Mapping ISO 27001 and NIST CSF 2.0 without losing your mind
Two frameworks, one control library. A practical mapping strategy that gives your board a single coverage view and doesn't require rewriting your ISMS.
Most teams pick ISO 27001 for the certificate, then get asked by their US customers for NIST CSF alignment. The trap is treating them as two separate control libraries and doubling the work. They aren't. They're two lenses over the same 100-ish controls.
Rule 1 - pick a canonical library
Your controls live in one library, ideally aligned to whichever framework you're being audited against first. Each control has a code, an owner, a status (Implemented / Partial / Not Implemented) and a description. Everything else - ISO 27001:2022 references, NIST CSF 2.0 subcategory references, CIS Controls v8 safeguards - is metadata on that control.
Rule 2 - map at the subcategory level, not the function level
Mapping SEC-001 to "NIST-CSF:PR" (Protect) tells you nothing. Mapping it to "PR.AA-01" (Identities and credentials are managed) tells you exactly which subcategory you're supporting. Same for ISO 27001 - map to A.8.5, not to Clause 8.
Rule 3 - accept one-to-many
One control usually satisfies multiple subcategories across frameworks. SEC-001 (MFA on admin accounts) satisfies NIST CSF PR.AA-01 AND ISO 27001 A.8.5 AND CIS 6.5. Store all three references. Coverage heatmaps do the counting for you.
Rule 4 - the coverage view is not the audit view
A framework coverage heatmap tells the board "are we covering the CSF Protect function?" - it does not tell the auditor "is this control implemented?". Keep them separate. In RiskEye the framework coverage view shows control-to-node counts; the control detail view shows status and last review.
The typical numbers
- ISO 27001:2022 has 93 controls across four themes.
- NIST CSF 2.0 has ~106 subcategories across six functions (Govern is new in 2.0).
- CIS Controls v8 has 153 safeguards across 18 controls.
- A well-run mid-market team typically has 60–90 canonical controls covering all three at ~85% coverage before a cert push.
Where teams get stuck
Trying to enforce a single owner per framework. Ownership is per-control, not per-framework. Two frameworks, one library, one owner per control. That's the whole discipline.
If you want a starting library aligned to ISO 27001:2022 + NIST CSF 2.0, ping hello@riskeye.io - we'll seed a private tenant with the seQure canonical set and hand you super-admin keys.
A 30-minute session with a seQure advisor is free. We'll seed a private tenant, walk through the working, and hand you super-admin keys the same day.