training.
What you get out of it
A system your team can run
Documents and processes written to be operated after we leave.
Audit-ready evidence
Evidence collected as work happens rather than assembled the week before the audit.
Bilingual delivery
Policies, training and reporting available in Arabic and English.
Before you enquire
How long does certification readiness take?
Can policies and reports be produced in Arabic?
Do you also perform the certification audit?
Where to go next
Assess NIST maturity
One scoping call with the consultant who would run the work. No obligation, no charge.
