Frameworks /  US

NIST CSF 2.0

The NIST Cybersecurity Framework is a voluntary, outcome-based framework for organising and communicating cybersecurity risk. It describes what good looks like, and unlike ISO 27001 it cannot be certified against.

What it requires

CSF 2.0, published in February 2024, is organised around six Functions: Govern (added in 2.0), Identify, Protect, Detect, Respond and Recover. Each Function contains Categories and Subcategories, which state security outcomes rather than prescriptive controls: the framework tells you that asset inventories are maintained, not which tool to use. Organisations express where they stand using Profiles: a Current Profile describing today, and a Target Profile describing the desired state, with the gap between them driving the roadmap. Implementation Tiers (1 Partial, 2 Risk Informed, 3 Repeatable, 4 Adaptive) characterise how rigorous and integrated the organisation's cyber risk governance is; they are not maturity grades to be climbed for their own sake. CSF 2.0 explicitly broadened its audience beyond critical infrastructure to organisations of every size and sector, and its GOVERN function pulls organisational context, roles, policy, supply chain and risk-management strategy to the centre.

NIST CSF is voluntary for the private sector and applies to any organisation that wants a common language for cyber risk. It shows up commercially in three ways: US customers and insurers ask "what framework do you follow"; boards want a defensible way to see and fund security; and it serves as the organising backbone when a company must satisfy several regimes at once. For Israeli companies without a CISO, CSF is often the most useful starting structure precisely because it does not require a certification project, but it also does not close a deal on its own, and buyers asking for proof will still ask for ISO 27001 or SOC 2.

The controls people actually fail

  • GOVERN is skipped entirely (no defined risk appetite, no named owners for cyber risk, no board-level reporting) and the programme becomes a technical checklist with no authority behind it.
  • The asset inventory (ID.AM) is partial: cloud accounts, SaaS applications and shadow IT are missing, which silently invalidates every downstream Protect and Detect outcome.
  • A Target Profile is defined once during a consulting engagement and never revisited, so the roadmap describes priorities that no longer match the business.
  • Detect capabilities exist as tooling but not as a process: alerts fire into a channel nobody owns, and no one can say what the mean time to detection actually is.
  • Recover is treated as backups existing, with no tested restoration, no recovery time objective, and no evidence that a restore has ever been performed end to end.
  • Supply chain risk management (GOVERN and ID) is asserted but not practised: no tiering of vendors by criticality, no reassessment cadence.
CSF has no audit and no expiry, which makes it easy to quietly stop doing. The Current Profile is a snapshot taken on the day of the workshop; every new SaaS tool, cloud account and acquisition moves the real profile away from it without anyone noticing. A framework whose whole purpose is to show you where you stand is worthless the moment it stops being re-measured.

Can you get certified in NIST CSF?

No. NIST does not operate a certification or accreditation scheme for the Cybersecurity Framework, and there is no accredited body that can issue a CSF certificate. Organisations self-assess, or commission a third party to assess them, and communicate the result as a Profile and an Implementation Tier. If a customer requires certified proof, they are asking for ISO 27001 or a SOC 2 report: CSF is the internal organising framework, not the external evidence.

What are the six functions of NIST CSF 2.0?

Govern, Identify, Protect, Detect, Respond and Recover. GOVERN is new in version 2.0 (February 2024) and covers organisational context, risk management strategy, roles and responsibilities, policy, oversight and cybersecurity supply chain risk management: it exists because the most common cause of failure was never a missing tool but an absent owner and an unfunded mandate.

What is the difference between NIST CSF and ISO 27001?

NIST CSF is a voluntary, outcome-based framework for describing and prioritising cyber risk; ISO 27001 is a certifiable standard specifying the requirements for a management system. CSF tells you what outcomes to achieve and helps you communicate progress to executives; ISO 27001 tells you what management process you must operate and lets an accredited body attest that you operate it. They are complementary: many organisations use CSF to structure and prioritise the work, and ISO 27001 to prove it externally.

What are NIST CSF Implementation Tiers, and should we aim for Tier 4?

The four Tiers (Partial, Risk Informed, Repeatable and Adaptive) describe how rigorously cybersecurity risk is governed and integrated into the organisation, not how many controls you have. They are not a maturity ladder every organisation should climb: NIST is explicit that the appropriate Tier is the one that fits your risk, resources and obligations. A 120-person company chasing Tier 4 usually produces expensive documentation, not less risk.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.