Recover covers incident recovery plan execution and recovery communication. It is the least frequently tested function in practice and the most commonly assumed: a backup job that reports success is not recovery evidence. Restoration testing against a defined recovery time objective is what demonstrates these outcomes.
Recover (RC) contains 8 subcategories across 2 categories. CSF 2.0 defines 106 subcategories in total across six functions: Govern, Identify, Protect, Detect, Respond and Recover.
No. CSF 2.0 is a voluntary framework of outcomes and there is no certification against it. Its outcomes become binding only through a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.
CSF 2.0 restructured the Core and renumbered subcategories, so RC identifiers do not map one-to-one to CSF 1.1. If you are transitioning a profile, re-assess against the 2.0 Core rather than renaming your existing entries.