Skip to content
GRC, ISO 27001 and SOC 2

NIST Cybersecurity Framework 2.0 explained for career starters

NIST CSF 2.0 explained for beginners: the six functions including Govern, how categories, profiles and tiers work, and a worked gap analysis you can copy.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 8 min read

NIST CSF 2.0 is a free, voluntary framework from the US National Institute of Standards and Technology that organises cybersecurity into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It tells an organisation what good security outcomes look like, not how to achieve them, which is why companies of every size and country use it as a common language for risk, from the board down to the SOC.

NIST published version 2.0 in February 2024, replacing the 2018 version 1.1. The biggest change was adding Govern as a sixth function, and widening the stated audience from critical infrastructure to all organisations. The official document is NIST CSWP 29, and the NIST Cybersecurity Framework page collects the guides and tools around it.

If you’re heading towards governance, risk and compliance (GRC), security analysis or audit, you’ll meet this framework in your first month. Here’s how it works and how to use it.

The three parts of CSF 2.0

The framework has three components. Most beginners only learn the first, which is why interviews about it go badly.

  1. The CSF Core: the hierarchy of functions, categories and subcategories that describe security outcomes.
  2. CSF Organisational Profiles: a way to describe where an organisation is today (Current Profile) and where it wants to be (Target Profile).
  3. CSF Tiers: a way to describe how rigorous and integrated an organisation’s risk management practices are.

The six functions of NIST CSF 2.0

Think of the functions as the questions a security leader has to answer continuously, not as steps you finish once.

Function ID The question it answers Plain-English example
Govern GV Who decides, by what rules, and how do we know it’s working? A board-approved security policy and named risk owners
Identify ID What do we have, and what are our risks? An up-to-date asset inventory and risk register
Protect PR How do we prevent or limit harm? MFA, patching, encryption, staff training
Detect DE How do we spot something going wrong? Log monitoring and alerting in a SIEM
Respond RS What do we do when an incident happens? An incident response plan that people have actually rehearsed
Recover RC How do we get back to normal? Tested backups and a restoration plan

NIST draws Govern at the centre of a wheel, with the other five around it. That’s deliberate: Govern informs how you do everything else.

Why Govern was added

In version 1.1, governance was a category tucked inside Identify. Version 2.0 promotes it to a function because most security failures have a governance root: nobody owned the risk, the policy didn’t exist, the supplier was never assessed, or the board never heard about the problem until it was in the news.

Govern has six categories:

  • Organisational Context (GV.OC): understanding the mission, stakeholders, and legal and regulatory requirements.
  • Risk Management Strategy (GV.RM): priorities, risk appetite and tolerance.
  • Roles, Responsibilities and Authorities (GV.RR): who is accountable, with enough authority and resources.
  • Policy (GV.PO): cybersecurity policy that is set, communicated and enforced.
  • Oversight (GV.OV): reviewing results to adjust the strategy.
  • Cybersecurity Supply Chain Risk Management (GV.SC): managing risk from suppliers and third parties.

The supply chain category deserves attention. Many organisations now run on outsourced platforms, payment providers and cloud services, and a supplier’s weakness becomes yours.

How the CSF Core is structured

Every outcome in the Core sits in a three-level hierarchy:

Function     PR       Protect
Category     PR.AA    Identity Management, Authentication, and Access Control
Subcategory  PR.AA-01 (an outcome about managing identities and credentials
                       for authorised users, services and hardware)

CSF 2.0 has 22 categories across the six functions:

  • Govern: GV.OC, GV.RM, GV.RR, GV.PO, GV.OV, GV.SC
  • Identify: ID.AM (Asset Management), ID.RA (Risk Assessment), ID.IM (Improvement)
  • Protect: PR.AA (Identity Management, Authentication and Access Control), PR.AT (Awareness and Training), PR.DS (Data Security), PR.PS (Platform Security), PR.IR (Technology Infrastructure Resilience)
  • Detect: DE.CM (Continuous Monitoring), DE.AE (Adverse Event Analysis)
  • Respond: RS.MA (Incident Management), RS.AN (Incident Analysis), RS.CO (Incident Response Reporting and Communication), RS.MI (Incident Mitigation)
  • Recover: RC.RP (Incident Recovery Plan Execution), RC.CO (Incident Recovery Communication)

Underneath sit the subcategories, each a specific outcome. Learn to read the IDs fluently. In a GRC role you’ll write “PR.AA-05 partially met” in a spreadsheet far more often than you’ll write an essay about the framework.

Implementation Examples and Informative References

The subcategories say what to achieve. Two companion resources help with how:

  • Implementation Examples give short, practical illustrations of actions that would meet a subcategory.
  • Informative References map CSF outcomes to other standards and control catalogues, such as NIST SP 800-53 or ISO/IEC 27001 controls. NIST keeps these online through its informative references page rather than inside the PDF, so they can be updated without a new framework version.

This mapping is why the CSF works so well as a common language. A company that is ISO 27001-certified can show how its controls line up against CSF outcomes without starting over.

Profiles: current versus target

A Current Profile records which outcomes the organisation achieves today, and how well. A Target Profile records the outcomes it wants, prioritised by its mission, risks and obligations. The gap between them becomes the action plan.

NIST also supports Community Profiles, shared target profiles for a sector or use case, so that similar organisations don’t each build one from scratch. See the CSF profiles page for the published ones.

Tiers: how mature is the risk management?

The four Tiers describe the rigour of an organisation’s cybersecurity risk governance and management:

Tier Name What it looks like
1 Partial Ad hoc, reactive, little awareness of risk at organisational level
2 Risk Informed Management approves risk practices, but they aren’t applied consistently organisation-wide
3 Repeatable Formal, approved policies, applied consistently and updated as things change
4 Adaptive Practices adapt based on lessons learned and predictive indicators; risk is part of the culture

A common beginner mistake is treating Tiers as a maturity score that everyone should push to 4. NIST is clear that the right Tier depends on the organisation’s risk and resources. A ten-person charity at Tier 2 may be perfectly sensible.

Worked example: a CSF gap analysis for a fictional company

Here’s the kind of exercise a junior GRC analyst does in their first weeks. The company is fictional: Acme Fintech, a 60-person payments start-up running on a public cloud.

Step 1: Scope. Agree what’s in scope: the production cloud environment, the mobile app and the customer support team.

Step 2: Pick the subcategories that matter. You don’t assess all of them on day one. For a payments start-up, you’d start with identity, data security, monitoring, incident response and suppliers.

Step 3: Gather evidence and score the Current Profile. Interview owners, read the policies, look at the configurations. Record what you actually see, not what people say they do.

Subcategory area Current state (evidence) Target Gap Priority
GV.RR: roles and accountability No named owner for cyber risk; the CTO “handles it” Named risk owner, reporting quarterly to the board No accountability or reporting High
GV.SC: supplier risk No list of critical suppliers; no security review before onboarding Critical supplier register with security due diligence Unknown third-party exposure High
PR.AA: identity and access MFA on email; not on the cloud console admin accounts Phishing-resistant MFA on all admin access Admin accounts exposed to credential phishing Critical
DE.CM: monitoring Cloud logs are kept but nobody reviews them Alerts on high-risk events, reviewed daily Incidents would go unnoticed High
RS.MA: incident management No written plan Documented plan, tested by a tabletop exercise twice a year Confused response under pressure Medium
RC.RP: recovery Backups run nightly; restore never tested Quarterly restore test with recorded results Backups may not work when needed Medium

Step 4: Turn gaps into a plan. Each gap gets an owner, an action and a date. “Enable MFA on all cloud admin accounts — owner: platform lead — due in two weeks” is a plan. “Improve identity security” is not.

Step 5: Report. Summarise for leadership in one page: top risks, what’s being fixed, what needs a decision or budget. That’s GV.OV and GV.RR in action.

Notice what you didn’t need: a hacking lab, a certification or ten years of experience. You needed structure, curiosity and the discipline to record evidence. That’s why the CSF is a good way into a GRC analyst role.

NIST CSF vs ISO 27001 vs SOC 2

People mix these up constantly, so here’s the short version:

NIST CSF 2.0 ISO/IEC 27001 SOC 2
What it is Voluntary framework of outcomes International standard for an information security management system An attestation report by an independent CPA firm
Can you be “certified”? No, there’s no official CSF certification Yes, organisations can be certified by accredited bodies No, you receive a report, not a certificate
Typical use Common language, self-assessment, planning Formal certification for customers and partners Assurance for customers of service organisations

For the deeper versions, read ISO 27001 explained for beginners and what SOC 2 is. The official sources are iso.org and the AICPA.

How to learn NIST CSF 2.0 this week

A practical plan for career starters:

  1. Read the document itself. CSWP 29 is short enough to read in an afternoon. Read the Core appendix slowly.
  2. Read a Quick Start Guide. NIST’s Quick Start Guides include versions for small businesses and for creating profiles.
  3. Browse the Core in NIST’s online tool. The CSF 2.0 reference tool lets you filter and export the Core, which is handy for building your own assessment spreadsheet.
  4. Do a mini gap analysis on something real you’re allowed to assess, such as your own home network, a family business with permission, or a club you belong to. Pick ten subcategories and fill in the table above.
  5. Put it in your portfolio. A two-page gap analysis with a sensible action plan is a stronger interview conversation than “I’ve read about NIST”.

Questions

Is NIST CSF 2.0 mandatory?

For most private organisations it's voluntary. Some regulators, contracts or customers may expect it or reference it, but the framework itself is not a law. Outside the US it's used widely as a reference framework.

Can I get a NIST CSF certification?

NIST does not certify individuals or organisations against the CSF. Some training providers sell CSF courses with their own certificates, which are not the same as a certification from a certifying body.

What's the difference between CSF 1.1 and 2.0?

Version 2.0 adds the Govern function, broadens the audience to all organisations, gives supply chain risk more emphasis, and adds resources such as Implementation Examples, Quick Start Guides and online Informative References.

Do SOC analysts need to know the CSF?

Yes, at least the Detect, Respond and Recover functions. Knowing where your daily work fits in the framework makes your reports and escalations far easier for managers to act on.