Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Security Frameworks

NIST Cybersecurity Framework (CSF) 2.0

Also known as: CSF 2.0, NIST CSF 2.0, Cybersecurity Framework 2.0, NIST Cybersecurity Framework version 2.0
Simply put

The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary set of guidance published by the U.S. National Institute of Standards and Technology to help organizations understand, assess, prioritize, and manage their cybersecurity risks. It is not a law and does not itself impose legal obligations; instead, it offers high-level guidance that industry, government agencies, and other organizations can adopt to structure their security efforts. Released in February 2024, version 2.0 organizes cybersecurity activities into a common structure that organizations can tailor to their own needs.

Formal definition

CSF 2.0 is a NIST-published cybersecurity guidance framework (issued via NIST Cybersecurity White Paper) intended to help organizations manage and reduce cybersecurity risk. It is structured around six core Functions—Govern, Identify, Protect, Detect, Respond, and Recover—which provide a high-level, outcome-based organization of cybersecurity activities. As guidance rather than a regulation or a certifiable standard, CSF 2.0 is voluntary and does not carry independent legal force unless incorporated by law, contract, or organizational policy; adoption and implementation depth are left to each organization based on its risk profile. NIST provides supplementary resources, including mapping concepts that relate CSF 2.0 outcomes to other references such as SP 800-53 controls. Practitioners should note that the framework is periodically revised and should verify against the current authoritative NIST publications; this entry does not address certification, as CSF 2.0 is a framework rather than a certification scheme.

Why it matters

Cybersecurity risk management is a persistent operational and governance challenge, yet organizations often lack a common vocabulary and structure for describing what they do, where they have gaps, and how their efforts compare against a recognized baseline. CSF 2.0 matters because it offers that shared, outcome-based structure without dictating specific technologies or prescribing a rigid compliance checklist. Because it is voluntary guidance rather than a regulation, it can be adopted flexibly across sectors and organization sizes, and it is frequently used as a reference point when organizations need to communicate their security posture to boards, business partners, or regulators.

A notable feature of version 2.0 is that its scope is explicitly framed for industry, government agencies, and other organizations generally, rather than being oriented toward a single sector. This broad framing, combined with the addition of the Govern function, reflects an emphasis on integrating cybersecurity into enterprise-level risk management and governance rather than treating it as a purely technical concern. For compliance and risk teams, this makes the framework useful as a organizing layer that can sit above more detailed control catalogs.

It is important to keep the framework's status clear: CSF 2.0 does not itself impose legal obligations and is not a certification scheme. It carries weight only where an organization adopts it by policy, where a contract references it, or where a law or regulator incorporates it. Its value depends heavily on how deeply and honestly an organization implements the underlying outcomes, and readers should verify specifics against the current authoritative NIST publications, since NIST periodically revises its guidance.

Who it's relevant to

Compliance and risk officers
CSF 2.0 gives compliance and risk teams a common structure for describing cybersecurity risk in enterprise terms, which is useful when reporting posture to boards or aligning security work with broader governance. It is not a regulation, so it does not create obligations on its own; teams should treat it as a voluntary organizing framework unless it is incorporated by policy, contract, or applicable law.
Information security practitioners
Security teams can use the six core Functions—Govern, Identify, Protect, Detect, Respond, and Recover—to structure and prioritize activities and to identify gaps in coverage. The supplementary mapping concepts that relate CSF 2.0 outcomes to references such as SP 800-53 controls can help practitioners connect high-level outcomes to more detailed control sets already in use.
Government agencies and public-sector organizations
CSF 2.0 is framed for use by government agencies as well as industry and other organizations. Agencies may adopt it to structure their cybersecurity efforts, though whether and how it applies in a given agency depends on that agency's own policies and any legal requirements incorporating NIST guidance, which vary and should be verified against authoritative sources.
Auditors and assessors
Because CSF 2.0 is a framework rather than a certification scheme, there is no formal certification to assess against. Assessors may nonetheless use the framework's outcome-based structure as a reference when evaluating an organization's cybersecurity posture, recognizing that implementation depth is discretionary and that any assessment approach is defined by the organization or the party requiring it, not by NIST.

Inside CSF 2.0

Core Functions
CSF 2.0 organizes cybersecurity outcomes into a set of high-level Functions. Version 2.0 introduced the Govern Function alongside the previously established Identify, Protect, Detect, Respond, and Recover Functions. These Functions are further broken down into Categories and Subcategories expressing desired outcomes rather than prescriptive controls.
Govern Function
A Function emphasized in the 2.0 revision that addresses organizational context, risk management strategy, roles and responsibilities, policy, and oversight of the cybersecurity program. It is intended to cut across and inform the other Functions rather than stand in isolation.
Profiles
A mechanism for aligning the Framework's outcomes with an organization's mission, requirements, risk appetite, and resources. Profiles are typically used to describe a Current state and a Target state, supporting gap analysis and prioritization. They are descriptive tools, not certification artifacts.
Tiers
A way to characterize the rigor and maturity of an organization's cybersecurity risk management practices. Tiers are intended to support internal communication about risk posture and are not a scoring or grading system that yields a formal rating or certification.
Voluntary, outcome-based structure
The CSF is a voluntary framework expressing cybersecurity outcomes at a technology-neutral level. It is designed to be adaptable across sectors and organization sizes and to be used alongside, or mapped to, other standards and control catalogs rather than replacing them.
Implementation resources
NIST provides supplementary materials intended to help organizations put the Framework into practice and to map its outcomes to other references. Practitioners should confirm the current set and versions of these resources against NIST's official publications.

Common questions

Answers to the questions practitioners most commonly ask about CSF 2.0.

Is compliance with the NIST Cybersecurity Framework 2.0 legally required?
Not by itself. The CSF is a voluntary framework developed by the U.S. National Institute of Standards and Technology, not a regulation, and it carries no independent legal force. It can, however, become effectively binding in specific contexts—for example, where a contract requires its use, where a regulator or sector authority references it, or where an organization adopts it as a benchmark for demonstrating reasonable security practices. Whether any such obligation applies to a given organization depends on its jurisdiction, sector, and contractual commitments, which should be verified against the applicable authoritative sources.
Can an organization become 'certified' against the NIST CSF 2.0?
There is no official certification issued for conformance with the CSF in the way certification bodies audit and certify against standards such as ISO/IEC 27001. The CSF is structured as a set of outcomes and functions intended to help organizations assess and improve their cybersecurity posture, not as a certifiable specification with an accredited attestation scheme. Organizations may perform self-assessments or engage third parties for readiness assessments, but such exercises are assessments rather than a formal certification, and readers should not treat any resulting statement as an equivalent to certification.
How does the CSF 2.0 relate to standards an organization may already use, such as ISO/IEC 27001?
The CSF is generally designed to be complementary rather than a replacement for detailed control standards. It organizes cybersecurity outcomes at a higher level and can be used to map to, and coordinate across, more prescriptive frameworks and standards an organization already maintains. In practice, many organizations use the CSF as an overarching structure and rely on other standards for specific control requirements. The precise mapping depends on the versions and scope in use, so cross-references should be confirmed against the current text of each source.
Where should an organization begin when implementing the CSF 2.0?
A common starting point is to establish the organizational context—understanding the systems, data, and risk environment in scope—before attempting to address the framework's functions in detail. Many organizations use the framework's profile concept to describe a current state and a target state, then prioritize gaps according to risk. Because implementation is fact-specific and depends on organizational size, sector, and risk tolerance, the appropriate scope and sequence require professional judgment rather than a single prescribed path.
How can the CSF 2.0 be used to communicate cybersecurity posture to leadership?
The framework is structured around high-level functions that are intended to support communication across technical and non-technical audiences, including executives and boards. Organizations often use profiles and the framework's tiers to describe current posture and priorities in terms that connect to broader risk management. It is generally used as a communication and organizing tool rather than a scoring system, and any summary presented to leadership should make clear that it reflects a self-directed assessment rather than an external validation.
How does an organization keep its CSF-based program current as the framework evolves?
The CSF is periodically revised, and supporting resources associated with it are updated over time, so a program aligned to one version may need review when a newer version is issued. Organizations generally treat alignment as an ongoing activity—revisiting profiles, reassessing gaps, and confirming that references to other standards remain accurate—rather than a one-time exercise. Readers should verify the current version and any related implementation resources against the official NIST publications, as versions and supplementary materials change.

Common misconceptions

The NIST CSF is a law or regulation that organizations are legally required to follow.
The CSF is a voluntary framework published by NIST, not binding law. It carries no legal force on its own. It may become effectively mandatory only where a contract, sector-specific regulation, or organizational policy incorporates it by reference, and such incorporation and its scope should be verified in the specific instrument that imposes it.
An organization can become 'CSF certified' the way it might certify against a standard such as ISO/IEC 27001.
The CSF is not a certification scheme and does not, by itself, produce a formal certificate. Its Tiers and Profiles are self-directed tools for describing and improving risk management posture, not a graded certification outcome. Any conformity or attestation claims tied to the CSF depend on separate, external arrangements.
CSF 2.0 is a fixed, final document that will not change.
NIST periodically revises the Framework and its supporting resources; 2.0 itself is a revision that introduced structural changes such as the Govern Function. Readers should treat the version they are using as point-in-time and verify against the latest authoritative NIST publication.

Best practices

Treat the CSF as a voluntary, outcome-based framework and confirm whether any contract, sector regulation, or internal policy makes its use obligatory in your specific context before relying on it as a compliance baseline.
Develop Current and Target Profiles tailored to your organization's mission, risk appetite, and resources, and use the gap between them to prioritize improvements rather than pursuing every Subcategory uniformly.
Give explicit attention to the Govern Function introduced in 2.0, ensuring roles, responsibilities, oversight, and risk management strategy are addressed alongside the operational Functions.
Map CSF outcomes to the control catalogs and standards you already use so the Framework complements, rather than duplicates or replaces, existing programs.
Use Tiers to communicate maturity internally and avoid presenting them externally as a formal rating or certification.
Verify the Framework version and supporting implementation resources against the current official NIST publications, since the CSF and its materials are periodically updated.
Promotional banner for the Pentest Readiness checklist download