NIST CSF 2.0 is a free, voluntary framework from the US National Institute of Standards and Technology that organises cybersecurity into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It tells an organisation what good security outcomes look like, not how to achieve them, which is why companies of every size and country use it as a common language for risk, from the board down to the SOC.
NIST published version 2.0 in February 2024, replacing the 2018 version 1.1. The biggest change was adding Govern as a sixth function, and widening the stated audience from critical infrastructure to all organisations. The official document is NIST CSWP 29, and the NIST Cybersecurity Framework page collects the guides and tools around it.
If you’re heading towards governance, risk and compliance (GRC), security analysis or audit, you’ll meet this framework in your first month. Here’s how it works and how to use it.
The three parts of CSF 2.0
The framework has three components. Most beginners only learn the first, which is why interviews about it go badly.
- The CSF Core: the hierarchy of functions, categories and subcategories that describe security outcomes.
- CSF Organisational Profiles: a way to describe where an organisation is today (Current Profile) and where it wants to be (Target Profile).
- CSF Tiers: a way to describe how rigorous and integrated an organisation’s risk management practices are.
The six functions of NIST CSF 2.0
Think of the functions as the questions a security leader has to answer continuously, not as steps you finish once.
| Function | ID | The question it answers | Plain-English example |
|---|---|---|---|
| Govern | GV | Who decides, by what rules, and how do we know it’s working? | A board-approved security policy and named risk owners |
| Identify | ID | What do we have, and what are our risks? | An up-to-date asset inventory and risk register |
| Protect | PR | How do we prevent or limit harm? | MFA, patching, encryption, staff training |
| Detect | DE | How do we spot something going wrong? | Log monitoring and alerting in a SIEM |
| Respond | RS | What do we do when an incident happens? | An incident response plan that people have actually rehearsed |
| Recover | RC | How do we get back to normal? | Tested backups and a restoration plan |
NIST draws Govern at the centre of a wheel, with the other five around it. That’s deliberate: Govern informs how you do everything else.
Why Govern was added
In version 1.1, governance was a category tucked inside Identify. Version 2.0 promotes it to a function because most security failures have a governance root: nobody owned the risk, the policy didn’t exist, the supplier was never assessed, or the board never heard about the problem until it was in the news.
Govern has six categories:
- Organisational Context (GV.OC): understanding the mission, stakeholders, and legal and regulatory requirements.
- Risk Management Strategy (GV.RM): priorities, risk appetite and tolerance.
- Roles, Responsibilities and Authorities (GV.RR): who is accountable, with enough authority and resources.
- Policy (GV.PO): cybersecurity policy that is set, communicated and enforced.
- Oversight (GV.OV): reviewing results to adjust the strategy.
- Cybersecurity Supply Chain Risk Management (GV.SC): managing risk from suppliers and third parties.
The supply chain category deserves attention. Many organisations now run on outsourced platforms, payment providers and cloud services, and a supplier’s weakness becomes yours.
How the CSF Core is structured
Every outcome in the Core sits in a three-level hierarchy:
Function PR Protect
Category PR.AA Identity Management, Authentication, and Access Control
Subcategory PR.AA-01 (an outcome about managing identities and credentials
for authorised users, services and hardware)
CSF 2.0 has 22 categories across the six functions:
- Govern: GV.OC, GV.RM, GV.RR, GV.PO, GV.OV, GV.SC
- Identify: ID.AM (Asset Management), ID.RA (Risk Assessment), ID.IM (Improvement)
- Protect: PR.AA (Identity Management, Authentication and Access Control), PR.AT (Awareness and Training), PR.DS (Data Security), PR.PS (Platform Security), PR.IR (Technology Infrastructure Resilience)
- Detect: DE.CM (Continuous Monitoring), DE.AE (Adverse Event Analysis)
- Respond: RS.MA (Incident Management), RS.AN (Incident Analysis), RS.CO (Incident Response Reporting and Communication), RS.MI (Incident Mitigation)
- Recover: RC.RP (Incident Recovery Plan Execution), RC.CO (Incident Recovery Communication)
Underneath sit the subcategories, each a specific outcome. Learn to read the IDs fluently. In a GRC role you’ll write “PR.AA-05 partially met” in a spreadsheet far more often than you’ll write an essay about the framework.
Implementation Examples and Informative References
The subcategories say what to achieve. Two companion resources help with how:
- Implementation Examples give short, practical illustrations of actions that would meet a subcategory.
- Informative References map CSF outcomes to other standards and control catalogues, such as NIST SP 800-53 or ISO/IEC 27001 controls. NIST keeps these online through its informative references page rather than inside the PDF, so they can be updated without a new framework version.
This mapping is why the CSF works so well as a common language. A company that is ISO 27001-certified can show how its controls line up against CSF outcomes without starting over.
Profiles: current versus target
A Current Profile records which outcomes the organisation achieves today, and how well. A Target Profile records the outcomes it wants, prioritised by its mission, risks and obligations. The gap between them becomes the action plan.
NIST also supports Community Profiles, shared target profiles for a sector or use case, so that similar organisations don’t each build one from scratch. See the CSF profiles page for the published ones.
Tiers: how mature is the risk management?
The four Tiers describe the rigour of an organisation’s cybersecurity risk governance and management:
| Tier | Name | What it looks like |
|---|---|---|
| 1 | Partial | Ad hoc, reactive, little awareness of risk at organisational level |
| 2 | Risk Informed | Management approves risk practices, but they aren’t applied consistently organisation-wide |
| 3 | Repeatable | Formal, approved policies, applied consistently and updated as things change |
| 4 | Adaptive | Practices adapt based on lessons learned and predictive indicators; risk is part of the culture |
A common beginner mistake is treating Tiers as a maturity score that everyone should push to 4. NIST is clear that the right Tier depends on the organisation’s risk and resources. A ten-person charity at Tier 2 may be perfectly sensible.
Worked example: a CSF gap analysis for a fictional company
Here’s the kind of exercise a junior GRC analyst does in their first weeks. The company is fictional: Acme Fintech, a 60-person payments start-up running on a public cloud.
Step 1: Scope. Agree what’s in scope: the production cloud environment, the mobile app and the customer support team.
Step 2: Pick the subcategories that matter. You don’t assess all of them on day one. For a payments start-up, you’d start with identity, data security, monitoring, incident response and suppliers.
Step 3: Gather evidence and score the Current Profile. Interview owners, read the policies, look at the configurations. Record what you actually see, not what people say they do.
| Subcategory area | Current state (evidence) | Target | Gap | Priority |
|---|---|---|---|---|
| GV.RR: roles and accountability | No named owner for cyber risk; the CTO “handles it” | Named risk owner, reporting quarterly to the board | No accountability or reporting | High |
| GV.SC: supplier risk | No list of critical suppliers; no security review before onboarding | Critical supplier register with security due diligence | Unknown third-party exposure | High |
| PR.AA: identity and access | MFA on email; not on the cloud console admin accounts | Phishing-resistant MFA on all admin access | Admin accounts exposed to credential phishing | Critical |
| DE.CM: monitoring | Cloud logs are kept but nobody reviews them | Alerts on high-risk events, reviewed daily | Incidents would go unnoticed | High |
| RS.MA: incident management | No written plan | Documented plan, tested by a tabletop exercise twice a year | Confused response under pressure | Medium |
| RC.RP: recovery | Backups run nightly; restore never tested | Quarterly restore test with recorded results | Backups may not work when needed | Medium |
Step 4: Turn gaps into a plan. Each gap gets an owner, an action and a date. “Enable MFA on all cloud admin accounts — owner: platform lead — due in two weeks” is a plan. “Improve identity security” is not.
Step 5: Report. Summarise for leadership in one page: top risks, what’s being fixed, what needs a decision or budget. That’s GV.OV and GV.RR in action.
Notice what you didn’t need: a hacking lab, a certification or ten years of experience. You needed structure, curiosity and the discipline to record evidence. That’s why the CSF is a good way into a GRC analyst role.
NIST CSF vs ISO 27001 vs SOC 2
People mix these up constantly, so here’s the short version:
| NIST CSF 2.0 | ISO/IEC 27001 | SOC 2 | |
|---|---|---|---|
| What it is | Voluntary framework of outcomes | International standard for an information security management system | An attestation report by an independent CPA firm |
| Can you be “certified”? | No, there’s no official CSF certification | Yes, organisations can be certified by accredited bodies | No, you receive a report, not a certificate |
| Typical use | Common language, self-assessment, planning | Formal certification for customers and partners | Assurance for customers of service organisations |
For the deeper versions, read ISO 27001 explained for beginners and what SOC 2 is. The official sources are iso.org and the AICPA.
How to learn NIST CSF 2.0 this week
A practical plan for career starters:
- Read the document itself. CSWP 29 is short enough to read in an afternoon. Read the Core appendix slowly.
- Read a Quick Start Guide. NIST’s Quick Start Guides include versions for small businesses and for creating profiles.
- Browse the Core in NIST’s online tool. The CSF 2.0 reference tool lets you filter and export the Core, which is handy for building your own assessment spreadsheet.
- Do a mini gap analysis on something real you’re allowed to assess, such as your own home network, a family business with permission, or a club you belong to. Pick ten subcategories and fill in the table above.
- Put it in your portfolio. A two-page gap analysis with a sensible action plan is a stronger interview conversation than “I’ve read about NIST”.