NIST Cybersecurity Framework 2.0: Implementing It in Practice
NIST CSF 2.0 updated the framework that most US enterprise security programs are aligned to. This guide covers what changed, what the framework actually requires, and how organizations use it practically.
By IPA-IAC · 6 min · 11 July 2025

The NIST Cybersecurity Framework (CSF) has been the dominant voluntary framework for US enterprise cybersecurity programs since its initial publication in 2014. Version 2.0, released in February 2024, made the most significant structural changes since the original publication — adding a sixth function, revising the profile and tier system, and expanding the framework’s intended audience beyond critical infrastructure operators.
Understanding what changed and what the framework actually requires is useful context for security leaders who reference CSF in program design, compliance teams that use it for reporting, and practitioners who implement controls against it.
What the Framework Is and Is Not
The NIST CSF is a voluntary framework — it has no legal force in most contexts. It is designed as a common language for communicating about cybersecurity risk, a structure for organizing cybersecurity activities, and a tool for identifying gaps between current and target security postures.
It is not a compliance standard with mandatory requirements, a control specification that tells you exactly what to implement, or an audit framework with pass/fail criteria. Organizations that use CSF as if it were any of those things misunderstand what it is and extract less value from it than organizations that use it for its intended purposes.
The framework describes outcomes, not controls. “Asset management” (ID.AM) describes an outcome — organizations maintain knowledge of their assets and associated security attributes — not a specific implementation. NIST publishes implementation guides and control mappings (including a mapping to NIST SP 800-53) that connect CSF outcomes to specific control requirements. The framework itself leaves implementation decisions to the organization.
The Six Functions
CSF 2.0 organizes cybersecurity activities into six functions that describe the lifecycle of cybersecurity risk management:
GOVERN (GV) — New in CSF 2.0. Establishes, communicates, and monitors the organization’s cybersecurity risk management strategy, expectations, and policy. This function addresses organizational context, risk management strategy, roles and responsibilities, and supply chain risk management. Its addition reflects NIST’s recognition that cybersecurity governance was underrepresented in the original five-function structure.
IDENTIFY (ID) — Understanding assets, risks, and the organization’s current cybersecurity posture. Asset management, risk assessment, business environment analysis, and improvement planning fall in this function.
PROTECT (PR) — Implementing safeguards to limit the impact of cybersecurity events. Access control, awareness and training, data security, platform security, and resilience — including backups and redundancy — are Protect functions.
DETECT (DE) — Identifying cybersecurity events as they occur. Continuous monitoring and anomaly detection activities. CSF 2.0 consolidated the original five categories into two: Continuous Monitoring (DE.CM) and Adverse Event Analysis (DE.AE).
RESPOND (RS) — Taking action following a detected cybersecurity incident. Incident management, analysis, mitigation, and reporting.
RECOVER (RC) — Restoring capabilities affected by a cybersecurity incident. Recovery planning and communications during and after recovery.
What Changed in CSF 2.0
Govern Function Added
The GOVERN function is the most significant structural addition. The original framework implicitly included governance through its Profile and Tier mechanisms, but governance activities were not represented as a first-class function. The explicit addition signals NIST’s recognition that security governance — leadership accountability, risk strategy, supply chain oversight — is not downstream of technical security activities but parallel to them.
Supply Chain Risk Management Elevated
Supply chain risk management (GOVERN.SC) received substantially expanded treatment in CSF 2.0, reflecting the growth in software supply chain attacks and third-party risk incidents since the original publication. The framework now explicitly addresses:
- Selecting, assessing, and managing suppliers and third parties with cybersecurity risk management requirements
- Understanding and managing vulnerabilities introduced through the supply chain
- Including cybersecurity requirements in contracts
Tier and Profile System Revised
The Tier system (Partial → Risk-Informed → Repeatable → Adaptive) was clarified to describe the maturity of cybersecurity risk management practices, not the maturity of cybersecurity controls. Organizations at Tier 1 (Partial) manage cybersecurity risk in an ad hoc way without documented practices; Tier 4 (Adaptive) organizations continuously improve risk management practices based on lessons learned and changing threat landscapes.
Profiles — representations of the outcomes an organization prioritizes given its specific risk context — were given more structured guidance in 2.0. NIST published example Community Profiles for specific sectors as reference starting points.
Building a CSF-Aligned Program
Organizations use CSF in two primary ways: as a gap assessment tool and as a reporting framework.
Gap assessment. A CSF gap assessment maps the organization’s current security practices against the framework’s outcomes, identifying categories where current practices are insufficient relative to target outcomes given the organization’s risk profile. The result is a prioritized set of improvements aligned to the framework.
The process involves:
- Defining the scope — which systems, business lines, or risk areas the assessment covers
- Defining the target profile — which outcomes matter most given the organization’s risk context, industry, and threat environment
- Assessing current state against target outcomes by function and category
- Identifying and prioritizing gaps
The gap assessment output should inform security investment decisions and roadmap planning. Organizations that conduct CSF assessments but do not connect them to budget allocation are doing the assessment work without extracting its value.
Reporting. CSF provides a common structure for communicating cybersecurity posture to board members, executives, regulators, and business partners. Security leaders who can report current posture across the six functions — with metrics that indicate where the organization is strong and where it has material gaps — communicate more effectively with leadership than those who present technical metrics without an organizing framework.
CSF also facilitates comparisons with industry peers and benchmarking against sector-specific implementations (sector-specific profiles and guidance are maintained by NIST and sector-specific agencies).
CSF and Other Frameworks
CSF does not stand alone in most compliance environments. Organizations that use CSF typically also manage requirements under one or more of:
- NIST SP 800-53 — comprehensive control catalog for federal agencies and contractors; NIST publishes a CSF-to-800-53 mapping
- ISO 27001 — international standard for information security management systems; NIST publishes a CSF-to-ISO 27001 mapping
- SOC 2 — AICPA standard for service organizations; maps partially but imperfectly to CSF
- FedRAMP — federal cloud security authorization program; built on 800-53 controls
- HIPAA Security Rule — healthcare-specific; NIST has published a HIPAA mapping
- PCI DSS — payment card industry standard; does not map cleanly to CSF but is used alongside it
Managing multiple frameworks efficiently requires a GRC (governance, risk, and compliance) tool that maintains a unified control framework with mappings to each compliance requirement, so that evidence collected once can satisfy multiple requirements rather than duplicating compliance work.
FAQ
Is CSF compliance mandatory? CSF is voluntary for most organizations. Some sectors have regulatory requirements that reference CSF — certain critical infrastructure sectors have requirements to align with NIST guidance — and some federal contracts require CSF alignment. The most significant mandatory framework for federal contractors is CMMC (Cybersecurity Maturity Model Certification), which has relationships to NIST 800-171 and 800-53 rather than CSF directly.
How does CSF 2.0 relate to Executive Order 14028? Executive Order 14028 (May 2021) directed NIST to develop guidance on software supply chain security, resulting in the NIST Secure Software Development Framework (SSDF) and guidance on software bill of materials (SBOM). The supply chain risk management emphasis in CSF 2.0 is consistent with the direction set by EO 14028, though CSF and SSDF are separate documents with different scopes.
How long does a CSF gap assessment take? A meaningful CSF gap assessment for an enterprise organization typically takes four to eight weeks for a scoped assessment (single business line or major system), or three to six months for an enterprise-wide assessment. The duration depends on the scope, the maturity of existing documentation, and whether the assessment is performed internally or by an external party.