Identify covers asset management, risk assessment and improvement — the understanding that everything downstream depends on. These outcomes are prerequisites rather than protections, and an incomplete inventory silently caps how well every Protect and Detect outcome can score. In CSF 2.0 the supply chain content that used to live here moved into Govern.
Identify (ID) contains 21 subcategories across 3 categories. CSF 2.0 defines 106 subcategories in total across six functions: Govern, Identify, Protect, Detect, Respond and Recover.
No. CSF 2.0 is a voluntary framework of outcomes and there is no certification against it. Its outcomes become binding only through a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.
Identify lost its supply chain category to the new Govern function and gained an Improvement category covering lessons learned, evaluations and testing.