Organisational Certification

CSI Trustmark

For Organisational Converged Security Readiness

Issued by Converged Security Institute (CSI) Version 1.1 November 2025 Martorell, Catalonia, Spain
Start Self-Assessment →

Purpose

The CSI Trustmark certifies that an organisation has implemented a standards-aligned, enterprise-wide converged security posture in full compliance with ST-CSF.001 Converged Security Framework requirements, using CSI Product-Oriented Endorsed solutions, and demonstrating strategic maturity across the 12 mandatory implementation domains defined in the standard. It affirms comprehensive alignment with ST-CSF.001 Converged Security Framework (September 2025) and all supporting technical standards including ST-CSF.TIA.001 Technology Integration and Architecture, ST-CSF.IRBC.001 Incident Response and Business Continuity Framework, ST-CSF.TRA.001 Training and Awareness, and CSI Product-Oriented Endorsement and Readiness Framework within a unified strategic framework that addresses hybrid risks, systemic risks, and cascading risks through validated, market-ready converged security solutions and organisational resilience capabilities.

The CSI Trustmark aligns with the CSF Strategic Standards for Unified Risk Management and Organisational Resilience, which establishes that contemporary organisations face hybrid, systemic, and cascading risks that render traditional siloed security approaches inadequate. The Trustmark provides external validation that an organisation has successfully implemented the converged approach defined in the framework - integrating cybersecurity, physical security, and operational technology under unified governance, supported by SIEM/PSIM platforms, Zero Trust Architecture, and AI/ML-enabled threat intelligence.

Framework Alignment

This Trustmark reflects the comprehensive integration of Converged Security Framework Strategic Standards with CSI Product-Oriented Endorsed solutions validated across 22 capability domains and 5 evaluation dimensions. Key alignments include:

  • Governance and Leadership: Board-level oversight, Chief Converged Security Officer (CCSO) appointment, and unified KPIs.
  • Risk Management and Assessment: Unified risk register for cyber, physical, and OT risks, using ISO 31000:2018 methodologies.
  • Standards Integration: Integrated management system aligned with ISO 31000:2018, ISO 27001:2022, and ISO 22301:2019.
  • Technology Integration: Unified SIEM/PSIM platforms, Zero Trust Architecture, and AI/ML for predictive analysis.
  • Strategic Risk Management: Unified approach to hybrid, systemic, and cascading risks.
  • Standards Harmonisation: Alignment of ISO, European (NIS2, DORA, GDPR), and international (NIST, CIS) frameworks.
  • CSI Product-Oriented Endorsement Integration: Deployment of CSI Endorsed Platinum/Gold/Standard products.

Key Implementation Domains

3.1 Risk Management and Resilience:

  • Integrated risk registers covering cyber, physical, and operational domains.
  • Analysis of hybrid, systemic, and cascading risks.
  • Business continuity and crisis response aligned with ISO 22301.

3.2 Technology and Architecture:

  • Unified Platform Integration: Deployed SIEM/PSIM platforms with minimum 75% integration coverage.
  • Zero Trust Architecture: Continuous verification across IT, OT, and physical environments.
  • AI/ML-Enabled Security Operations: Predictive threat analysis and automated response.

3.3 Identity and Access Management (IAM):

  • Unified IAM systems for physical, IT, and OT access.
  • MFA enforcement and role-based access control (RBAC).

3.4 Incident Response and Continuity:

  • Unified incident response protocols for cyber, physical, and OT disruptions.
  • Defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).

3.5 Training and Culture:

  • Cross-functional security training with 95% or more personnel completion.
  • Regular multi-domain tabletop exercises and simulation drills.

Certification Process

Organisations are assessed for full ST-CSF.001 compliance across all 12 mandatory implementation domains through a multi-phase evaluation process.

  1. Pre-Certification Review: Comprehensive evaluation of strategic standards implementation and deployment of CSI Endorsed solutions.
  2. Technical Validation: Multi-disciplinary audit of implementation effectiveness and technical validation of deployed products in live environments.
  3. Scoring and Endorsement: Weighted scoring across twelve mandatory domains. A minimum threshold is required for Trustmark issuance.
  4. Ongoing Recognition: The Trustmark is valid for 24 months, with revalidation required for renewal.

Benefits of CSI Trustmark

  • Demonstrates full ST-CSF.001 Converged Security Framework compliance.
  • Enhances regulatory and stakeholder confidence.
  • Provides competitive differentiation through demonstrated unified risk management maturity.
  • Facilitates regulatory compliance across multiple frameworks (NIS2, DORA, GDPR).
  • Enables enhanced threat detection through cross-domain intelligence correlation.
  • Supports business resilience against hybrid, systemic, and cascading security incidents.
  • Validates product-oriented security excellence through deployment of CSI Endorsed solutions.

Addressing the Modern Threat Landscape

The CSI Trustmark directly addresses the three risk categories defined in the CSF Strategic Standards:

  • Hybrid Risks: Threats that exploit vulnerabilities across both physical and digital domains simultaneously. The Trustmark validates that organisations have integrated security measures across IT, OT, and physical environments with unified monitoring and coordinated response.
  • Systemic Risks: Risks arising from complex interactions within networked systems that can cascade across multiple sectors. The Trustmark requires unified risk registers covering cyber, physical, and OT domains with ISO 31000:2018 risk governance.
  • Cascading Risks: Sequential failures triggered by initial incidents that propagate through organisational dependencies. The Trustmark validates business continuity planning aligned with ISO 22301:2019 and defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).

Organisations achieving the CSI Trustmark demonstrate the ability to identify threat interdependencies, assess cascade effects, and maintain resilience across all three risk categories.

CSI Trustmark Implementation Pathway

Trustmark certification follows the structured implementation timeline defined in the CSF Strategic Standards, ensuring organisations achieve full framework compliance systematically:

Months 1-2 - Risk Assessment

Conduct comprehensive risk assessment across all domains - cyber, physical, and operational technology. Map threat interdependencies and potential cascade effects.

Month 3 - Governance Structures

Establish unified governance with executive sponsorship, appoint Chief Converged Security Officer (CCSO), and define cross-domain KPIs.

Months 4-6 - Technology Integration

Deploy integrated SIEM/PSIM platforms achieving minimum 75% integration coverage. Implement Zero Trust Architecture across IT and OT. Activate AI/ML threat analytics.

Months 7-9 - Protocols and Training

Develop unified incident response protocols. Implement cross-functional security training achieving minimum 95% personnel completion. Conduct multi-domain tabletop exercises.

Months 10-12+ - Continuous Monitoring

Implement continuous monitoring with real-time dashboards. Establish quarterly KPI reporting and annual self-assessment mechanisms. Submit for CSI Trustmark evaluation.

International Standards Integration

The CSI Trustmark validates compliance across the integrated standards framework:

ISO 31000:2018 - Risk Management

Provides overarching risk management principles and guidance for risk governance. Required for unified risk register and risk assessment methodology.

ISO 27001:2022 - Information Security

Addresses information security management systems (ISMS) and cybersecurity controls. Required for data protection, access management, and incident response.

ISO 22301:2019 - Business Continuity

Ensures business continuity resilience through BCM systems. Required for RTO/RPO definitions and crisis response planning.

NIS2 Directive - EU Cyber Resilience

European directive on network and information security. Required for critical infrastructure operators and digital service providers in the EU.

DORA - Digital Operational Resilience

EU regulation on digital operational resilience for financial entities. Required for financial sector organisations.

GDPR - Data Protection

EU General Data Protection Regulation. Required for all organisations handling personal data of EU residents.

Trustmark-certified organisations demonstrate alignment across all applicable standards, eliminating fragmented compliance approaches and reducing regulatory burden.

Global Compliance Alignment - CSI Trustmark and International Standards

The CSI Trustmark framework does not replace ISO 27001 or NIST CSF 2.0. Instead, it provides a converged-security readiness layer that aligns with these and other global standards, translating international governance, risk, protection, detection, response, recovery, and improvement expectations into a practical, evidence-based assessment model that extends across cybersecurity, physical security, operational technology, business continuity, privacy, and executive leadership.

Strategic Alignment Overview

ISO/IEC 27001:2022 Information Security Management

CSI Trustmark supports ISO 27001 leadership, risk, access, incident, continuity, awareness, compliance, and improvement requirements. CSI extends the ISMS model into physical security, OT, and converged governance.

NIST CSF 2.0 - Govern, Identify, Protect, Detect, Respond, Recover

All six NIST CSF 2.0 functions are addressed by CSI Trustmark domains. Governance, risk identification, technical protection, monitoring, incident response, and continual improvement are each assessed across cyber, physical, and OT domains.

EU Regulatory Framework - NIS2, DORA, GDPR

CSI Trustmark integrates NIS2 board-level oversight, DORA ICT risk management, and GDPR privacy-by-design requirements directly into its assessment criteria, providing structured readiness evidence for EU regulatory compliance.

Domain-to-Standard Mapping Table

CSI Trustmark Domain ISO 27001:2022 NIST CSF 2.0 EU Regulations
Domain 1 - Governance and LeadershipClauses 4, 5, 6, 9GovernNIS2 (board oversight)
Domain 2 - Risk ManagementClauses 6.1.2, 6.1.3 + Annex AGovern, IdentifyNIS2, DORA
Domain 3 - Technology IntegrationAnnex A technology controlsProtect, DetectNIS2, DORA
Domain 4 - Identity and Access ManagementAnnex A access controlsProtectGDPR, NIS2
Domain 5 - Incident Response and Business ContinuityAnnex A incident + continuityRespond, RecoverNIS2 (24-hr), DORA, GDPR (72-hr)
Domain 6 - Training and AwarenessAnnex A awareness + trainingGovern, ProtectNIS2
Domain 7 - Data Protection and PrivacyAnnex A information protectionGovern, Protect, IdentifyGDPR
Domain 8 - Compliance and Regulatory AlignmentClauses 4, 6, 9, 10 + Annex A complianceGovernNIS2, DORA, GDPR
Domain 9 - CCSO Policy and LeadershipClause 5 - LeadershipGovernNIS2 (board accountability)
Domain 10 - Continuous ImprovementClause 10 - ImprovementGovern, Identify, Respond, RecoverAll EU directives

How to position CSI Trustmark compliance readiness

CSI Trustmark provides structured readiness evidence that supports formal compliance, audit preparation, and maturity benchmarking against ISO/IEC 27001:2022 and NIST CSF 2.0. It does not replace independent certification or regulatory assessment. Organisations that complete the CSI Trustmark Self-Assessment gain a documented evidence base that can materially accelerate their ISO 27001 audit preparation and NIST CSF maturity evaluation - while also demonstrating converged security readiness that goes beyond the scope of traditional information-security-only frameworks.

Added value beyond ISO 27001 and NIST CSF 2.0

Physical security integration (PSIM, access control, physical incident response)
Operational technology and ICS/SCADA security
Cross-domain hybrid, systemic, and cascading risk management
Executive leadership model through the CCSO role
Unified SIEM-PSIM technology convergence requirement
Zero Trust Architecture across IT and OT
Converged Incident Response (Class 1/2/3 classification)
Business continuity aligned with ISO 22301 and operational resilience

Trustmark Assessment KPIs

CSI Trustmark assessment measures organisational performance across quantifiable indicators drawn from the CSF Strategic Standards:

KPI Minimum Threshold
SIEM/PSIM Platform Integration Coverage75% minimum across all security domains
Cross-Domain Security Training Completion95% of all personnel
Incident Detection Time (Mean Time to Detect)Continuously monitored and benchmarked
Cross-Domain Incident Response ActivationUnified protocols covering cyber, physical, and OT
Business Continuity Plan CurrencyTested within last 12 months
Zero Trust Architecture CoverageVerified across IT and OT environments
Risk Register CurrencyUpdated within last 6 months covering all domains
Quarterly KPI ReportingSubmitted to CSI within required timeframes
Annual Self-AssessmentCompleted and documented

Annex A - Certification Tiers

Choose the certification tier that matches your organisation's maturity level and requirements. All tiers provide comprehensive security validation.

CSI Bronze

CSI Bronze

Entry-level certification for emerging solutions.

Score: 60-69%.

Features:

  • Core CSI domain assessment (22 domains)
  • Pre-Certification track evaluation (10 core domains)
  • Digital CSI certification badge
  • Basic vendor directory listing
  • Annual reassessment eligibility
CSI Silver

CSI Silver

Intermediate certification for established solutions.

Score: 70-79%.

Features:

  • All Bronze tier features
  • Enhanced CSI domain evaluation
  • Standard certification track assessment
  • Featured directory listing
  • Quarterly compliance check-ins
  • CSI improvement roadmap
Most Popular

CSI Gold (Most Popular)

Advanced certification for comprehensive solutions.

Score: 80-89%.

Features:

  • All Silver tier features
  • Premium directory placement
  • Monthly compliance reviews
  • Dedicated CSI certification advisor
  • Advanced security validation
  • CSI framework leadership recognition
CSI Platinum

CSI Platinum

Elite certification for industry-leading solutions.

Score: 90-100%.

Features:

  • All Gold tier features
  • Elite CSI framework validation
  • Industry leadership recognition
  • White-glove certification support
  • CSI thought leadership opportunities
  • Premium partner program access

Annex B - Certification Investment

Transparent pricing based on assessment performance. All certifications are valid for 3 years. A non-refundable €1,500 Initial Application Fee is required for all tiers to begin the assessment.

CSI Bronze

Score 60-69%

€1,000 Certification Award Fee

Total: €2,500

Validity: For 3 years

CSI Silver

Score 70-79%

€2,500 Certification Award Fee

Total: €4,000

Validity: For 3 years

CSI Gold

Score 80-89%

€5,000 Certification Award Fee

Total: €6,500

Validity: For 3 years

CSI Platinum

Score 90-100%

€8,000 Certification Award Fee

Total: €9,500

Validity: For 3 years

Why Invest in CSI Trustmark?

+28%Increased Market Access
-35%Reduced Sales Cycle
67%Competitive Advantage
-22%Lower Implementation Costs

Certification Validity and Maintenance

  • Certification Period: 24 months with ongoing compliance monitoring.
  • Annual Self-Assessment: Required documentation of continued platform performance and integration effectiveness.
  • Quarterly Reporting: Submission of key performance indicators (KPIs).
  • Technology Updates: Notification required for material changes to integrated architecture within 30 days.

Application and Contact

To initiate the Trustmark process or request further information, please contact us.

Start Self-Assessment →

Email: info@convergedsecurity.es

Web: www.convergedsecurity.es