Article
Jul 23, 2026
NIST CSF 2.0 Explained: The Six Functions, Tiers, and Profiles — A Practical Guide
The NIST Cybersecurity Framework 2.0, released in February 2024, is a voluntary framework for organising, assessing and communicating cybersecurity risk. Version 2.0 added a sixth function — Govern — and widened the framework beyond critical infrastructure to organisations of every size. This guide explains the six Functions and their Categories, the Core / Tiers / Profiles structure, how to run a Current-to-Target gap assessment, the new Govern function and CSF Tiers, and how CSF maps to ISO 27001 and SOC 2 so it becomes the connective tissue of a single compliance programme.