NIST CSF 2.0

NIST CSF 2.0,
explained plainly

The NIST Cybersecurity Framework 2.0 is a voluntary way to organize and improve your cybersecurity — not a certification you pass. Here is what it actually is: the six Functions including the new Govern, the Categories and Subcategories that describe outcomes, the Implementation Tiers, and the Current and Target Profiles that give you a path. And how teams run the whole thing in one Swiss-hosted workspace.

Book a conversation
Every framework
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • Swiss nFADP
  • NIST CSF 2.0
  • OWASP
  • EU AI Act
The framework

What NIST CSF 2.0 actually is.

NIST CSF 2.0, published by the US National Institute of Standards and Technology in February 2024, is a voluntary framework — not a law and not certifiable. Its Core organizes cybersecurity outcomes into six Functions, with Tiers and Profiles to gauge and plan your progress.

The six Functions

Govern, Identify, Protect, Detect, Respond and Recover — the top level of the Core, with Govern newly added in 2.0 to cover strategy, roles and oversight.

Categories and Subcategories

Each Function breaks into Categories and Subcategories that state security outcomes to achieve — not prescriptive controls telling you exactly how.

Implementation Tiers

Tier 1 Partial through Tier 4 Adaptive describe how rigorous and risk-informed your practices are — a maturity gauge, not a grade.

Current and Target Profiles

A Current Profile captures where you are today, a Target Profile where you want to be — the gap between them is your prioritized roadmap.

The full picture

NIST CSF 2.0, explained in full.

A plain-language walkthrough — what it is, what it asks for, and what it takes to keep it current.

01

What is NIST CSF 2.0?

The NIST Cybersecurity Framework (CSF) is a voluntary framework for organizing, understanding and improving your cybersecurity. It was created by the US National Institute of Standards and Technology, and version 2.0 was published in February 2024. It is not a regulation, and crucially it is not a standard you certify against: there is no NIST CSF audit, no exam, and no certificate to hang on the wall.

Because of that, the language around CSF is different from a certifiable standard. You do not "pass" NIST CSF, and nobody "fails" it. You adopt it, you align to it, and you build a profile against it. Its job is to give you a shared structure and vocabulary for cybersecurity, a way to describe what good looks like, see where you stand, and decide what to improve next, rather than a fixed bar an auditor checks you over.

The original 2014 framework was aimed at operators of US critical infrastructure. Version 2.0 deliberately broadened that audience: it is now written for organizations of all sizes and every sector, anywhere in the world. A small European software company can use CSF just as readily as a large US utility, and increasingly does, because the structure travels well even though the framework itself is American in origin.

Outcomes, not a control checklist

It helps to know up front what CSF is not. It is not a list of controls you tick off. The Core describes outcomes, things you want to be true about your security, and leaves the choice of how to achieve them to you. That is what makes it flexible enough to fit almost any organization, and also why two teams can both align to CSF and run very different programs underneath.

02

The six Functions (and the new Govern)

The heart of CSF is the Core, and the top level of the Core is six Functions: Govern, Identify, Protect, Detect, Respond and Recover. Read together they describe the full lifecycle of managing cybersecurity risk — from setting strategy, through understanding and protecting what matters, to spotting, responding to and recovering from incidents.

The headline change in 2.0 is Govern. Earlier versions had five Functions; 2.0 adds Govern as a sixth, and places it at the centre rather than the end. Govern covers the cybersecurity strategy, the roles and responsibilities, the policies and the oversight that hold the whole program together — the decisions leadership owns. By naming it explicitly, CSF 2.0 makes the point that cybersecurity is a governance and risk-management problem, not just a technical one.

The other five Functions each address a distinct part of the lifecycle. Identify is about understanding your assets, your risks and your context. Protect covers the safeguards that reduce the likelihood or impact of an incident. Detect is about noticing that something has happened. Respond is what you do when it does, and Recover is how you restore normal operations and learn from it afterwards. None stands alone; a healthy program touches all six.

03

Categories and Subcategories

Each Function is broken down into Categories, and each Category into Subcategories. This is where the framework gets specific — but specific about results, not methods. A Subcategory states an outcome to achieve, written as something that should be true: an asset inventory is maintained, access is managed, events are analyzed. It does not tell you which tool to buy or exactly how to do it.

That outcome-based design is deliberate, and it is the most important thing to understand about the Core. Because Subcategories describe what good looks like rather than prescribing how, the same framework fits a two-person startup and a multinational. You decide which controls and practices satisfy each outcome in your context; CSF just tells you which outcomes matter and how they fit together.

Informative references

CSF does not pretend to be the only source of guidance. Each Subcategory can be mapped to informative references — pointers to other standards and control sets that help you achieve the outcome, such as ISO 27001 or NIST SP 800-53. This is what lets CSF sit on top of frameworks you may already use, rather than competing with them, and it is the mechanism behind using CSF as a backbone.

04

Implementation Tiers

Alongside the Core, CSF offers Implementation Tiers as a way to describe how mature and risk-informed your cybersecurity practices are. There are four: Tier 1 Partial, Tier 2 Risk Informed, Tier 3 Repeatable and Tier 4 Adaptive. They run from ad hoc and reactive at Tier 1 to consistent, well-governed and continuously improving at Tier 4.

It is important not to read Tiers as a score or a target to max out. A higher Tier is not automatically "better" for every organization — the right Tier is the one that matches your risk, your resources and what your context demands. A small low-risk team operating well at Tier 2 may be exactly where it should be. Tiers are a gauge to inform a conversation about how rigorously you want to manage cyber risk, not a grade you are chasing.

05

Current and Target Profiles

Profiles are how CSF turns the Core into a plan. A Profile is your selection of the Functions, Categories and Subcategories that matter for your organization, together with where you stand on each. You build two: a Current Profile that honestly captures your security outcomes as they are today, and a Target Profile that describes where you want or need to be.

The gap between the two is the whole point. Lay the Current Profile next to the Target Profile and the differences become a prioritized list of improvements — a roadmap grounded in your own risk and resources rather than someone else's checklist. As you close gaps, you update the Current Profile, and the framework becomes a living record of progress rather than a one-off assessment.

This is also where CSF earns its keep across stakeholders. A Profile is concrete enough to brief a board, scope a budget, or align a security team and leadership on the same priorities — without anyone needing to read the full framework first.

06

What changed in version 2.0

If you have used the older framework, three changes in 2.0 matter most. The first is the new Govern Function, which we have already covered — it elevates strategy, roles, policy and oversight into a Function of their own and puts governance at the centre of the model.

The second is scope. The 2014 framework was framed around US critical infrastructure; 2.0 explicitly widens the audience to organizations of every size and sector, anywhere. The framework text reads as something a small company or a non-US organization can adopt without translation, which it largely was not before.

The third is the supporting material. NIST paired 2.0 with more practical resources — quick-start guides, implementation examples and reference tools, all designed to make the framework easier to actually use rather than just read. The Core became more usable, and the surrounding scaffolding grew up around it.

07

Using CSF as a backbone for ISO 27001 or SOC 2

Because CSF is outcome-based and maps to other standards through its informative references, many teams use it as the organizing backbone of their security program rather than as a destination. CSF gives you the structure, the Functions and outcomes, and you certify against ISO 27001 or attest to SOC 2 underneath it, where a customer or tender specifically needs that proof.

This works well because the frameworks are complementary, not competing. CSF answers "how is our whole program organized and where are the gaps?" in language a board understands. ISO 27001 and SOC 2 answer "can we prove to a third party that specific controls operate?" Run CSF on top, map its outcomes down to your ISO or SOC controls, and one body of evidence serves both the internal roadmap and the external attestation.

In practice the order varies. Some teams adopt CSF first to get their bearings, then pursue a certificate once they know what their program looks like. Others already hold ISO 27001 or a SOC 2 report and overlay CSF to give leadership a clearer, risk-based view across the whole estate. Either way, doing the mapping once is what keeps the second framework from being a second full project.

08

Showing progress without a certificate

The flip side of "no certificate" is a fair question: if nobody hands you a pass, how do you show anyone you are taking cybersecurity seriously? The answer is your Profiles and your Tier. A Current Profile that shows which outcomes you have achieved, a Target Profile that shows where you are heading, and the trend between them over time is a credible, honest picture of a managed program — often more informative than a binary certificate.

This is what you put in front of a customer, a partner or your own board. It demonstrates that you have assessed your risks, chosen outcomes deliberately, and are improving against a plan. Many organizations also use a CSF Profile as the internal map and then layer a certificate like ISO 27001 on top when a specific deal requires third-party assurance — the Profile shows the program, the certificate proves a slice of it.

09

Getting started with NIST CSF 2.0

The lightest way to begin is to build a rough Current Profile. Walk the six Functions and, for the Categories that matter to you, note honestly where you stand. You do not need to address every Subcategory on day one — the value is in getting an organized, end-to-end picture instead of a scattered list of security tasks.

From there, define a Target Profile that reflects your risk and resources — and pick a realistic Tier to aim for, not the highest one available. The gap between Current and Target becomes your prioritized roadmap, and the work shifts to closing it and keeping the Current Profile honest as you go. Because CSF is voluntary and outcome-based, you can move at your own pace and shape it to your context; the framework rewards a living program far more than a one-time assessment filed away.

The real problem

Audit-ready is a state you keep, not a sprint you survive.

Most tools optimize for getting the first certificate. The expensive part is the years after — the spreadsheet sprawl, the evidence you reassemble from memory the week before an audit, the client (or control) you haven't looked at since last cycle. That's the part no first-cert tool was built for.

Spreadsheet sprawl across drives, tabs and inboxes
The week-before scramble, reassembled from memory
The control you haven't looked at since last cycle
Audit-readiness over time
Year over year
audit-readyYear 1Year 2Year 3
Point-in-time tools — scramble & drift
devguard — a state you keep
Run it in devguard

Your NIST CSF program, in one workspace.

The Functions, your Profiles, the policies and the reviews behind them — connected, current and ready to show, not scattered across spreadsheets. Pick one to see it.

All six Functions, in one view

See Govern, Identify, Protect, Detect, Respond and Recover with your coverage across each — your Current Profile as a live picture rather than a spreadsheet you rebuild before every board update, with the Target you are working towards in the same view.

Learn more
Control coverage64%
Asset managementCovered
CryptographyPartial
Supplier securityGap
Document once. Reuse across every standard you add.

CSF maps to ISO 27001 and SOC 2 through its informative references, so the outcomes you evidence for your Profile are the same controls those standards ask for. Map them once in devguard and a single policy and piece of evidence satisfy CSF and the certificate underneath it.

See the full feature comparison

Already certified and dreading the next cycle? See how we help certified companies stay audit-ready.

Already using NIST CSF? Move your profile across.

If you already run a CSF program, you do not want to rebuild your Profiles from a blank page. In a scoped conversation we agree exactly what moves — your Current and Target Profiles, the outcomes you have mapped, your policies, risks and review history, and run that migration with you, for a fixed scope and a date set before we start. Your existing setup stays untouched and exportable until you are satisfied the new one holds up side by side.

Book a conversation
NIST CSF 2.0 FAQ

NIST CSF 2.0, answered plainly.

Is NIST CSF 2.0 a certification you can pass?

No. NIST CSF is a voluntary framework, not a certifiable standard — there is no NIST CSF audit, exam or certificate. You adopt it, align to it and build a Profile against it. To show a third party that specific controls operate, teams typically certify against ISO 27001 or attest to SOC 2 alongside their CSF program.

What are the six Functions of NIST CSF 2.0?

Govern, Identify, Protect, Detect, Respond and Recover. Govern is the one added in version 2.0; it covers cybersecurity strategy, roles, policy and oversight, and sits at the centre of the framework rather than alongside the others.

What changed between the old framework and CSF 2.0?

Three things mostly. CSF 2.0 added the Govern Function (the previous version had five), broadened its scope from US critical infrastructure to organizations of all sizes and sectors anywhere, and shipped more practical resources such as quick-start guides and implementation examples to make it easier to use.

What are Implementation Tiers, and should I aim for Tier 4?

Tiers (1 Partial through 4 Adaptive) describe how rigorous and risk-informed your practices are. They are a gauge, not a grade — the right Tier is the one that matches your risk and resources, not the highest one. A small, low-risk team can be exactly right at a lower Tier.

What is a Current Profile versus a Target Profile?

A Current Profile captures where your security outcomes stand today; a Target Profile describes where you want or need to be. The gap between them is your prioritized improvement roadmap. As you close gaps you update the Current Profile, so it stays a living record of progress.

Can I use NIST CSF alongside ISO 27001 or SOC 2?

Yes, and many teams do. CSF maps to other standards through its informative references, so it works well as the organizing backbone of your program while you certify against ISO 27001 or attest to SOC 2 underneath. Map the outcomes to those controls once and a single body of evidence serves both.

See how your NIST CSF program would look in devguard.

The fastest way to know if this fits is a short conversation about how you run NIST CSF today — your Profiles, where the effort goes, and what moving it would involve. No deck unless you want one.

Book a conversation
Sign in
Start for free
Book a conversationStart for free