All posts
Compliance Frameworks8 min readAug 16, 2026

NIST Cybersecurity Framework

Ashish / CEO/Co-Founder
NIST Cybersecurity Framework

What Is the NIST Cybersecurity Framework?

The NIST Cybersecurity Framework, or NIST CSF, is a voluntary cybersecurity risk management framework from the National Institute of Standards and Technology, it gives organizations a common way to understand, assess, prioritize, and communicate cybersecurity risk through high-level outcomes rather than a fixed control checklist.

As of 16 August 2026, NIST presents CSF 2.0 as the active version and archives CSF 1.1. CSF 2.0 is designed for organizations of different sizes, sectors, and cybersecurity maturity levels. It can be used voluntarily, although some organizations may also encounter it through government policy, contractual expectations, or sector-specific requirements.

The framework is not a certification program by itself. NIST states that it does not offer certification or endorsement for CSF-related products, implementations, or services, and does not plan a CSF conformity-assessment program in its CSF FAQ. In practice, CSF helps structure cybersecurity work; it does not automatically prove compliance, eliminate risk, or replace legal, regulatory, or audit judgment.

What Changed in NIST CSF 2.0?

The most important thing to know is that CSF 2.0 uses six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. Readers familiar with CSF 1.1 will encounter a six-function model in CSF 2.0, or more precisely, the same model expanded with Govern included as a core Function.

Govern matters because it makes cybersecurity risk management a leadership and operating concern, not only a technical control activity. NIST describes Govern as establishing, communicating, and monitoring cybersecurity risk management strategy, expectations, and policy; it also informs how an organization prioritizes the other five Functions.

The practical takeaway: if your internal materials, vendor questionnaires, or older templates still use only Identify, Protect, Detect, Respond, and Recover, update your framing. CSF 2.0 expects governance decisions — roles, policy, oversight, risk expectations, and accountability — to be part of the framework discussion from the start.

The Six NIST CSF 2.0 Functions, Explained

NIST organizes CSF 2.0 outcomes into six Functions, but the Functions are not a step-by-step sequence. They should be considered together because decisions in one area affect the others.

FunctionQuestion it helps answerPractical exampleHow it connects
GovernWho is accountable for cybersecurity risk, and how are risk decisions made?Define risk management roles, policy ownership, reporting expectations, and escalation paths.Sets direction for how the other Functions are prioritized, funded, reviewed, and adjusted.
IdentifyWhat assets, systems, dependencies, and risks need to be understood?Maintain an inventory of systems, data stores, suppliers, and critical business processes.Gives Protect, Detect, Respond, and Recover a realistic view of what matters most.
ProtectWhat safeguards reduce the likelihood or impact of cybersecurity events?Apply access controls, secure configuration practices, awareness training, or data protection measures.Turns risk priorities into preventive and resilience-focused safeguards.
DetectHow will the organization notice cybersecurity events or anomalies?Monitor logs, alerts, endpoint activity, or suspicious access patterns.Provides the signal needed to trigger response before damage expands.
RespondWhat happens when a cybersecurity incident occurs?Use an incident response process with decision points, communications, containment actions, and post-incident review.Converts detection into coordinated action.
RecoverHow will the organization restore capabilities and improve resilience after disruption?Restore affected services, validate backups, communicate recovery status, and update lessons learned.Feeds improvements back into governance, protection, detection, and response planning.

For a first-time user, the point is not to memorize every category and subcategory. It is to use the six Functions as a complete lens: governance, understanding, safeguards, monitoring, response, and restoration all need attention.

How Core, Profiles, and Tiers Work Together

CSF 2.0 has three major components that matter for practical use: Core, Organizational Profiles, and Tiers.

The CSF Core is NIST’s taxonomy of cybersecurity outcomes, arranged into Functions, Categories, and Subcategories. It describes what an organization may want to achieve, such as understanding assets, managing identities, detecting anomalies, or coordinating response.

Organizational Profiles turn the Core into something usable for a specific organization or scope. A Profile describes current and/or target cybersecurity outcomes based on business context, stakeholder expectations, risk, and requirements.

A Current Profile records the CSF outcomes an organization is achieving or attempting to achieve and how far it has achieved them. A Target Profile identifies selected, prioritized outcomes the organization wants to achieve. The difference between the two becomes the basis for gap analysis and a prioritized action plan.

Tiers characterize the rigor of cybersecurity risk governance and management practices. They can be applied to Profiles, but they should not be treated as a maturity certification, a mandatory ladder, or a universal target. A higher Tier is not automatically the right answer for every organization or every scope.

The most useful starting point, useful for many teams, is the Profile workflow: define what you are looking at, describe where you are now, decide where you need to be, and prioritize the gaps. NIST’s CSF 2.0 publication describes Current and Target Profiles and the use of differences between them to create a prioritized action plan.

How to Start Using NIST CSF 2.0

A practical way to begin is to start small and Profile-based. NIST’s guide to Creating and Using Organizational Profiles shows one workflow: scope the Profile, gather relevant information, create the Profile, analyze Current-versus-Target gaps and create an action plan, then implement and update it as needed.

CSF 2.0 first-steps checklist

This is an editorial starting checklist, adapted from NIST’s Profile workflow. It is not the only valid implementation method.

  1. Define the scope.
    Choose a business unit, product, environment, system, service, or risk area. Avoid trying to profile the entire organization on day one unless you have the people and context to do it well.

  2. Identify stakeholders.
    Include the people who understand risk decisions and operational reality: leadership, security, IT, engineering, risk/compliance, legal where needed, and business owners for the scoped area.

  3. Review relevant CSF outcomes.
    Use the CSF Core to select outcomes that matter for the scope. Do not assume every outcome has equal priority.

  4. Create a Current Profile.
    Record what is already in place, what is partially in place, and where the organization is still trying to achieve an outcome.

  5. Define a Target Profile.
    Select the outcomes the organization wants or needs to achieve based on business risk, stakeholder expectations, threat landscape, applicable requirements, and operational priorities.

  6. Identify and prioritize gaps.
    Compare Current and Target Profiles. Prioritize gaps by risk, business impact, dependencies, and feasibility rather than by a universal scoring formula.

  7. Assign owners.
    Make each action accountable to a role or team. Some gaps may belong to security; others may depend on engineering, IT operations, procurement, legal, or business leadership.

  8. Define evidence expectations.
    Decide what will show progress. Possible evidence may include policies, risk registers, asset inventories, access reviews, tickets, test results, incident records, approvals, or architecture decisions. CSF does not prescribe one evidence set.

  9. Review governance periodically.
    Update the Profile when systems, suppliers, products, risks, or requirements change. Governance review should check whether the Target Profile still reflects the organization’s priorities.

For execution, the real shift is from “we mapped ourselves to CSF” to “we know which outcomes matter, who owns the gaps, what evidence shows progress, and when governance will review the target state.” If you use Ciphrix or another operating layer for compliance work, keep that role practical: translate selected CSF outcomes into owners, controls, evidence, and repeatable review workflows. It should not replace NIST’s materials, professional judgment, or independent assessment where those are required.

Which Official NIST Resource Should You Use Next?

NIST’s CSF Resource Center links to the main publication, Quick Start Guides, Profiles, Informative References, videos, translations, and the CSF 2.0 tool. Use the official materials as the source of truth; use summaries like this article only for orientation.

ResourceBest forWhen to use itWhat not to expect from it
Main CSF 2.0 publicationOfficial definitions, structure, Functions, Core, Profiles, and TiersWhen you need authoritative language or are building internal documentationA step-by-step implementation plan for your specific organization
CSF Resource CenterFinding official downloads and supporting materialsWhen you are not sure which NIST CSF resource to open nextA single tailored answer for your environment
Quick Start GuidesShort, handy topic-specific implementation guidanceWhen you need a more accessible entry point than the full publicationA replacement for reading the main CSF document
Organizational Profiles guideCurrent Profile, Target Profile, gap analysis, and action planningWhen you are ready to turn CSF outcomes into a scoped planA universal target state or required scoring model
Informative References and mappingsExploring relationships to other standards, guidelines, regulations, and contentWhen you need to understand how CSF outcomes may connect to other materialsA universal control baseline or NIST endorsement of every non-NIST mapping
Videos, update materials, translations, and CSF 2.0 toolOrientation, communication, and navigation supportWhen educating stakeholders or working across teamsA substitute for governance decisions, ownership, or implementation work

How NIST CSF Relates to Other Frameworks and Standards

NIST CSF is a cybersecurity risk management framework built around high-level outcomes. It is not a control catalog in the same sense as NIST SP 800-53 Rev. 5, which provides a catalog of security and privacy controls for information systems and organizations.

It is also different from the NIST Risk Management Framework, which is a system life-cycle risk management process with steps such as preparing, categorizing, selecting controls, implementing controls, assessing, authorizing, and monitoring.

Organizations may also need to consider CSF alongside other applicable frameworks and standards, including ISO 27001. That does not make the frameworks equivalent, interchangeable, or universally preferable in combination. Detailed comparisons usually belong in separate guidance, though.

Conclusion

NIST CSF 2.0 gives you a common language for cybersecurity outcomes and risk decisions. To begin using it, not a giant mapping exercise. Pick a scope, build a Current Profile, define a Target Profile, prioritize the gaps, assign owners, decide what evidence will show progress, and review governance as your environment changes.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents