Where ISO 27001 gives you a certificate and SOC 2 gives you a report, the NIST Cybersecurity Framework (CSF) gives you something subtler and, for many organisations, more useful day to day: a shared language for talking about cyber-risk that a board member, an engineer, and an auditor can all use. There is no certification and no audit — CSF is voluntary. Its value is as an organising structure that tells you what good looks like across the whole security programme and lets you measure how close you are. This guide covers CSF 2.0 — the February 2024 revision — its six Functions, the Core/Tiers/Profiles model, how to run a gap assessment, and how it ties your ISO 27001 and SOC 2 efforts together.

The short version

NIST CSF 2.0 organises cybersecurity into six Functions — Govern, Identify, Protect, Detect, Respond, Recover — subdivided into Categories and Subcategories (the specific outcomes you aim for). You assess where you are using Implementation Tiers (1–4, from Partial to Adaptive) and describe where you want to be using Profiles (a Current Profile and a Target Profile). The gap between them is your roadmap. The headline change in 2.0 is the new Govern function, which elevates cybersecurity governance — strategy, roles, policy, oversight, supply-chain risk — to sit alongside the technical functions. Crucially, CSF is outcome-based: it tells you what to achieve, not how, and it maps cleanly onto the controls you build for ISO 27001 and SOC 2.

What changed in version 2.0

CSF 1.1 (2018) was written primarily for US critical infrastructure and had five functions. Version 2.0, published in February 2024, made three consequential changes:

  • A sixth function, Govern. Governance was previously scattered through the other functions; 2.0 pulls it into its own function covering organisational context, risk-management strategy, roles and responsibilities, policy, oversight, and — importantly — cybersecurity supply-chain risk management. This reflects the reality that most security failures are governance failures first.
  • Scope widened to everyone. The title dropped its critical-infrastructure framing. CSF 2.0 is explicitly for organisations of all sizes and sectors, including small businesses and non-US entities.
  • A suite of implementation resources. NIST added Quick-Start Guides, Implementation Examples (concrete actions per subcategory), and Community Profiles (sector-specific baselines), making the framework far more actionable than a document alone.

The six Functions

The Functions are the top level of the CSF Core. Read together they form a continuous lifecycle — govern the programme, know what you have, protect it, detect problems, respond, and recover — wrapped around your risk management.

Function Core question Representative categories
Govern (GV)How do we make and oversee cyber-risk decisions?Organizational context; risk management strategy; roles, responsibilities and authorities; policy; oversight; cybersecurity supply-chain risk management.
Identify (ID)What do we have and what are the risks?Asset management; risk assessment; improvement.
Protect (PR)How do we safeguard it?Identity management and access control; awareness and training; data security; platform security; technology infrastructure resilience.
Detect (DE)How do we spot something wrong?Continuous monitoring; adverse event analysis.
Respond (RS)What do we do when it happens?Incident management; analysis; response reporting and communication; mitigation.
Recover (RC)How do we get back to normal?Incident recovery plan execution; recovery communication.

Beneath the Functions sit Categories (outcome groups such as "Asset Management" or "Identity Management, Authentication and Access Control") and, beneath those, Subcategories — the specific, measurable outcomes like "PR.AA-01: Identities and credentials for authorized users are managed." The Subcategories are where a gap assessment lives, and each links to Informative References that map it to ISO 27001, SOC 2, NIST SP 800-53 and CIS Controls. Our free NIST CSF reference tool has a page per subcategory with these mappings.

Core, Tiers and Profiles: the three-part model

CSF has three components, and understanding how they interlock is the key to using it well rather than just quoting it.

  • The Core is the catalogue described above — Functions, Categories, Subcategories, and the outcomes they represent. It is the what.
  • Implementation Tiers (1–4) describe how rigorous and integrated your risk management is — not a maturity score of individual controls, but of the programme. Tier 1 (Partial) is ad hoc and reactive; Tier 2 (Risk Informed) has risk awareness but inconsistent practice; Tier 3 (Repeatable) has formal, organisation-wide policy consistently applied; Tier 4 (Adaptive) actively improves from lessons learned and adapts to a changing threat landscape. Higher is not automatically the goal — the right tier is the one that matches your risk appetite and resources.
  • Profiles are where it becomes actionable. A Current Profile records the outcomes you achieve today; a Target Profile records the outcomes you need given your business, risk and obligations. The delta between them is your prioritised roadmap.

This Current-to-Target mechanic is CSF's most practical feature. It turns "are we secure?" — an unanswerable question — into "here are the 18 subcategories where we fall short of our target, ranked by risk," which a leadership team can actually fund and track.

The Govern function — why 2.0's biggest change matters

Adding Govern as a peer of the technical functions is a statement about where security programmes actually fail. It codifies six areas: organizational context (mission, obligations, stakeholders), risk management strategy (appetite, tolerance, how risk decisions get made), roles, responsibilities and authorities (who owns what, up to the board), policy, oversight (measuring whether the strategy works and adjusting), and cybersecurity supply-chain risk management (C-SCRM). That last one — governing the risk your vendors and software supply chain introduce — is increasingly the source of major breaches, which is why it now has first-class status. If you already run a structured third-party risk management programme with a vendor risk assessment process, you have a running start on GV.SC. The Govern function is also where CSF connects most directly to ISO 27001's Clause 5 leadership requirements and SOC 2's CC1 control-environment criteria — the same governance, described three ways.

How to actually use CSF: a practical sequence

CSF is not something you "pass"; it is something you operate. A workable approach:

  • Step 1: Set organizational context and scope (Govern + Identify). Define what the programme protects, your mission and obligations, your risk appetite, and who is accountable. This grounds every later decision.
  • Step 2: Build the Current Profile. Assess each in-scope Subcategory honestly — achieved, partial, or not achieved — with evidence. This is a facilitated workshop plus document review, not a self-graded quiz.
  • Step 3: Define the Target Profile. Decide the outcomes you need, informed by your risk appetite, customer and regulatory requirements, and any sector Community Profile. Not every subcategory needs to be maxed out.
  • Step 4: Gap analysis and prioritisation. Compare Current to Target, then rank the gaps by risk and effort. This is your roadmap and the artefact leadership cares about.
  • Step 5: Remediate and re-measure. Close gaps, then reassess on a cadence — annually at least, and after any major change or incident. The Current Profile should visibly move toward the Target over time.

A risk register feeds Step 1 and Step 4 directly, and the Control Mapper lets you reuse the same evidence across CSF subcategories, ISO Annex A controls, and SOC 2 criteria in one pass.

CSF, 800-53, 800-171 and CMMC — where CSF sits

CSF is the strategic layer; other NIST publications provide the detailed controls beneath it. NIST SP 800-53 is the comprehensive control catalogue (used for US federal systems and FedRAMP) that CSF subcategories reference for implementation depth. NIST SP 800-171 protects Controlled Unclassified Information (CUI) in non-federal systems and underpins CMMC, the certification US defense contractors must hold. The relationship is layered: use CSF to organise and communicate the programme, and reach for 800-53 or 800-171 when you need the specific, testable controls — for example if you are a federal contractor. For most commercial SMBs, CSF 2.0 plus ISO 27001 or SOC 2 controls is the right altitude; 800-53/171 come into play only with government exposure.

CSF vs ISO 27001 vs SOC 2 — the connective tissue

CSF's superpower in a multi-framework world is that it was designed to map to the others:

  • NIST CSF 2.0 — a voluntary, outcome-based framework. No audit, no certificate. Best for organising the whole programme and communicating risk to leadership. Free to adopt.
  • ISO 27001 — a certification against a management-system standard with a fixed control set. A formal, internationally recognised badge. See the ISO 27001 guide.
  • SOC 2 — a US CPA attestation report against the Trust Services Criteria, shared with customers. See the SOC 2 guide.

Because CSF subcategories carry Informative References to ISO 27001 Annex A and to the AICPA criteria, many organisations use CSF as the master structure and treat ISO and SOC 2 as specific outputs of the same programme. Assess once against the CSF Core, build a single control set, and use the Control Mapper to present it as an ISO Statement of Applicability, a SOC 2 control matrix, or a CSF profile as each audience requires.

Common mistakes

  • Chasing Tier 4 for its own sake. The Tiers describe rigour, not a trophy. A well-run Tier 3 programme that matches your risk appetite beats an aspirational Tier 4 you cannot sustain.
  • Skipping the Target Profile. A Current Profile with nothing to compare against is a status report, not a roadmap. The gap is the whole point.
  • Treating Govern as paperwork. The new function fails if it becomes a policy binder. It only works when risk decisions, ownership and oversight actually change how the organisation behaves.
  • Self-assessing without evidence. A Current Profile built on optimism rather than artefacts produces a roadmap that fixes the wrong things. Grade against evidence.
  • Forgetting supply chain. GV.SC exists because vendors are a leading breach vector. A CSF programme that ignores third-party risk has a hole where its newest priority should be.
  • Using CSF in isolation. Its greatest value is as the map that connects your other frameworks. Run it standalone and you miss the "assess once, report many" payoff.

Bottom line

NIST CSF 2.0 is the framework you reach for when you need to understand and communicate your security posture rather than certify it. Its six functions give leadership a complete picture, the Current-to-Target profile turns that picture into a funded roadmap, and the new Govern function finally puts strategy and supply-chain risk where they belong. Best of all, because it maps directly to ISO 27001 and SOC 2, CSF is the connective tissue that lets one security programme speak every compliance language your customers ask for. Start with an honest Current Profile; the roadmap writes itself from there.

Frequently asked questions

What is the NIST Cybersecurity Framework 2.0?

NIST CSF 2.0, published in February 2024, is a voluntary framework for organising, assessing and communicating cybersecurity risk. It structures security into six Functions — Govern, Identify, Protect, Detect, Respond and Recover — broken into Categories and Subcategories that describe specific outcomes. There is no certification or audit; organisations use it to understand where they stand, set targets, and build a prioritised improvement roadmap. Version 2.0 widened the framework from its original critical-infrastructure focus to organisations of all sizes and sectors.

What are the six functions of NIST CSF 2.0?

The six Functions are Govern (risk-management strategy, roles, policy, oversight and supply-chain risk), Identify (assets and risks), Protect (safeguards such as access control and data security), Detect (monitoring and event analysis), Respond (incident management and mitigation) and Recover (restoring capabilities after an incident). Govern is new in version 2.0 and sits at the centre, informing the other five. Together they form a continuous risk-management lifecycle.

What is new in CSF 2.0 compared with 1.1?

The three main changes are: the addition of the Govern function, which elevates governance, strategy and cybersecurity supply-chain risk management to a top-level function; a broadened scope so the framework explicitly applies to organisations of all sizes and sectors rather than mainly critical infrastructure; and a set of new implementation resources including Quick-Start Guides, Implementation Examples and Community Profiles that make the framework more actionable.

What are CSF Tiers and Profiles?

Implementation Tiers (1 Partial, 2 Risk Informed, 3 Repeatable, 4 Adaptive) describe how rigorous and integrated your cybersecurity risk management is at a programme level. Profiles apply the framework to your organisation: a Current Profile captures the outcomes you achieve today, and a Target Profile captures the outcomes you need. The gap between Current and Target profiles becomes your prioritised roadmap. Higher tiers are not automatically better — the right tier matches your risk appetite and resources.

Is NIST CSF a certification like ISO 27001?

No. NIST CSF is a voluntary framework with no certification, audit or formal pass/fail — you adopt it to organise and communicate cyber-risk. ISO 27001 is a certification against a management-system standard, issued by an accredited body, and SOC 2 is a CPA attestation report. CSF's strength is that its subcategories map to both ISO 27001 and the SOC 2 criteria, so many organisations use it as the master structure and produce ISO or SOC 2 outputs from the same underlying programme.

How does NIST CSF relate to NIST 800-53 and CMMC?

CSF is the strategic, outcome-based layer; NIST SP 800-53 is the detailed control catalogue (used for federal systems and FedRAMP) that CSF subcategories reference for implementation depth. NIST SP 800-171 protects Controlled Unclassified Information in non-federal systems and underpins CMMC, the certification required of US defense contractors. For most commercial organisations, CSF 2.0 combined with ISO 27001 or SOC 2 controls is the right level; 800-53, 800-171 and CMMC become relevant when you have US government or defense-contract exposure.