What is the NIST CSF?
The Cybersecurity Framework was developed by the National Institute of Standards and Technology (NIST) — an agency of the US Department of Commerce. The first version was created in 2014 under a presidential executive order on critical infrastructure protection; version 1.1 was published in 2018, and the current version 2.0 in February 2024. The CSF is neither a law nor a certifiable standard: it is a free, voluntary framework that organises desired cybersecurity outcomes while leaving the organisation free to choose how to achieve them.
The framework core (CSF Core) consists of six functions divided into categories and subcategories — over a hundred subcategories in total, each describing a concrete outcome, for example “hardware assets are inventoried”. Version 2.0 introduced two major changes: the new Govern function (governance, risk strategy, roles, oversight and supply chain) and an expanded audience — from critical infrastructure to all organisations regardless of size or sector. NIST publishes a rich ecosystem around the framework: implementation examples, quick start guides and mappings to other standards (informative references).
Who is it for?
The CSF is voluntary and universal — any organisation can adopt it, from a startup to a critical infrastructure operator. In the United States it is the de facto common language of the market: sector regulators, cyber insurers, corporate customers running due diligence, and boards expecting an understandable maturity measure all use it. For US federal agencies the reference point remains the NIST SP 800-53 catalogue, but the CSF serves them as the governance and communication layer.
Outside the US, the CSF is widely used as the backbone of a security programme and as a mapping layer between standards: an organisation can run its programme by the CSF and satisfy ISO 27001, SOC 2, NIS 2 or DORA requirements through mappings. For companies that do not (yet) need certification, the CSF is the fastest way to organise security around a recognised model — without external audit costs.
The six functions of CSF 2.0
The six functions describe the full cybersecurity risk management cycle. The Govern function is cross-cutting — it provides governance and priorities to the other five, which cover understanding, protection, detection, response and recovery respectively.
- Govern (GV) — new in 2.0: organisational context, risk management strategy and risk appetite, roles and leadership accountability, policies, performance oversight, and supply chain risk management.
- Identify (ID): asset inventories (hardware, software, data, flows), risk and vulnerability assessment, and programme improvement based on findings from assessments and incidents.
- Protect (PR): identity and access management (including MFA), training and awareness, data security (encryption, backups), platform security (hardening, patching, secure software development) and infrastructure resilience.
- Detect (DE): continuous monitoring of networks, devices, personnel and providers, and analysis of adverse events up to incident declaration.
- Respond (RS): incident management — triage, root cause and scope analysis, containment and eradication, and stakeholder communication including legally required reporting.
- Recover (RC): executing the recovery plan, verifying backup integrity before use, communicating progress, and formally closing recovery with lessons learned.
Profiles and Tiers — how the CSF measures maturity
The CSF does not impose a single level of requirements — instead it uses Organizational Profiles. The Current Profile describes which framework outcomes the organisation achieves today and to what degree; the Target Profile describes the desired state, derived from business goals, risk appetite and stakeholder requirements. The gap between the profiles defines the action plan and investment priorities. NIST also publishes Community Profiles for industries and scenarios, for example ransomware.
Profiles are complemented by four Implementation Tiers characterising the rigour of risk management practices: Tier 1 — Partial (ad hoc actions), Tier 2 — Risk Informed (risk awareness without full discipline), Tier 3 — Repeatable (formal, repeatable practices) and Tier 4 — Adaptive (continuous adaptation based on data and experience). Tiers describe how the organisation operates as a whole, not a score for individual controls — and not everyone should aim for Tier 4: the target level should follow from the risk profile.
What does adoption look like?
The CSF is not certifiable — there is no certification audit and no “NIST CSF certificate”. Adoption starts with a self-assessment: building the Current Profile (state per subcategory), defining the Target Profile and a gap-closing plan. Maturity is verified internally or through an independent external assessment, increasingly requested by boards, insurers and key customers. Because the framework is outcome-based, the evidence is the same as for ISO 27001 or SOC 2: registers, policies, configurations, logs, test reports.
A typical first iteration — from self-assessment to an approved action plan — takes from a few weeks to three months depending on the organisation’s size. The CSF’s strength is its iterative nature: the profile is refreshed periodically (for example annually), and progress between profiles is a clear measure for the board. Thanks to official mappings, work done in the CSF carries over almost directly to ISO 27001, SOC 2 and the NIST SP 800-53 catalogue.
How does Guardiso help?
Guardiso turns CSF 2.0 from a PDF document into a working programme: a measurable Current Profile, a roadmap to the Target Profile, and evidence collected continuously.
- CSF 2.0 subcategories seeded automatically when you enable the standard — all six functions, with implementation statuses and assigned owners; control statuses act as your Current Profile.
- A per-function self-assessment showing maturity across Govern, Identify, Protect, Detect, Respond and Recover — a ready starting point for defining the Target Profile.
- A risk register with risk appetite and treatment plans — covering the Govern and Identify functions with evidence for the assessor.
- A supplier register with risk assessment and reviews — covering the supply chain category (GV.SC) expanded in 2.0.
- Evidence collected in one place: training, access reviews, restore tests, and an incident register with a response and recovery timeline.
- Cross-mapping to ISO 27001, SOC 2, NIS 2 and NIST SP 800-53 — an outcome achieved in the CSF counts towards overlapping requirements of other frameworks.
- Leadership reports showing progress between successive assessments — a clear maturity measure for the board and customers.
