What NIST CSF is, and isn't
The CSF is not a certification and not a rigid checklist. It is a voluntary framework that describes cybersecurity outcomes in a common language, so organisations of any size can assess where they are, decide where they want to be, and communicate risk to leadership. Because it is outcome-based rather than prescriptive, it maps cleanly onto other frameworks you may already run.
Govern
Strategy & oversight
Identify
Assets & risk
Protect
Safeguards
Detect
Find events
Respond
Act on incidents
Recover
Restore capability
What changed in CSF 2.0
The headline change is the addition of Govern as a sixth function, elevating governance (roles, policy, risk appetite and oversight) to sit alongside the original five. CSF 2.0 also broadened its audience beyond critical infrastructure to organisations of all sizes and sectors, and strengthened its treatment of supply-chain risk.
How to adopt it
- 1Create a current profile: assess which outcomes you achieve today across the six functions.
- 2Create a target profile: decide the outcomes you need, based on your risk and obligations.
- 3Gap and prioritise: the distance between current and target becomes your roadmap.
- 4Map to evidence: link each outcome to the artefacts that demonstrate it.
- 5Reassess on a cadence: profiles are living, not one-off.
Common pitfalls to avoid
- Treating the tiers as a maturity score to maximise, rather than a risk-based choice.
- Skipping Govern and jumping straight to technical controls.
- Building profiles once and never revisiting them.