The most common question we get is which framework do we need? It usually arrives with an implied deadline — a customer questionnaire, an insurer, a procurement process, a regulator.
Here is the answer, up front: any of them. Pick one and start your journey.
That is not a dodge. Every mainstream security framework is asking the same underlying questions in a different vocabulary. Do you know what you own? Who can reach it, and how strongly are they authenticated? Is it patched? Do you keep logs, and would anyone notice? Could you recover? Something that governs how those questions get answered beats a perfect framework you are still choosing in three months.
Why the choice is reversible
People freeze on this decision because they fear picking wrong and doing the work twice. That fear is well founded when every framework is a separate project — a new spreadsheet, a fresh round of evidence gathering, the same access-control question answered four times in four vocabularies. The cost multiplies with each one, and the answers drift apart. That drift is the real failure: four descriptions of one control, three of them out of date.
It stops being true the moment every standard is mapped onto one common spine. We use NIST CSF 2.0 — broad enough to receive almost anything, freely available, and structured around outcomes rather than one sector's controls. Every requirement in every other framework points at the CSF outcome it serves, so an answer given once propagates.
Practically:
- Evidence attached for one framework counts for the others it satisfies.
- A configuration check that passes in your cloud tenancy becomes evidence against every mapped requirement, not just the one you were thinking about.
- Adding a framework later is mostly a reconciliation exercise, not a restart.
Which is the real argument for starting today: the work transfers, so the first choice is low-stakes.
If nothing is forcing your hand
Start with our SMB Minimum Baseline. It is our own baseline, sourced from publicly available security checklists and frameworks — inspired in particular by Health New Zealand's security checklist for health service providers and the NCSC Minimum Cyber Security Standards — then universalised so any small organisation can use it, whatever sector or country it is in. It is mapped to NIST CSF 2.0 and scored on the four-level CS-CMM maturity scale, Insufficient → Baseline → Better → Best, rather than a pass/fail tick.
Two things make it a good first framework rather than a smaller version of a big one:
- It marks a genuine minimum. Controls carry a threat-informed minimum flag, so "where do we have to get to" is a property of the baseline itself, not a judgement call you make control by control at 11pm.
- It is honest about maturity. Insufficient is a real, usable answer. A baseline that only lets you record success is a baseline that gets gamed.
There is no licence to buy and no certification body in the loop. It exists to get you to a defensible starting position quickly.
If something is forcing your hand
Then that is your framework, and the decision is already made. Broadly:
- A customer or supplier wants a certificate — a certifiable scheme such as ISO/IEC 27001, SOC 2, or a tiered small-business certification. These are the heaviest options; starting here without an existing management system is how programmes stall in month three.
- A regulator or sector obligation applies — the sector framework wins, and it is usually not optional. Health, finance and critical infrastructure each have their own.
- A government buyer or insurer names a baseline — national minimum standards exist for exactly this, and they tend to be short, outcome-worded and free to read. Worth knowing that they move: baselines get revised, renumbered and occasionally replaced, so anchor the underlying work rather than the document.
- You just want good practice — control catalogues and top-ten lists are free, specific, and a good source of concrete next actions.
Our standards catalogue lists what we support across each of these, with region, coverage and licensing for each. Whichever you enable, it maps to the same spine.
What to do this month
- Pick one. If an external deadline names a standard, that is your answer; if not, take the minimum baseline.
- Run an honest assessment. The goal is a truthful starting position, not a good score.
- Fix the gaps that also reduce real exposure first. Multi-factor authentication and administrative access governance appear in every framework and in every breach report, which is not a coincidence.
- Attach the evidence as you go, with expiry dates. The scramble the week before an audit is entirely avoidable and entirely self-inflicted.
The organisations that end up in a good position are rarely the ones that chose the perfect framework. They are the ones that started.