NIST CSF 2.0

Six functions, one shared vocabulary: how boards, regulators and security teams talk about cyber risk.

Universal core · NIST Cybersecurity Framework 2.0

Issued by

NIST

Region

International

Effective

1.0 released 2014; CSF 2.0 released February 2024

Oversight

Voluntary framework; self-assessed, no certification scheme

Applies when

Any organisation that needs a common language for cyber risk, from the board down

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

The NIST Cybersecurity Framework organises a security programme into six functions: Govern, Identify, Protect, Detect, Respond and Recover. Version 2.0 promoted governance to a function of its own, which is exactly where regulated organisations feel the pressure.

CSF is voluntary, but it has become the lingua franca of cyber-risk reporting: supervisors reference it, boards understand it, and local regimes like the CBN's cybersecurity framework echo its shape.

Where programmes are tested.

01

Govern

Strategy, roles, policy and oversight: cyber risk treated as an enterprise risk with named accountability.

02

Identify and Protect

Know the assets and the threats to them; run the controls that reduce the exposure.

03

Detect, Respond, Recover

See incidents quickly, work them to closure, and prove you can restore service.

Curated once, evidenced continuously.

  • CSF outcomes are curated and cross-walked to the control library, so the same controls that satisfy ISO 27001 report your CSF posture.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

NIST CSF 2.0, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Is NIST CSF mandatory?

It is voluntary for most organisations, though contracts, insurers and supervisors increasingly reference it. Its real power is as a shared vocabulary: boards, regulators and security teams can all read a CSF posture without translation.

Can you get certified against NIST CSF?

No. There is no accredited certification scheme; organisations self-assess against the framework's outcomes and describe their posture with profiles and tiers. Assurance, when needed, comes from mapping CSF to certifiable standards like ISO 27001.

What changed in NIST CSF 2.0?

Version 2.0 added Govern as a sixth function, elevating strategy, roles and oversight to the same level as the operational functions, and broadened the framework's scope beyond critical infrastructure to organisations of any size and sector.

How does NIST CSF relate to ISO 27001?

CSF describes outcomes; ISO 27001 defines a certifiable management system. They cross-map cleanly, which is why a well-run programme implements controls once and reports them in both languages, CSF for the board and supervisor, 27001 for the certificate.

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.