Once nonprofits decide to improve cybersecurity, the next question is usually:
“Which framework should we use?”
The two most common answers are the NIST Cybersecurity Framework (NIST CSF) and the CIS Critical Controls. Both are widely recognized, accepted by insurers and regulators, and capable of supporting a strong cybersecurity program. The difference is in how they approach the problem.
NIST CSF is designed as a strategic roadmap. It helps organizations think about cybersecurity as a business and operational risk, not just an IT issue. The framework is organized around functions like Identify, Protect, Detect, Respond, Recover, and Govern, helping leadership connect security efforts to governance, compliance, and long-term planning.
For nonprofits with boards, grant requirements, or multiple departments involved in decision-making, NIST often provides clearer organizational structure and reporting.
CIS Critical Controls take a more tactical approach. Instead of focusing on broad outcomes, CIS provides prioritized technical actions organizations can implement immediately. It acts more like a practical checklist for IT teams:
- Secure accounts
- Patch systems
- Inventory devices
- Monitor activity
- Improve ransomware defenses
For smaller nonprofits with limited staffing, CIS often feels more approachable because it focuses on concrete implementation steps instead of governance language. A simple way to think about it:
NIST focuses heavily on the “why”
CIS focuses heavily on the “how”
In practice, the choice is less about which framework is “better” and more about what your organization needs most right now. If leadership is focused on governance, board reporting, and long-term program maturity, NIST CSF may be the stronger fit. If the immediate need is operational improvement and technical hardening, CIS Controls often provide faster direction.
One important takeaway is to avoid “custom” or proprietary frameworks created by vendors or consultants. Recognized standards like NIST and CIS are easier to defend during audits, align better with cyber insurance requirements, and evolve alongside the changing threat landscape.
The best framework is usually the one your organization will consistently follow over time.
Filament Protip
All of our service area leaders has dozens of years of experience. These are protips they’ve picked up along the way that you can use right now to solve common issues.