Compyl

The NIST CSF 2.0 Implementation Guide

June 08, 2026
Framework · NIST CSF 2.0

The NIST CSF 2.0 Implementation Guide

By Compyl ResearchUpdated June 20264 min read

The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary framework that organizes cybersecurity into six functions — Govern, Identify, Protect, Detect, Respond, and Recover — to help any organization understand, prioritize, and communicate its cyber risk.

Key takeaways
  • CSF 2.0 has six functions: Govern, Identify, Protect, Detect, Respond, Recover.
  • Govern is new in 2.0 — it elevates cybersecurity governance and supply-chain risk to a top-level function.
  • It’s a flexible outcome framework, not a rigid control list — you tailor it with Tiers and Profiles.
  • It maps cleanly to other standards, so it works as an organizing layer over SOC 2, ISO 27001, and more.

The six functions

Function Outcome
Govern (GV) Establish and monitor the cyber risk strategy, roles, policy, and supply-chain risk
Identify (ID) Understand assets, the environment, and risks
Protect (PR) Safeguards: access, awareness, data and platform security
Detect (DE) Find cybersecurity events through continuous monitoring
Respond (RS) Act on detected incidents
Recover (RC) Restore operations and communicate during recovery

Tiers and Profiles

Tiers (1–4: Partial → Adaptive) describe how rigorous and risk-informed your practices are. Profiles describe your “current” vs. “target” state, so you can prioritize the gap between where you are and where you want to be. Together they make CSF adaptable to any size and maturity.

How to implement CSF 2.0

  1. Establish governance (Govern). Set your risk strategy, roles, and policy — and treat supply-chain risk as first-class.
  2. Build a current Profile. Assess where you stand against the function/category outcomes.
  3. Define a target Profile. Set the outcomes you need based on your risk and obligations.
  4. Prioritize the gaps into an action plan, weighted by risk.
  5. Implement and monitor. Roll out improvements and verify them continuously.
  6. Communicate. Use the framework’s common language to report posture to leadership and partners.

Where it fits with other frameworks

CSF 2.0 is an excellent organizing layer. Because it maps to controls in ISO 27001, SOC 2, and NIST SP 800-53, you can manage one set of controls and report against several frameworks. Pairing CSF’s Detect function with continuous controls monitoring turns its outcomes into live, verifiable signals.

Frequently asked questions

What are the six functions of NIST CSF 2.0?
Govern, Identify, Protect, Detect, Respond, and Recover. Govern is the function added in the 2.0 release.
What's new in CSF 2.0 vs. 1.1?
The addition of the Govern function, a stronger emphasis on supply-chain risk, and expanded scope to all organizations, not just critical infrastructure.
Is NIST CSF mandatory?
It's voluntary, but widely adopted and frequently referenced in contracts and regulation as a benchmark for cybersecurity maturity.
How is CSF different from NIST 800-53?
CSF is a high-level, outcome-based framework for organizing and communicating cyber risk; 800-53 is a detailed control catalog. CSF can be implemented using 800-53 (or other) controls.

See NIST CSF run on your own data

Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.

Request a demo →

About this guide. By Compyl Research, referencing NIST CSF 2.0 (Feb 2024). Compyl is an AI-powered, agentic GRC platform built by CISOs.

Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies