← Glossary

Frameworks & Standards

NIST Cybersecurity Framework (CSF 2.0)

Also: NIST Cybersecurity Framework · CSF 2.0 · Cybersecurity Framework · NIST CSF 2.0

Last reviewed:

In one sentence

The NIST Cybersecurity Framework is a voluntary, outcome-based structure that organises a security programme into six Functions — Govern, Identify, Protect, Detect, Respond and Recover — so you can describe where you are, where you want to be, and the gap between.

Why it matters

CSF is the lingua franca between the security team and everyone who funds it. It is not a checklist of controls and it certifies nothing — it is a common set of outcomes ("recovery activities are communicated to stakeholders") that lets a board, an auditor and an engineer talk about the same programme without drowning in control IDs.

Its real value is comparison over time and across frameworks. Because CSF is outcome-based rather than prescriptive, you can map ISO 27001 Annex A controls, NIS2 measures and DORA requirements onto the same six Functions and see coverage in one picture — then track whether this year's investment actually moved the needle.

Functions, Profiles and Tiers

CSF 2.0 (released 2024) has three moving parts:

  • The Core — six Functions. GV Govern (new in 2.0, and now the centre: risk strategy, roles, policy, oversight), ID Identify, PR Protect, DE Detect, RS Respond, RC Recover. Each Function breaks into Categories and Subcategories — the concrete outcome statements.
  • Profiles. A Profile is your set of chosen outcomes. A Current Profile says where you are; a Target Profile says where you want to be; the difference is your prioritised gap list. This is the day-to-day artefact.
  • Tiers (1–4). Partial → Risk Informed → Repeatable → Adaptive. Tiers describe how rigorous and integrated your risk-management practice is — they are a maturity lens on the whole programme, deliberately not a grade for individual controls.

The big change in 2.0 is Govern and a widened scope: CSF is now pitched at organisations of every size and sector, not just US critical infrastructure.

Try it yourself hands-on

Build a Current Profile, find your gaps, and put a maturity Tier around it.

  1. Open the NIST CSF 2.0 Profile Builder. Score each Subcategory on the 0–4 scale (0 = Not performed, 4 = Optimizing). Be honest: rate GV and RC, not just the PR outcomes you enjoy talking about — Govern and Recover are where most programmes are quietly weakest.
  2. Read the Gap analysis by Function. If DE Detect averages 1.2 while PR Protect sits at 3.5, you have a monitoring blind spot: you are buying locks but not looking at the door. Export the profile to hand to leadership.
  3. Now step up a level: run the NIST CSF 2.0 Tier Assessment to place the programme at Tier 1–4. A pile of Tier-4 outcomes with an ad-hoc, Tier-1 governance process is a real and common mismatch — the assessment surfaces it.
  4. Finally, tie CSF back to whatever framework you are audited against with the Control Mapper — e.g. show which ISO 27001 Annex A controls satisfy your PR Target outcomes, so one piece of evidence answers two auditors.

Result: a Current-vs-Target Profile, a prioritised gap list by Function, and a defensible maturity Tier — the three things a CSF programme review actually asks for.

Common misreadings

  • A Tier is not a grade to maximise. Not every org should be Tier 4 — the target Tier follows your risk appetite and resources. Chasing Tier 4 everywhere is how budgets get burned on the wrong outcomes.
  • CSF is outcomes, not controls. "Detect anomalies" is the outcome; your SIEM rules are the implementation. Don't mistake owning a tool for achieving the outcome.
  • Govern is not optional paperwork. In 2.0 it is the Function that steers the other five; skipping it leaves you with capable controls and no direction.