NIST CSF 2.0Free Resource

NIST CSF 2.0 Cyber risk governance and implementation hub

Published by NIST on February 26, 2024, CSF 2.0 is guidance for managing cybersecurity risk through a common taxonomy of outcomes. Organizations can adopt it voluntarily, while laws, policies, or contracts may separately require or reference its use. The CSF itself is not a certification scheme or proof of compliance.

By Sorena AIBased on NIST CSWP 29No signup required
Quick scan
NIST CSF
NIST CSF 2.0 implementation playbook
How to run CSF 2.0 as an operating model.
NIST CSF 2.0 profiles template
Current vs workflow and template guidance.
NIST CSF 2.0 topic guides
Governance + metrics, FAQ, and CSF vs ISO/IEC 27001 comparison.

Address the six Functions concurrently. Implementation Examples are non-exhaustive illustrations, Informative References are mappings whose coverage can be partial, and characterize the rigor of risk governance and management practices.

Key dates
6
Functions
22
Categories
4
Tiers
1
Core taxonomy
What this artifact helps you do
Build a governance-first program
Establish organizational context, risk strategy, roles, policy, oversight, and cybersecurity supply-chain risk management. GOVERN informs how the other five Functions are prioritized and carried out.
Turn outcomes into a roadmap
Scope an , document current and desired outcomes, analyze the differences, and maintain a prioritized action plan with owners and review triggers.
Choose implementation evidence
Work at Category and Subcategory level, then select context-appropriate practices, controls, and records. NIST's examples and mappings inform choices but are not mandatory baselines.
GOVERN
Profiles
Tiers
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 24, 2026

Define the organizational, system, service, supplier, or threat-scenario scope; use GOVERN to establish context and direction; and address all six Functions together across relevant IT, operational technology, Internet of Things, cloud, mobile, and AI environments. Build a from outcomes achieved now, select and prioritize a , analyze the gaps, and choose actions and evidence that fit the organization's risks and requirements.

Recommended reading path

Choose the next CSF 2.0 decision

New to the framework? Start with what CSF 2.0 is, what it does not require by itself, and how the six Functions work together. Then build Profiles, choose implementation evidence, and use comparisons only after your scope and desired outcomes are clear.

1

Start here: framework, scope, and governance

Understand the Core, why GOVERN informs the other five Functions, and how NIST guidance differs from a certification or a legal, contractual, or policy requirement that separately calls for CSF use.

2

Profiles, gaps, and priorities

Define a useful boundary, gather policies and risk information, document the Current Profile, select and prioritize the Target Profile, and turn the gap analysis into an action plan.

4

Compare CSF with controls, standards, and RMF

See when CSF outcomes can organize risk communication and when a control catalog, management-system standard, or system life-cycle process supplies a different kind of structure.

5

Answer a focused implementation question

Use the FAQ for direct answers about Tiers, GOVERN, supplier risk, board reporting, Profiles, examples, and evidence mapping.

Next step

Turn selected CSF outcomes and Profile gaps into owned work

Keep the Profile scope, selected outcomes, supporting evidence, gap decisions, owners, and review triggers together so teams can explain the current posture, the desired state, and the reason for each priority.

What this unlocks
  • Define whether the Profile covers the enterprise, a business unit, a system, a supplier relationship, or a specific threat scenario.
  • Record Current and judgments at outcome level and preserve the evidence and assumptions behind them.
  • Prioritize gaps using mission objectives, stakeholder expectations, the threat landscape, requirements, risk appetite and tolerance, and available resources.
  • Set organization-defined review points and update the Profile and action plan when risks, technologies, requirements, scope, or implementation evidence materially change; CSF 2.0 itself sets no universal certification deadline or recurring assessment interval.