The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary guidance framework developed by the National Institute of Standards and Technology (NIST) to help organizations of all sizes and sectors manage, mitigate, and improve their cybersecurity risk posture. Released on February 26, 2024, the framework represents the first major revision since the original v1.0 in 2014 and v1.1 in 2018.
Building on decades of widespread adoption across public and private sectors, CSF 2.0 expands the original model by adding a sixth core function—Govern—and aligning more closely with international standards, supply chain risk management, and modern threat landscapes1.
Key Takeaway: CSF 2.0 is not a compliance checklist but a risk-based roadmap. It provides a flexible language for boards, executives, and technical teams to communicate cybersecurity priorities and measure progress.
Evolution from v1.1
The original framework established five foundational functions: Identify, Protect, Detect, Respond, and Recover. While highly effective, feedback from regulators, industry leaders, and policymakers highlighted gaps in executive oversight, third-party risk, and alignment with emerging standards.
| Aspect | CSF v1.1 (2018) | CSF 2.0 (2024) |
|---|---|---|
| Core Functions | 5 (Identify, Protect, Detect, Respond, Recover) | 6 (Govern added) |
| Scope | Primary focus on internal operations | Explicit third-party & supply chain risk |
| Governance | Implied within Identify | Dedicated top-level function |
| Standards Alignment | Partial mapping | Formal alignment with ISO/IEC 27001, ENISA, etc. |
| Implementation | Tiers 1–4 descriptive | Tiers refined with actionable maturity indicators |
These changes reflect a strategic shift from purely technical controls to enterprise-wide risk governance, acknowledging that cybersecurity is fundamentally a business and leadership responsibility2.
The Six Core Functions
CSF 2.0 organizes cybersecurity activities into six interconnected functions. Each contains categories and subcategories that define specific outcomes and best practices.
1. Govern (New)
Establishes organizational context, risk appetite, and oversight structures. Ensures cybersecurity strategy aligns with enterprise governance, compliance requirements, and resource allocation. Covers roles, policies, supply chain risk management strategy, and continuous improvement cycles.
2. Identify
Assets, environment, and risk assessment. Organizations catalog critical systems, data flows, and third-party dependencies to understand exposure and prioritize protections.
3. Protect
Safeguards and controls implementation. Includes access management, security training, data encryption, resilient architecture, and maintenance protocols to limit potential impact.
4. Detect
Anomalies and event identification. Relies on monitoring, logging, threat intelligence, and automated detection systems to rapidly recognize cybersecurity incidents.
5. Respond
Incident management and communication. Covers response planning, analysis, mitigation, and stakeholder notification to contain and manage the impact of events.
6. Recover
Restoration and lessons learned. Focuses on recovery planning, improvements based on post-incident analysis, and resilience building for future operations.
Implementation Tiers
CSF 2.0 retains the four-tier maturity model but refines definitions to provide clearer progression pathways. Tiers describe the degree to which an organization's cybersecurity risk management practices exhibit characteristics defined in the Framework:
- Partial (Tier 1): Risk management is ad-hoc, reactive, and lacks formalized processes.
- Risk-Informed (Tier 2): Leadership is aware of risks; processes exist but are not consistently communicated across the organization.
- Repeatable (Tier 3): Policies are formalized, consistently implemented, and updated based on lessons learned.
- Adaptive (Tier 4): Continuous improvement driven by predictive analytics, threat intelligence, and adaptive governance structures.
Organizations are encouraged to assess their current tier, set target goals, and roadmap investments accordingly. The framework explicitly states that higher tiers are not mandatory—appropriateness depends on industry, risk tolerance, and operational context3.
Alignment & Integration
A defining feature of CSF 2.0 is its formalized alignment with major international and sector-specific standards. The NIST Crosswalks now provide direct mapping to:
- ISO/IEC 27001:2022 (Information Security Management)
- ENISA Cybersecurity Framework
- NERC CIP (North American Electric Reliability Corporation)
- Executive Order 14028 (Improving the Nation’s Cybersecurity)
This interoperability reduces compliance overhead and enables organizations to satisfy multiple regulatory requirements through a single governance structure. Additionally, CSF 2.0 integrates software supply chain security principles aligned with the Software Bill of Materials (SBOM) and Build 11 initiatives.
Adoption & Impact
Since its inception, the NIST CSF has been referenced in federal regulations, state legislation, and international policy directives. Notable adoptions include:
- SEC Cybersecurity Disclosure Rules (2023): Public companies must disclose material cybersecurity risks and incidents, often citing CSF as the reporting baseline.
- Cybersecurity Information Sharing Act (CISA): Federal agencies are mandated to use the framework for risk management and information sharing.
- Private Sector: Over 70% of Fortune 500 companies report using CSF as their primary risk management reference4.
CSF 2.0’s emphasis on governance and supply chain risk positions it as a critical tool for navigating increasingly complex regulatory environments, including the EU’s Cyber Resilience Act (CRA) and NIS2 Directive.
References & Citations
- NIST. (2024). Cybersecurity Framework Version 2.0. National Institute of Standards and Technology. SP 800-218 Rev. 1. nist.gov/cyberframework
- Executive Order 14028. (2021). Improving the Nation’s Cybersecurity. The White House.
- NIST. (2018). Framework for Improving Critical Infrastructure Cybersecurity. Version 1.1. doi.org/10.6028/NIST.FIPS.180-4
- Cybersecurity Ventures. (2023). The State of Cybersecurity Framework Adoption. Industry Survey Report.
- ENISA. (2023). Cybersecurity Framework for Critical Infrastructure Entities. European Union Agency for Cybersecurity.