✨ Standpoint covers NIST CSF 2.0 readiness free for 14 days. Start your free trial →
Standpointby AI Service Pro
Frameworks / NIST CSF 2.0
Security · Voluntary framework

NIST CSF 2.0

The NIST Cybersecurity Framework (CSF) is a voluntary, outcome-based framework for understanding, managing, and reducing cybersecurity risk. Version 2.0, released in 2024, is a significant update: it added a new Govern Function and broadened the framework's audience from critical-infrastructure operators to organizations of every size and sector. If a customer, board, or auditor is asking you to "map to the NIST CSF," here's the plain-language version: what CSF 2.0 is, its six Functions, how Categories and Subcategories fit beneath them, what Tiers and Profiles mean, and how CSF relates to NIST 800-53, ISO 27001…

What
NIST CSF 2.0 — a voluntary framework of cybersecurity outcomes, organized into Functions, Categories and Subcategories (published February 2024).
Who
organizations of any size or sector — not just critical infrastructure.
How it's organized
six Functions — Govern, Identify, Protect, Detect, Respond, Recover — each broken into Categories and Subcategories.
Tiers & Profiles
Tiers (1–4, Partial → Adaptive) describe how rigorous your risk practices are; Profiles capture your Current vs.
// What Standpoint gives you

NIST CSF 2.0 checklist

A Function-by-Function readiness checklist.

Free readiness assessment

See your CSF gaps in minutes.

Map to other frameworks

How CSF lines up with NIST 800-53, ISO 27001 & SOC 2.

// What the framework covers
GovernGAP
IdentifyPARTIAL
ProtectDONE
DetectGAP
RespondPARTIAL
RecoverDONE

Illustrative statuses. Your real assessment is generated from your answers in the app. Standpoint is a self-assessment aid, not legal advice.

// Go deeper

What is the NIST Cybersecurity Framework?

CSF is a framework of outcomes, not a certification and not a prescriptive checklist of technical controls. It describes what good cybersecurity risk management looks like — leaving how you achieve each outcome up to you and the detailed control sets you choose. Produced by the U.S. National Institute of Standards and Technology, CSF gives organizations a shared vocabulary to describe their current posture, set targets, and communicate risk to executives and partners. Because it is high-level, technology-neutral, and public-domain, it has become one of the most widely adopted ways to organize …

What changed in CSF 2.0?

The 2024 update made two headline changes. First, it added a sixth Function, Govern, which pulls cybersecurity into the organization's broader enterprise risk-management and governance decisions — roles, policy, strategy, and oversight now sit at the center of the framework rather than being scattered across it. Second, CSF 2.0 dropped its original critical-infrastructure framing and was rewritten to apply to organizations of all sizes and sectors, with new implementation resources (quick-start guides and reference examples) aimed at smaller teams.

The six Functions

The heart of CSF is its six Functions. They are not sequential steps — they run continuously and concurrently. Here they are in plain language:

Categories and Subcategories

Beneath each Function, CSF gets more specific. Each Function is divided into Categories — groups of related outcomes (for example, under Protect you'll find Identity Management & Access Control, Awareness & Training, and Data Security). Each Category is then broken into Subcategories, the most granular level: concrete, outcome-based statements you can assess yourself against. Subcategories are where CSF connects to detailed control sets: NIST publishes Informative References that map each Subcategory to controls in frameworks such as NIST 800-53, ISO 27001 and others.

Tiers and Profiles

Tier 1 — Partial; Risk management is ad hoc and reactive; limited awareness of cybersecurity risk. Tier 2 — Risk Informed; Risk practices are approved but may not be organization-wide or repeatable. Tier 3 — Repeatable; Formal, organization-wide policies are in place and updated as risk changes. Tier 4 — Adaptive; Practices are risk-informed and continuously improved from lessons learned. CSF adds two tools for tailoring the framework to your organization. Tiers (1 through 4) describe how mature and rigorous your cybersecurity risk practices are — they run from Partial (ad hoc, reactive) up to Adaptive (risk-informed and continuously improving): Profiles describe your organization's alignment to the CSF outcomes. A Current Profile captures where you are today; a Target Profile captures where you want to be. The gap between the two is your improvement plan. Tiers and Profiles are what make CSF flexible: two organizations can both "use CSF" while targeting very different levels of rigor. NIST publications are in the public domain. We summarize the framework here in our own words; consult the official NIST CSF 2.0 (NIST CSWP 29) for authoritative Function, Category, and Subcategory text.

How CSF relates to NIST 800-53, ISO 27001 & SOC 2

They work together. CSF 2.0 is the high-level layer — the outcomes you want to achieve. NIST 800-53 is the detailed catalog of controls you implement underneath CSF to actually reach those outcomes; NIST even publishes mappings from CSF Subcategories to 800-53 controls. ISO 27001 is a certifiable management-system standard and SOC 2 is an attestation against the AICPA Trust Services Criteria — both cover much of the same ground, and because the outcomes map to each other, evidence gathered for one framework advances the others. See the NIST CSF 2.0 crosswalk for the detail.

NIST CSF 2.0 work counts elsewhere too

The crosswalk maps your NIST CSF 2.0 evidence onto the frameworks it overlaps — so you move forward on several at once.

ISO 27001SOC 2NIST 800-53

Get your NIST CSF 2.0 readiness score.

Free to start. No card, no demo wall. You decide what leaves your device.

Run your free check →