FrameworkUnited StatesGlobal

NIST Cybersecurity Framework

NIST · Version 2.0 · February 26, 2024

NIST's voluntary, risk-based framework for managing cybersecurity risk across any organization.

Overview

The NIST Cybersecurity Framework 2.0 was published on February 26, 2024. It is a voluntary framework that provides guidance for organizations to manage and reduce cybersecurity risk through a common language. Version 2.0 added a sixth Function, GOVERN, to address organizational context, risk management strategy, supply chain risk, and defined roles and responsibilities. These topics existed informally in CSF 1.1 but are now explicitly required at the function level. The framework organizes cybersecurity activities into Functions, Categories, and Subcategories, with 22 categories and 106 subcategories across the six functions.

Organizations use the framework through Profiles and Tiers. A Profile describes the current or target cybersecurity outcomes relevant to the organization's mission and risk tolerance. Tiers describe the degree to which cybersecurity risk management is integrated into organizational decision-making, ranging from Tier 1 (Partial) to Tier 4 (Adaptive). The framework is not a checklist and does not define compliance. It maps to other standards including ISO 27001, NIST 800-53, and CIS Controls, making it useful as a common reporting language across organizations that use different underlying standards.

Who Needs This

US critical infrastructure organizations in sectors including energy, water, finance, and healthcare

Federal agencies and contractors required to demonstrate cybersecurity program maturity

Organizations seeking a risk-based maturity model that does not require external certification

Companies using CSF as a board-level reporting structure for cybersecurity risk

Organizations aligning disparate security programs under a single common language

Structure at a Glance

GVGOVERN6 controls

New in v2.0. Covers organizational context, cybersecurity risk management strategy, supply chain risk management, roles and responsibilities, policies and procedures, and oversight.

IDIDENTIFY4 controls

Asset management, risk assessment, improvement activities, and understanding the organizational environment to manage cybersecurity risk.

PRPROTECT5 controls

Identity management and access control, awareness and training, data security, platform security, and technology infrastructure resilience.

DEDETECT3 controls

Continuous monitoring of assets and infrastructure, and analysis of adverse events to characterize them accurately.

RSRESPOND4 controls

Incident management, incident analysis, incident response reporting and communication, and mitigation activities.

RCRECOVER3 controls

Execution of recovery plans after cybersecurity incidents, communications during recovery, and incorporation of lessons learned.

AI Prompt Recipes

Copy these prompts directly into Claude or any capable model. Replace the bracketed placeholders with your organization-specific details.

Current Profile Development

Use this at the start of a CSF 2.0 assessment to document current cybersecurity outcomes.

You are a cybersecurity risk advisor using NIST CSF 2.0. I need to develop a Current Profile for my organization: [TYPE OF ORGANIZATION], [SIZE], [SECTOR]. Based on the following description of our current security program: [DESCRIBE PROGRAM]. For each of the six CSF 2.0 Functions — GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER — provide: a maturity assessment of our current state, the three most significant subcategory gaps in each function, and a prioritized Target Profile recommendation for the next 12 months.

GOVERN Function Gap Analysis

Use this specifically for the new GOVERN function, which is unfamiliar to most practitioners.

The NIST CSF 2.0 GOVERN function is new in v2.0 and requires explicit organizational governance over cybersecurity. Analyze my organization's governance posture: [DESCRIBE CURRENT GOVERNANCE PROGRAM, POLICIES, AND BOARD OVERSIGHT]. For each GOVERN category — GV.OC (Organizational Context), GV.RM (Risk Management Strategy), GV.SC (Supply Chain Risk Management), GV.RR (Roles and Responsibilities), GV.PO (Policies and Procedures), and GV.OV (Oversight) — identify specific gaps, the evidence needed to close each gap, and draft a one-paragraph policy statement appropriate for each category.

Board-Level Reporting

Use this to translate CSF 2.0 assessment results into executive-readable format.

Draft a board-level cybersecurity risk report using NIST CSF 2.0 as the reporting structure. My organization is a [TYPE AND SIZE]. Our current Implementation Tier is [TIER 1 THROUGH 4]. Key gaps identified in our last assessment: [LIST GAPS BY FUNCTION]. The report must: explain each CSF Function in terms a non-technical board member can understand, quantify key risks in business impact terms rather than technical terms, present a 12-month improvement roadmap organized by function with cost estimates where possible, and propose three board-level metrics for ongoing oversight.

Supply Chain Risk Assessment

Use this to evaluate a vendor or supplier against the GV.SC subcategories.

I am conducting a supply chain cybersecurity risk assessment under NIST CSF 2.0 GV.SC. Vendor: [VENDOR NAME AND FUNCTION]. Data they access or process: [DESCRIBE DATA AND ACCESS LEVEL]. Their current security documentation: [DESCRIBE WHAT THEY HAVE PROVIDED]. Against NIST CSF 2.0 GV.SC subcategories, identify: which subcategories this vendor relationship triggers, specific questions to include in our vendor security questionnaire, minimum acceptable evidence this vendor should provide, and a risk rating for this vendor relationship with recommended controls.

Common Pitfalls

These are the mistakes practitioners see repeatedly in real assessments and implementation projects.

1

Treating Implementation Tiers as a maturity score. Tiers describe the degree to which risk management is integrated into organizational decisions, not the quality of individual controls. A Tier 3 organization is not necessarily more secure than a Tier 2 one.

2

Ignoring the GOVERN function because it was not in CSF 1.1. Government agencies and critical infrastructure regulators are already referencing GV categories in oversight reviews. Leaving GOVERN unaddressed creates visible gaps.

3

Building a Target Profile without executive agreement on risk tolerance. The GOVERN function makes risk tolerance a documented requirement. If leadership has not explicitly set it, you cannot build a valid Target Profile.

4

Using CSF as a compliance checklist rather than a risk prioritization tool. The framework explicitly states it is not a compliance program. Organizations that treat it as one miss the risk management intent entirely.

5

Skipping the informative references. Each CSF subcategory maps to specific controls in ISO 27001, NIST 800-53, and CIS Controls. Using those mappings avoids duplicating work across frameworks.

Cross-Framework Mapping

ISO 27001

NIST provides an official mapping between CSF 2.0 and ISO/IEC 27001:2022. The Protect and Detect functions map closely to ISO 27001 Annex A Technological Controls.

View Detailed Mapping ↗

NIST 800-53

CSF 2.0 subcategories map directly to NIST 800-53 Rev 5 controls. Federal agencies typically use 800-53 for control implementation and CSF for risk communication.

CIS Controls v8

CIS publishes a community profile that maps CIS Controls v8 to CSF 2.0, providing a practical implementation roadmap particularly useful for mid-market organizations.

All content sourced from official issuing body documentation.

Official source ↗

Framework

NIST Cybersecurity Framework