Compliance · US
NIST CSF 2.0, released Feb 2024Voluntary framework

NIST CSF 2.0

Plain-English definition

The NIST Cybersecurity Framework 2.0 is a voluntary, sector-agnostic framework organized around six functions: Govern (new in 2.0), Identify, Protect, Detect, Respond, and Recover. It's not certifiable, but it's widely used as a common language for assessing and communicating cyber risk, including to boards and regulators who reference it even outside the US.

The addition of Govern in the 2.0 revision elevates cybersecurity governance and risk oversight to the same level as the original five operational functions.

Who needs it

Organizations that want a structured, defensible way to baseline and communicate their security posture, especially to a board, without committing to a formal certification process, and companies that need a common framework to align disparate security initiatives.

Key requirements

A current-profile assessment against the six functions and their subcategories, a target-profile defining desired maturity, and a gap-closure plan, typically supported by a maturity tier rating (Partial, Risk Informed, Repeatable, Adaptive).

Cyber/privacy implications

Governance and executive accountability for cyber risk now sit inside the framework itself via the Govern function, not as an afterthought bolted onto a technical control list.

Assessment methodology

Current-profile assessment across all six functions, target-profile definition based on business risk tolerance, tier rating, and a prioritized roadmap to close the gap.

Implementation phases

01
Baseline

Assess current state across Govern, Identify, Protect, Detect, Respond, Recover.

02
Target

Define the target profile and tier appropriate to your risk tolerance.

03
Close the gap

Prioritized roadmap execution with periodic re-assessment.

Evidence & documentation requirements

Current and target profile documentation, maturity tier justification, and a tracked roadmap showing progress against identified gaps, useful as board-reporting material as much as audit evidence.

Common mistakes

Treating NIST CSF as a checklist to complete once rather than a continuous profile to maintain; ignoring the Govern function and focusing only on the original five operational functions, which was a common gap even before 2.0 formalized it.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

Is NIST CSF 2.0 mandatory for us?
It's voluntary on its own, though some contracts, insurers, or sector regulators reference it as an expected baseline.
How does this relate to CMMC?
CMMC for DoD contractors is built substantially on NIST SP 800-171/800-172, a related but distinct NIST publication; we can map your CSF work toward CMMC readiness if that applies to you.
Can this replace ISO 27001 for customer due diligence?
Some customers accept a CSF profile as evidence of maturity, but ISO 27001 and SOC 2 remain the more commonly requested formal credentials; we'll help you figure out what your specific buyers actually need.

Request a Maturity Assessment

See your current profile across all six functions before you set a target.

Request a Maturity Assessment →