NIST CSF 2.0 explained: the six Functions
The NIST Cybersecurity Framework (CSF) is one of the most quoted names in security, and one of the most misunderstood. It is not a certification, and it is not a list of technologies to buy. It is a taxonomy of outcomes, statements of what good cybersecurity looks like, that you map to your own controls, risks and priorities. Version 2.0, published in February 2024 as NIST CSWP 29, widened its audience from critical infrastructure to organisations of every size and sector.
Think of CSF less as an exam and more as a shared vocabulary. It gives your engineers, your executives and your customers one way to describe where your programme is strong, where it is thin, and where you are heading next.
The six Functions
CSF 2.0 organises everything under six top-level Functions. The headline change in 2.0 is the first one, Govern, which is entirely new:
- Govern (new in 2.0): the cyber-risk strategy, roles, policy and oversight that steer everything else. This is the Function that puts cybersecurity on the leadership table.
- Identify: understand the assets, data, suppliers and risks you are actually protecting.
- Protect: the safeguards, from access control to training, that reduce the likelihood of an incident.
- Detect: find the anomalies and events that signal something is wrong.
- Respond: contain, analyse and communicate during an incident.
- Recover: restore what was affected and learn from it.
Adding Govern was NIST saying the quiet part out loud: most security programmes do not fail on the firewalls, they fail on ownership, strategy and oversight.
Tiers and Profiles: the two dials
Under the six Functions sit 22 Categories and 106 Subcategory outcomes, and you assess yourself against them with two tools. Implementation Tiers, from Tier 1 (Partial) up to Tier 4 (Adaptive), describe how rigorous and risk-informed your practices are. Organizational Profiles capture where you are (a Current Profile) and where you need to be (a Target Profile). The gap between the two is, quite literally, your prioritised action plan.
That is the whole trick of CSF. You are never scored pass or fail. You describe your current outcomes honestly, set the outcomes you need, and work the difference.
Why it pairs so well with ISO 27001
Because the 106 Subcategories are outcomes rather than prescriptions, they crosswalk cleanly to ISO/IEC 27001:2022 and other standards. If you already run 27001, most of the evidence you collect can be pointed straight at the matching CSF Subcategories. In Compliance One the full CSF 2.0 outcome library ships ready to score against Current and Target Profiles, cross-mapped to your 27001 controls, and the Profile gap turns into an owned, prioritised plan. The framework stops being a giant spreadsheet and becomes a picture leadership can read.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.