NIST CSF 2.0
Universal core · NIST Cybersecurity Framework 2.0
NIST
International
1.0 released 2014; CSF 2.0 released February 2024
Voluntary framework; self-assessed, no certification scheme
Any organisation that needs a common language for cyber risk, from the board down
Curated, versioned & cross-mapped
The obligation, plainly.
The NIST Cybersecurity Framework organises a security programme into six functions: Govern, Identify, Protect, Detect, Respond and Recover. Version 2.0 promoted governance to a function of its own, which is exactly where regulated organisations feel the pressure.
CSF is voluntary, but it has become the lingua franca of cyber-risk reporting: supervisors reference it, boards understand it, and local regimes like the CBN's cybersecurity framework echo its shape.
Where programmes are tested.
Govern
Strategy, roles, policy and oversight: cyber risk treated as an enterprise risk with named accountability.
Identify and Protect
Know the assets and the threats to them; run the controls that reduce the exposure.
Detect, Respond, Recover
See incidents quickly, work them to closure, and prove you can restore service.
Curated once, evidenced continuously.
- CSF outcomes are curated and cross-walked to the control library, so the same controls that satisfy ISO 27001 report your CSF posture.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
NIST CSF 2.0, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
Is NIST CSF mandatory?
It is voluntary for most organisations, though contracts, insurers and supervisors increasingly reference it. Its real power is as a shared vocabulary: boards, regulators and security teams can all read a CSF posture without translation.
Can you get certified against NIST CSF?
No. There is no accredited certification scheme; organisations self-assess against the framework's outcomes and describe their posture with profiles and tiers. Assurance, when needed, comes from mapping CSF to certifiable standards like ISO 27001.
What changed in NIST CSF 2.0?
Version 2.0 added Govern as a sixth function, elevating strategy, roles and oversight to the same level as the operational functions, and broadened the framework's scope beyond critical infrastructure to organisations of any size and sector.
How does NIST CSF relate to ISO 27001?
CSF describes outcomes; ISO 27001 defines a certifiable management system. They cross-map cleanly, which is why a well-run programme implements controls once and reports them in both languages, CSF for the board and supervisor, 27001 for the certificate.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.