What NIST CSF is — and isn't
The CSF is not a certification and not a rigid checklist. It is a voluntary framework that describes cybersecurity outcomes in a common language, so organisations of any size can assess where they are, decide where they want to be, and communicate risk to leadership. Because it is outcome-based rather than prescriptive, it maps cleanly onto other frameworks you may already run.
Govern
Strategy & oversight
Identify
Assets & risk
Protect
Safeguards
Detect
Find events
Respond
Act on incidents
Recover
Restore capability
What changed in CSF 2.0
The headline change is the addition of Govern as a sixth function, elevating governance — roles, policy, risk appetite and oversight — to sit alongside the original five. CSF 2.0 also broadened its audience beyond critical infrastructure to organisations of all sizes and sectors, and strengthened its treatment of supply-chain risk.
How to adopt it
- 1Create a current profile: assess which outcomes you achieve today across the six functions.
- 2Create a target profile: decide the outcomes you need, based on your risk and obligations.
- 3Gap and prioritise: the distance between current and target becomes your roadmap.
- 4Map to evidence: link each outcome to the artefacts that demonstrate it.
- 5Reassess on a cadence: profiles are living, not one-off.
Common pitfalls to avoid
- Treating the tiers as a maturity score to maximise, rather than a risk-based choice.
- Skipping Govern and jumping straight to technical controls.
- Building profiles once and never revisiting them.