The starting bar with no regulator
No law forces this one. Boards, banks, insurers and customers simply ask: are you aligned to NIST or CIS? It is the recognized way to answer 'are we secure?' with something better than a shrug.
NIST CSF 2.0 + CIS Controls v8.1
NIST CSF 2.0 and CIS Controls v8.1 are the plain-English bar for a defensible security program. We assess your controls against both, then build the shortest path to alignment your team can actually execute.
Scope, timing, and fees are documented before work begins.
No law forces this one. Boards, banks, insurers and customers simply ask: are you aligned to NIST or CIS? It is the recognized way to answer 'are we secure?' with something better than a shrug.
Every heavier framework (SOC 2, ISO 27001, HIPAA) overlaps these controls. Work done here is never wasted; it is the down payment on whatever a customer demands next.
There is no such thing as a NIST certificate or a CIS certificate. Anyone selling you one is lying to you. What exists is alignment you can evidence, and that is what we build.
Best fit: businesses of 25 to 200 people with no framework being demanded of them yet, who want a recognized, defensible security baseline with evidence to show whoever asks next.
Not the right fit: organizations being held to a specific certifiable framework by a customer or regulator; go straight to the readiness service for that framework instead.
NIST CSF 2.0 is the U.S. standards institute's cybersecurity framework: six functions (Govern, Identify, Protect, Detect, Respond, Recover) that describe what a working security program does. CIS Controls v8.1 is the practical companion: a prioritized list of concrete safeguards, with Implementation Group 1 defined as essential cyber hygiene for smaller organizations.
Neither one certifies anybody. They are measuring sticks, and that is their power: when your insurer, a customer's security team, or your own board asks where you stand, 'assessed and aligned to NIST CSF and CIS, with the evidence on file' is an answer they all recognize.
Our assessment measures every control against both standards at once, so one engagement produces one honest picture and one prioritized roadmap, readable by leadership and executable by your IT team or MSP.
Every engagement includes
Example alignment matrix
Illustrative structure only. Your findings, owners, evidence, and priorities are based on your environment.
See what your scope includesWe learn how your business runs, pick the right depth, and fix the price in writing.
Controls reviewed against both standards, evidence collected, every gap scored and ranked.
Your team or MSP executes the roadmap with our direction; evidence lands in one index. A reassessment a year later proves the progress.
How pricing works
Your quote is built from your headcount, your systems, and how far you are from the bar. It is fixed in writing at the free 30-minute call, before any work starts, and it never changes after you approve it.
Separately scoped, always disclosed
Remediation labor, new software, and any external testing are never buried in the quote; they appear as their own line items or not at all. If a customer later demands a certifiable framework, this work carries forward and we say so up front.
No, and this matters: neither NIST nor CIS certifies organizations, and anyone selling a 'NIST certificate' is misleading you. What exists is documented alignment, which is exactly what insurers, customers and boards actually check for. We build that documentation.
Both at once. They overlap heavily and we assess each control against the two standards in one pass. NIST gives you the recognized language; CIS gives your IT team the concrete to-do list. One engagement, both answers.
Then this work becomes your head start. The control evidence, policies and roadmap from alignment map directly onto the heavier frameworks, and the readiness engagement picks up from where alignment left off instead of starting over.
A few hours total across the assessment window: a kickoff call, one or two interviews, and evidence uploads to a private shared folder. Your operation keeps running.
We cover your organization, your deadline, and who is asking for what. You leave knowing the likely scope, the timeline, and your next step, with the price fixed in writing before any work starts.
Prefer phone or email?
(754) 216-9664 info@hardenwell.com
Do not include PHI or sensitive records in booking notes. See our Privacy Policy.