Govern is the function CSF 2.0 added, and adding it was the headline change in the 2.0 revision. It covers organisational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management. The outcomes here are decisions rather than deployments, which is why organisations with mature tooling still score low on Govern: there is no product that makes an executive accountable for cyber risk.
Govern (GV) contains 31 subcategories across 6 categories. CSF 2.0 defines 106 subcategories in total across six functions: Govern, Identify, Protect, Detect, Respond and Recover.
No. CSF 2.0 is a voluntary framework of outcomes and there is no certification against it. Its outcomes become binding only through a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.
Govern is entirely new in CSF 2.0 — CSF 1.1 had five functions and no Govern. Supply chain risk management moved here from Identify, and governance content that was previously scattered across other functions was consolidated into it.