Respond covers incident management, analysis, reporting and communication, and mitigation. Response capability is hard to evidence without incidents, so exercises and tabletop records carry the weight — they are what demonstrates the capability exists before it is needed rather than after.
Respond (RS) contains 13 subcategories across 4 categories. CSF 2.0 defines 106 subcategories in total across six functions: Govern, Identify, Protect, Detect, Respond and Recover.
No. CSF 2.0 is a voluntary framework of outcomes and there is no certification against it. Its outcomes become binding only through a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.
CSF 2.0 restructured the Core and renumbered subcategories, so RS identifiers do not map one-to-one to CSF 1.1. If you are transitioning a profile, re-assess against the 2.0 Core rather than renaming your existing entries.