Identity & Access Management capability of SimpliKeys (SK), mapped to the IAM-relevant CSF 2.0 outcomes
Reference version: NIST CSF 2.0 (Feb 2024) · Prepared mid-2026 · Capability mapping, not a compliance attestation
Coverage of the 11 IAM-relevant outcomes
NIST CSF 2.0 (published 26 February 2024) is the current version — NIST marked its two-year anniversary in February 2026. It organises 106 outcomes (subcategories) across six functions (Govern, Identify, Protect, Detect, Respond, Recover) and 22 categories. There is no newer edition.
The IAM-relevant CSF outcomes — the PR.AA category (identity management, authentication and access control) plus the access-related logging, monitoring and incident-containment outcomes. This is NOT a full CSF mapping: the Govern, Identify and Recover functions and the many non-IAM outcomes are out of scope here. Organisations select and prioritise outcomes through their own CSF Profile.
SimpliKeys is a single unified platform: the capabilities described below are facets of one system applied to each control, not separate products. It protects every identity with the same vaulting, brokering and session recording, and applies strong authentication from a configurable spectrum of factors that can be targeted per system, chained, and stepped up within a session.
Every rating below holds only to the extent of two things: (1) breadth — the scope of the environment SimpliKeys is protecting; a control is supported only where SimpliKeys sits in the access path, not for systems outside its reach; and (2) depth — how SimpliKeys is configured. The analysis assumes SimpliKeys is deployed and configured as the central authentication manager for the in-scope environment.
Entries describe summarised SimpliKeys capability under common circumstances and when appropriately configured. They do not represent verified or certified behaviour.
NIST CSF 2.0 is a voluntary, outcome-based framework — there is no certification against it. SimpliKeys can help achieve specific outcomes when appropriately configured, but no tool makes an organisation 'CSF compliant'; an organisation measures itself against its own current and target CSF Profile. Treat every 'Supports' as 'capability provided when appropriately configured.'
Supports
SimpliKeys provides the capability that meets this control when appropriately configured; configuration to the applicable thresholds and implementation still apply.
Partial
SimpliKeys addresses part of this control; full compliance needs additional measures, or depends on coverage or architecture beyond SimpliKeys alone.
Assists
SimpliKeys does not perform this control (it is organisational or process), but supplies information, logs, visibility, or evidence that makes it easier to complete or to demonstrate.
Out of scope / N/A
Outside SimpliKeys’ role — purely organisational, or not applicable to SimpliKeys (e.g., applies only to third-party service providers).
Filter by coverage
Identities and credentials for authorized users, services, and hardware are managed.
What SimpliKeys does
Governs the full identity lifecycle and credentials for every identity — person, non-human identity, or AI agent — with unique identification.
Customer responsibility & notes
Customer connects the identity sources; SimpliKeys issues and manages unique identities and their credentials, including non-human and AI-agent identities.
Identities are proofed and bound to credentials based on the context of the interaction.
What SimpliKeys does
Binds credentials to proofed identities and applies context to the interaction, ingesting proofing results via API.
Customer responsibility & notes
SimpliKeys binds credentials to proofed identities and applies context. The proofing / identity verification itself is performed by an integrated identity-verification service or the authoritative source (e.g., HR), whose result SimpliKeys ingests via API.
Users, services, and hardware are authenticated.
What SimpliKeys does
Authenticates every identity — person, non-human identity, or AI agent — with strong authentication from a configurable spectrum of factors.
Customer responsibility & notes
Customer selects the factors and per-system policy; SimpliKeys authenticates human and non-human identities alike.
Identity assertions are protected, conveyed, and verified.
What SimpliKeys does
Is the single sign-on and federation layer (SAML, OIDC, WS-Fed) that issues, conveys and verifies identity assertions.
Customer responsibility & notes
Customer configures assertion signing/encryption and the federation trust to its standard.
Access permissions, entitlements, and authorizations are defined in policy, managed, enforced, and reviewed — incorporating least privilege and separation of duties.
What SimpliKeys does
Defines, enforces and reviews access by policy with least privilege, and runs periodic access-review campaigns; enforces segregation of duties at the access-to-application layer.
Customer responsibility & notes
SimpliKeys covers permissions, least privilege and periodic review. Separation of duties is enforced at the access-to-application layer; SoD within an application is the application's function unless SimpliKeys is fed application data and configured for it.
Physical access to assets is managed, monitored, and enforced commensurate with risk.
What SimpliKeys does
n/a — SimpliKeys manages logical access only.
Customer responsibility & notes
Physical access control is a separate control set outside SimpliKeys.
Log records are generated and made available for continuous monitoring.
What SimpliKeys does
Records identity and access activity — every action on the network by any identity — with session recording and device, location and keystroke detail, and forwards it to SIEM.
Customer responsibility & notes
SimpliKeys generates the identity/access logs and forwards them; platform-wide log generation, protection and retention across the environment remain the customer's.
Personnel activity and technology usage are monitored to find potentially adverse events.
What SimpliKeys does
Monitors all actions taken by any identity on the network — person, non-human identity or AI agent — with behavioural analytics, and can shut down a compromised session immediately.
Customer responsibility & notes
Strong fit for insider-threat and anomalous-access monitoring across in-scope systems.
External service-provider activities and services are monitored to find potentially adverse events.
What SimpliKeys does
Monitors and records third-party and contractor sessions through brokered, recorded access.
Customer responsibility & notes
SimpliKeys monitors the third party's access and sessions; monitoring a provider's broader services and operations is outside SimpliKeys.
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events.
What SimpliKeys does
Monitors identity and access activity on the systems it fronts.
Customer responsibility & notes
SimpliKeys monitors identity-related activity, not full host, runtime or endpoint telemetry; pair with EDR / host monitoring for full coverage.
Incidents are contained.
What SimpliKeys does
Contains at the identity layer: immediately shuts down a compromised session and can revoke access or disable an account.
Customer responsibility & notes
SimpliKeys provides fast identity-layer containment; full incident containment across network and host is broader and uses other tooling.
Mapping reflects NIST CSF 2.0 (Feb 2024) as understood in mid-2026, reviewed outcome-by-outcome with SimpliKeys. Outcome text is paraphrased; the official text is public-domain at nist.gov/cyberframework. 'Supports' = capability provided when appropriately configured; the customer configures and operates its deployment and selects outcomes via its CSF Profile. CSF is voluntary and has no certification.
30 minutes against a real environment — we’ll walk your controls line by line.
Book demo