NIST CSF 2.0 Explained: The Six Functions
A breakdown of the framework's six core functions, including the new Govern function added in version 2.0.
The short version
- CSF 2.0 added a sixth function, Govern, that sits above the original five and covers strategy, roles, and policy.
- The framework is outcome-based rather than prescriptive, so it describes what good looks like without dictating controls.
- Its main practical use is as a common language for mapping to more detailed frameworks like ISO 27001 or NIST SP 800-53.
- CSF 2.0 is not certifiable. There is no audit and no certificate, which is a feature for some organizations and a limitation for others.
What is the NIST Cybersecurity Framework?
The NIST Cybersecurity Framework is a voluntary, outcome-based structure for organizing a cybersecurity program. It describes the outcomes a mature program achieves without prescribing the specific controls used to get there. Version 2.0, released in 2024, broadened the framework's stated audience beyond critical infrastructure to organizations of any size or sector.
What changed in version 2.0?
NIST CSF 2.0 added a sixth function, Govern, that sits above the original five. It formalizes what many mature programs already did informally: setting risk management strategy, roles, and policy at the organizational level, not just at the control level. The change matters in practice because it gives program owners a defined place to put board reporting, risk appetite, and role accountability, which previously had no natural home in the framework.
What are the six functions?
- Govern: organizational context, risk strategy, roles, and policy
- Identify: asset management and risk assessment
- Protect: safeguards to limit or contain an incident's impact
- Detect: timely discovery of cybersecurity events
- Respond: actions taken once an incident is detected
- Recover: restoring capabilities and services after an incident
Why do organizations use CSF as a starting point?
CSF 2.0 is deliberately outcome-based rather than prescriptive, which makes it a useful common language for mapping to more detailed frameworks like ISO 27001 or NIST SP 800-53, rather than a replacement for them. It is also readable by people outside security, which makes it unusually effective for board and executive conversations where a control catalog would lose the room.
Can you get certified against NIST CSF 2.0?
No. There is no certification body, no audit, and no certificate for CSF 2.0. Organizations self-assess, often scoring each function on a maturity scale and tracking movement over time. If you need a certificate to satisfy a customer or a tender, ISO 27001 is the standard to pursue. CSF is frequently used alongside it as the internal reporting structure, with ISO 27001 providing the external attestation.
How do I actually run a CSF assessment?
- Agree a maturity scale up front and write down what each level means in your context
- Baseline every subcategory, not just the functions, or the scores will be too coarse to act on
- Set target maturity by business risk rather than aiming for the top score everywhere
- Sequence the gap closure into phases with named owners and dates
- Rescore on a fixed cadence so the scorecard shows movement rather than a one-time snapshot
Need hands-on help with this?
See how our NIST CSF 2.0 Implementation engagement works.
Ready to put this into practice?
Reading the guide is the easy part. If you want practitioners who have run these implementations to scope the work with you, start with a free consultation.