NIST Cybersecurity Framework

NIST CSF 2.0,
six functions, one plan.

The NIST CSF is the common language US security teams, boards and many customers use for cyber risk. This guide covers what changed in CSF 2.0, how tiers and profiles work, how it compares with ISO 27001, and where NIST SP 800-53 and 800-171 fit. General guidance, not legal advice.

CSF 2.0GovernIdentifyProtectDetectRespondRecover

Last updated Published by TryTrustableNot legal advice

Short answer

The NIST CSF (Cybersecurity Framework) is a voluntary framework from the US National Institute of Standards and Technology that describes cybersecurity outcomes an organisation should achieve, without prescribing how. Version 2.0, published on 26 February 2024, organises 106 outcomes (subcategories) into 22 categories under six functions: Govern, Identify, Protect, Detect, Respond and Recover. You use it by writing a current profile, a target profile, and a plan to close the gap. There is no NIST CSF certification.

01

What is the NIST CSF?

The NIST Cybersecurity Framework is published by the US National Institute of Standards and Technology. Version 1.0 was written for critical infrastructure; CSF 2.0, published on 26 February 2024, is explicitly for organisations of any size or sector. It has three parts: the Core (the functions, categories and subcategories of outcomes), Organizational Profiles (where you are and where you want to be against the Core) and Tiers (how rigorous your risk governance and management are).

The CSF says what to achieve, not how. For the how, it points to Informative References such as NIST SP 800-53 and ISO 27001, and to Implementation Examples and Quick Start Guides on the NIST website.

02

The six NIST CSF 2.0 functions

CSF 2.0 added Govern as a sixth function. It pulls risk strategy, roles, policy, oversight and supply chain risk management into one place, and NIST describes it as informing how the other five functions are prioritised.

FunctionWhat NIST says it coversCategories
Govern (GV)The cybersecurity risk management strategy, expectations and policy are established, communicated and monitoredOrganizational Context, Risk Management Strategy, Roles and Responsibilities, Policy, Oversight, Cybersecurity Supply Chain Risk Management
Identify (ID)Current cybersecurity risks are understoodAsset Management, Risk Assessment, Improvement
Protect (PR)Safeguards to manage cybersecurity risks are usedIdentity Management, Authentication and Access Control; Awareness and Training; Data Security; Platform Security; Technology Infrastructure Resilience
Detect (DE)Possible cybersecurity attacks and compromises are found and analysedContinuous Monitoring, Adverse Event Analysis
Respond (RS)Actions regarding a detected cybersecurity incident are takenIncident Management, Incident Analysis, Incident Response Reporting and Communication, Incident Mitigation
Recover (RC)Assets and operations affected by an incident are restoredIncident Recovery Plan Execution, Incident Recovery Communication

22 categories and 106 subcategories in total. Source: NIST CSWP 29, CSF 2.0 (26 February 2024).

03

What changed from NIST CSF 1.1 to 2.0?

  • Govern function added, making leadership and strategy an explicit outcome rather than an assumption.
  • Broader audience: all organisations, not just critical infrastructure.
  • Supply chain risk expanded and moved into Govern (GV.SC).
  • Restructured categories: for example Identity Management, Authentication and Access Control (PR.AA) and Platform Security (PR.PS) replace several 1.1 categories.
  • New supporting resources: Implementation Examples, Quick Start Guides and Community Profiles.
04

NIST CSF tiers

TierNameIn practice
1PartialAd hoc, reactive; limited awareness of cyber risk at the organisational level
2Risk InformedRisk practices approved by management but not established as organisation-wide policy
3RepeatableFormally approved practices expressed as policy, updated regularly as risks change
4AdaptivePractices adapt from lessons learned and predictive indicators; cyber risk is part of the culture

Tiers describe the rigour of governance and risk management. NIST says they complement your risk methodology rather than replace it, and are not a maturity score you must climb.

05

NIST CSF profiles: current, target and community

An Organizational Profile describes your posture in terms of Core outcomes. A Current Profile records which outcomes you achieve today and how well; a Target Profile records the outcomes you have chosen to prioritise. A Community Profile is a baseline published for a sector or use case, which you can adopt as the starting point for your target.

NIST's own steps are: scope the profile, gather information, create it, analyse the gaps between current and target, and implement an action plan, which NIST suggests can take the form of a risk register. Then repeat.

06

NIST CSF vs ISO 27001

NIST CSF 2.0ISO/IEC 27001:2022
What it isA voluntary framework of outcomesAn international standard with requirements for an information security management system (ISMS)
CertificationNone. You can be assessed against it, but there is no official certificateCertification by an accredited certification body, with surveillance audits and recertification
Structure6 functions, 22 categories, 106 subcategoriesClauses 4 to 10 (the management system) plus Annex A with 93 controls in four themes
How you use itCurrent and target profiles, a gap analysis and an action planScope, risk assessment, risk treatment, Statement of Applicability, internal audit, management review
Who asks for itUS organisations, boards, US public sector and critical infrastructure buyersCustomers worldwide, especially in Europe, the UK, the Middle East and Asia
Cost to adoptFree to download and useThe standard is purchased; certification audits are paid

They overlap heavily. Many teams run ISO 27001 as the management system and report progress to the board in CSF functions.

If customers ask for proof, ISO 27001 certification or a SOC 2 report is usually what they want; a CSF self-assessment rarely replaces them. If the board wants a clear picture of cyber risk, CSF functions and tiers are easier to read than a Statement of Applicability. Using both is common and the control work is largely the same.

07

Is there a NIST CSF certification?

No. NIST does not certify organisations against the CSF and there is no accredited certification scheme for it. Third parties can assess you against it and you can report your profiles, but anyone offering an official "NIST CSF certificate" is describing their own attestation.

08

Where NIST SP 800-53 and SP 800-171 fit

NIST SP 800-53 is a catalogue of security and privacy controls, used as the control baseline for US federal information systems and by many other organisations. Revision 5 was published in September 2020, and NIST issued Release 5.2.0 in August 2025. Where the CSF lists outcomes, 800-53 lists detailed controls that can achieve them.

NIST SP 800-171 sets requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems, and is applied through federal contracts. Revision 3 was published in May 2024, with assessment procedures in SP 800-171A. US defence contractors meet it through the Department of Defense's CMMC programme; check which revision your contract specifies.

In short: CSF for the overall programme and board reporting, 800-53 for a detailed control catalogue, 800-171 only if you handle CUI under a US federal contract.

09

NIST CSF compliance with TryTrustable

NIST CSF 2.0 is one of the frameworks with requirements modelled in the platform, on the same control library as your other frameworks. Here is what that means today, and what is not covered.

In TryTrustableWhat it does today
NIST CSF 2.0 modelledRequirements across all six functions, from GV.RM (risk management strategy) and GV.SC (supply chain) to RC.RP (recovery plan execution)
Shared controlsEach CSF requirement maps to controls in the same library used for SOC 2, ISO 27001, NIS2 and GDPR, so a passing control counts for all of them. See cross-framework mapping
EvidenceCollected automatically, read-only, from GitHub, AWS and GCP into a hash-chained evidence ledger; other evidence is uploaded by your team
Risk registerLikelihood x impact with residual risk derived from linked controls: the action plan CSF profiles point to. See risk register
Not modelledNIST SP 800-53, NIST SP 800-171 and CMMC are not modelled frameworks in the product

NIST AI RMF is also modelled; see the NIST AI RMF guide.

Questions

The things people ask us

Is the NIST CSF mandatory?

Not for private companies in general. It is voluntary guidance, although customers, regulators in some sectors and US public sector contracts may expect you to align with it.

What are the six functions of NIST CSF 2.0?

Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in version 2.0.

What is the difference between NIST CSF and ISO 27001?

The CSF is a voluntary framework of outcomes with no certification. ISO 27001 is an international standard for an information security management system that you can be certified against by an accredited body. The control work overlaps heavily.

Can you get NIST CSF certified?

No. There is no official NIST CSF certification. You can be assessed against the framework by a third party and report your current and target profiles.

What is the difference between NIST CSF and NIST 800-53?

The CSF describes outcomes for a whole cybersecurity programme. SP 800-53 is a detailed catalogue of security and privacy controls, used as the baseline for US federal systems, that can be used to achieve those outcomes.

Does TryTrustable support NIST CSF 2.0?

Yes. NIST CSF 2.0 requirements are modelled across all six functions and mapped to the shared control library. NIST SP 800-53, SP 800-171 and CMMC are not modelled.

Book a walkthrough

Map NIST CSF 2.0 onto the controls you already run.

Thirty minutes: your current profile against CSF, ISO 27001 and SOC 2 on one control library.