The NIST CSF 2.0 Implementation Guide
The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary framework that organizes cybersecurity into six functions — Govern, Identify, Protect, Detect, Respond, and Recover — to help any organization understand, prioritize, and communicate its cyber risk.
- CSF 2.0 has six functions: Govern, Identify, Protect, Detect, Respond, Recover.
- Govern is new in 2.0 — it elevates cybersecurity governance and supply-chain risk to a top-level function.
- It’s a flexible outcome framework, not a rigid control list — you tailor it with Tiers and Profiles.
- It maps cleanly to other standards, so it works as an organizing layer over SOC 2, ISO 27001, and more.
The six functions
| Function | Outcome |
|---|---|
| Govern (GV) | Establish and monitor the cyber risk strategy, roles, policy, and supply-chain risk |
| Identify (ID) | Understand assets, the environment, and risks |
| Protect (PR) | Safeguards: access, awareness, data and platform security |
| Detect (DE) | Find cybersecurity events through continuous monitoring |
| Respond (RS) | Act on detected incidents |
| Recover (RC) | Restore operations and communicate during recovery |
Tiers and Profiles
Tiers (1–4: Partial → Adaptive) describe how rigorous and risk-informed your practices are. Profiles describe your “current” vs. “target” state, so you can prioritize the gap between where you are and where you want to be. Together they make CSF adaptable to any size and maturity.
How to implement CSF 2.0
- Establish governance (Govern). Set your risk strategy, roles, and policy — and treat supply-chain risk as first-class.
- Build a current Profile. Assess where you stand against the function/category outcomes.
- Define a target Profile. Set the outcomes you need based on your risk and obligations.
- Prioritize the gaps into an action plan, weighted by risk.
- Implement and monitor. Roll out improvements and verify them continuously.
- Communicate. Use the framework’s common language to report posture to leadership and partners.
Where it fits with other frameworks
CSF 2.0 is an excellent organizing layer. Because it maps to controls in ISO 27001, SOC 2, and NIST SP 800-53, you can manage one set of controls and report against several frameworks. Pairing CSF’s Detect function with continuous controls monitoring turns its outcomes into live, verifiable signals.
Frequently asked questions
What are the six functions of NIST CSF 2.0?
What's new in CSF 2.0 vs. 1.1?
Is NIST CSF mandatory?
How is CSF different from NIST 800-53?
See NIST CSF run on your own data
Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.
About this guide. By Compyl Research, referencing NIST CSF 2.0 (Feb 2024). Compyl is an AI-powered, agentic GRC platform built by CISOs.