What is the NIST Cybersecurity Framework?
The NIST CSF is the most widely used way to organise a security programme. This guide explains what it is and how CSF 2.0 changed it.
The NIST Cybersecurity Framework (CSF) is a voluntary framework from the US National Institute of Standards and Technology for organising and improving a cybersecurity programme. It is widely adopted worldwide because it is practical, outcome-based, and maps cleanly to other standards.
CSF 2.0, released in 2024, added a new Govern function and broadened the framework beyond critical infrastructure to any organisation. This guide covers its structure and how to use it.
- CSF is a voluntary framework for structuring a programme, not a certification.
- CSF 2.0 has six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
- Tiers describe how mature your practices are; Profiles describe your current and target state.
- It is a common language that maps to ISO 27001, SOC 2, and regulatory frameworks.
The six functions
CSF 2.0 organises cybersecurity outcomes into six functions:
- Govern: set and monitor strategy, roles, and risk management (new in 2.0).
- Identify: understand assets, risks, and exposure.
- Protect: put safeguards in place.
- Detect: find events quickly.
- Respond: act on incidents.
- Recover: restore operations.
Tiers and profiles
Tiers (1 to 4) describe how rigorous and adaptive your risk practices are, from partial to adaptive. Profiles let you describe your current state and a target state, so the gap between them becomes your roadmap. Together they turn the framework into a plan rather than a static list.
How to use it
Most organisations use CSF as the backbone of their programme: map current controls to the functions, identify gaps against a target profile, and prioritize. Because CSF maps to standards like ISO 27001 and SOC 2, it also helps you avoid duplicating work across multiple compliance efforts.
Frequently asked questions
References
This guide is based on official primary sources, reviewed against them in July 2026. Always confirm the latest text with the issuing authority.
Put a framework behind your programme
Get a clear, prioritized view of your risk aligned to the CSF functions.
Get your free risk score