Months 1-2 - Risk Assessment
Conduct comprehensive risk assessment across all domains - cyber, physical, and operational technology. Map threat interdependencies and potential cascade effects.
Organisational Certification
For Organisational Converged Security Readiness
The CSI Trustmark certifies that an organisation has implemented a standards-aligned, enterprise-wide converged security posture in full compliance with ST-CSF.001 Converged Security Framework requirements, using CSI Product-Oriented Endorsed solutions, and demonstrating strategic maturity across the 12 mandatory implementation domains defined in the standard. It affirms comprehensive alignment with ST-CSF.001 Converged Security Framework (September 2025) and all supporting technical standards including ST-CSF.TIA.001 Technology Integration and Architecture, ST-CSF.IRBC.001 Incident Response and Business Continuity Framework, ST-CSF.TRA.001 Training and Awareness, and CSI Product-Oriented Endorsement and Readiness Framework within a unified strategic framework that addresses hybrid risks, systemic risks, and cascading risks through validated, market-ready converged security solutions and organisational resilience capabilities.
The CSI Trustmark aligns with the CSF Strategic Standards for Unified Risk Management and Organisational Resilience, which establishes that contemporary organisations face hybrid, systemic, and cascading risks that render traditional siloed security approaches inadequate. The Trustmark provides external validation that an organisation has successfully implemented the converged approach defined in the framework - integrating cybersecurity, physical security, and operational technology under unified governance, supported by SIEM/PSIM platforms, Zero Trust Architecture, and AI/ML-enabled threat intelligence.
This Trustmark reflects the comprehensive integration of Converged Security Framework Strategic Standards with CSI Product-Oriented Endorsed solutions validated across 22 capability domains and 5 evaluation dimensions. Key alignments include:
Organisations are assessed for full ST-CSF.001 compliance across all 12 mandatory implementation domains through a multi-phase evaluation process.
The CSI Trustmark directly addresses the three risk categories defined in the CSF Strategic Standards:
Organisations achieving the CSI Trustmark demonstrate the ability to identify threat interdependencies, assess cascade effects, and maintain resilience across all three risk categories.
Trustmark certification follows the structured implementation timeline defined in the CSF Strategic Standards, ensuring organisations achieve full framework compliance systematically:
Conduct comprehensive risk assessment across all domains - cyber, physical, and operational technology. Map threat interdependencies and potential cascade effects.
Establish unified governance with executive sponsorship, appoint Chief Converged Security Officer (CCSO), and define cross-domain KPIs.
Deploy integrated SIEM/PSIM platforms achieving minimum 75% integration coverage. Implement Zero Trust Architecture across IT and OT. Activate AI/ML threat analytics.
Develop unified incident response protocols. Implement cross-functional security training achieving minimum 95% personnel completion. Conduct multi-domain tabletop exercises.
Implement continuous monitoring with real-time dashboards. Establish quarterly KPI reporting and annual self-assessment mechanisms. Submit for CSI Trustmark evaluation.
The CSI Trustmark validates compliance across the integrated standards framework:
Provides overarching risk management principles and guidance for risk governance. Required for unified risk register and risk assessment methodology.
Addresses information security management systems (ISMS) and cybersecurity controls. Required for data protection, access management, and incident response.
Ensures business continuity resilience through BCM systems. Required for RTO/RPO definitions and crisis response planning.
European directive on network and information security. Required for critical infrastructure operators and digital service providers in the EU.
EU regulation on digital operational resilience for financial entities. Required for financial sector organisations.
EU General Data Protection Regulation. Required for all organisations handling personal data of EU residents.
Trustmark-certified organisations demonstrate alignment across all applicable standards, eliminating fragmented compliance approaches and reducing regulatory burden.
The CSI Trustmark framework does not replace ISO 27001 or NIST CSF 2.0. Instead, it provides a converged-security readiness layer that aligns with these and other global standards, translating international governance, risk, protection, detection, response, recovery, and improvement expectations into a practical, evidence-based assessment model that extends across cybersecurity, physical security, operational technology, business continuity, privacy, and executive leadership.
CSI Trustmark supports ISO 27001 leadership, risk, access, incident, continuity, awareness, compliance, and improvement requirements. CSI extends the ISMS model into physical security, OT, and converged governance.
All six NIST CSF 2.0 functions are addressed by CSI Trustmark domains. Governance, risk identification, technical protection, monitoring, incident response, and continual improvement are each assessed across cyber, physical, and OT domains.
CSI Trustmark integrates NIS2 board-level oversight, DORA ICT risk management, and GDPR privacy-by-design requirements directly into its assessment criteria, providing structured readiness evidence for EU regulatory compliance.
| CSI Trustmark Domain | ISO 27001:2022 | NIST CSF 2.0 | EU Regulations |
|---|---|---|---|
| Domain 1 - Governance and Leadership | Clauses 4, 5, 6, 9 | Govern | NIS2 (board oversight) |
| Domain 2 - Risk Management | Clauses 6.1.2, 6.1.3 + Annex A | Govern, Identify | NIS2, DORA |
| Domain 3 - Technology Integration | Annex A technology controls | Protect, Detect | NIS2, DORA |
| Domain 4 - Identity and Access Management | Annex A access controls | Protect | GDPR, NIS2 |
| Domain 5 - Incident Response and Business Continuity | Annex A incident + continuity | Respond, Recover | NIS2 (24-hr), DORA, GDPR (72-hr) |
| Domain 6 - Training and Awareness | Annex A awareness + training | Govern, Protect | NIS2 |
| Domain 7 - Data Protection and Privacy | Annex A information protection | Govern, Protect, Identify | GDPR |
| Domain 8 - Compliance and Regulatory Alignment | Clauses 4, 6, 9, 10 + Annex A compliance | Govern | NIS2, DORA, GDPR |
| Domain 9 - CCSO Policy and Leadership | Clause 5 - Leadership | Govern | NIS2 (board accountability) |
| Domain 10 - Continuous Improvement | Clause 10 - Improvement | Govern, Identify, Respond, Recover | All EU directives |
CSI Trustmark provides structured readiness evidence that supports formal compliance, audit preparation, and maturity benchmarking against ISO/IEC 27001:2022 and NIST CSF 2.0. It does not replace independent certification or regulatory assessment. Organisations that complete the CSI Trustmark Self-Assessment gain a documented evidence base that can materially accelerate their ISO 27001 audit preparation and NIST CSF maturity evaluation - while also demonstrating converged security readiness that goes beyond the scope of traditional information-security-only frameworks.
CSI Trustmark assessment measures organisational performance across quantifiable indicators drawn from the CSF Strategic Standards:
| KPI | Minimum Threshold |
|---|---|
| SIEM/PSIM Platform Integration Coverage | 75% minimum across all security domains |
| Cross-Domain Security Training Completion | 95% of all personnel |
| Incident Detection Time (Mean Time to Detect) | Continuously monitored and benchmarked |
| Cross-Domain Incident Response Activation | Unified protocols covering cyber, physical, and OT |
| Business Continuity Plan Currency | Tested within last 12 months |
| Zero Trust Architecture Coverage | Verified across IT and OT environments |
| Risk Register Currency | Updated within last 6 months covering all domains |
| Quarterly KPI Reporting | Submitted to CSI within required timeframes |
| Annual Self-Assessment | Completed and documented |
Choose the certification tier that matches your organisation's maturity level and requirements. All tiers provide comprehensive security validation.
Entry-level certification for emerging solutions.
Score: 60-69%.
Features:
Intermediate certification for established solutions.
Score: 70-79%.
Features:
Advanced certification for comprehensive solutions.
Score: 80-89%.
Features:
Elite certification for industry-leading solutions.
Score: 90-100%.
Features:
Transparent pricing based on assessment performance. All certifications are valid for 3 years. A non-refundable €1,500 Initial Application Fee is required for all tiers to begin the assessment.
Score 60-69%
€1,000 Certification Award Fee
Total: €2,500
Validity: For 3 years
Score 70-79%
€2,500 Certification Award Fee
Total: €4,000
Validity: For 3 years
Score 80-89%
€5,000 Certification Award Fee
Total: €6,500
Validity: For 3 years
Score 90-100%
€8,000 Certification Award Fee
Total: €9,500
Validity: For 3 years
To initiate the Trustmark process or request further information, please contact us.
Email: info@convergedsecurity.es