NIST CSF 2.0 in plain terms
NIST CSF 2.0 is a free, voluntary framework from the US National Institute of Standards and Technology that describes the security outcomes an organization should achieve, grouped into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It says what good looks like, not which product to buy, and any organization of any size can use it.
The six functions of NIST CSF 2.0
Govern. Decide who owns cyber risk, how much of it you will accept, and what your policies are. This includes risk from suppliers and service providers.
Identify. Know what you have: systems, data, suppliers, and the risks to each. You cannot protect a server nobody listed.
Protect. The safeguards: access control, training, data security, patching and secure configuration.
Detect. Notice when something goes wrong, through monitoring and the ability to recognize an attack in progress.
Respond. Act on a detected incident: triage, contain, communicate and report.
Recover. Restore systems and operations, and confirm the restored state is trustworthy before going back to normal.
Govern sits in the middle of NIST’s diagram on purpose. It shapes how the other five are run.
What changed from CSF 1.1
NIST published CSF 2.0 in February 2024, replacing version 1.1 from 2018. Three changes matter most.
Govern was added. In 1.1, governance was a category inside Identify. In 2.0 it is a function of its own, which makes leadership ownership of cyber risk an explicit outcome.
The audience widened. The original framework was built for US critical infrastructure. Version 2.0 is written for any organization: a school board, a software company, a regional credit union.
Supply chain got more weight. In 1.1, supply chain risk management was a category inside Identify. In 2.0 it moved to Govern and was expanded, covering how you choose, contract with and monitor suppliers. Work done against the 1.1 supply chain outcomes (ID.SC) maps across to the 2.0 ones (GV.SC) rather than starting again. A vendor with admin access to your payroll system is squarely in scope.
NIST also added implementation examples and quick-start guides. The full text is in the CSF 2.0 publication, with supporting material on NIST’s framework site.
Profiles explained simply
A profile is a snapshot of the framework’s outcomes, rated for your organization. The current profile says where you are today. The target profile says where you need to be. The gap between them is your roadmap.
Version 2.0 calls these organizational profiles. It also introduces community profiles: shared targets written for a sector or a threat, which a member organization can adopt as a starting point instead of building its own from nothing.
Tiers explained simply
The four tiers are Partial, Risk Informed, Repeatable and Adaptive. They describe how cyber risk is governed and managed: ad hoc at Tier 1, formally approved and updated at Tier 3, continuously improved at Tier 4.
A higher tier is not automatically better. A small firm with a clear owner and a repeatable annual review may be exactly where it should be at Tier 2.
Who should use NIST CSF 2.0
Any organization that wants a common language for security. It suits companies that answer customer security questionnaires, boards that want the same view year on year, and regulated firms that need to show a structured programme. It also works as a bridge when ISO 27001, SOC 2 and sector guidance all have to map to one set of outcomes.
It is less useful as a checklist. Rating every outcome at maximum is expensive and usually unnecessary. Set the target from your risk appetite instead.
Questions we are asked
What is new in NIST CSF 2.0?
Version 2.0 adds a sixth function, Govern, which covers risk strategy, roles, policy and supply chain risk. It also widens the audience from critical infrastructure to every organization and adds implementation examples and quick-start guides.
Are the CSF tiers maturity levels?
No. NIST describes the tiers as a measure of how rigorous your cyber risk governance and management practices are. Tier 4 is not the goal for everyone; the right tier depends on your risk.
Can a Canadian organization use NIST CSF?
Yes. It is voluntary and free to use anywhere. Canadian organizations use it because customers and insurers recognize it, and it maps to ISO 27001 and can be mapped to regulator guidance such as OSFI Guideline B-13.
Where should a small organization start?
Start with Govern and Identify: name who owns cyber risk and list what you need to protect. Then write a short current profile and pick three gaps to close this year.
Building a CSF programme
If you want the current and target profiles built and kept up to date, see our NIST CSF 2.0 programme service, or the wider cyber risk and governance practice. More articles are at writing.