NIST CSF 2.0 Cyber risk governance and implementation hub
Published by NIST on February 26, 2024, CSF 2.0 is guidance for managing cybersecurity risk through a common taxonomy of outcomes. Organizations can adopt it voluntarily, while laws, policies, or contracts may separately require or reference its use. The CSF itself is not a certification scheme or proof of compliance.
Address the six Functions concurrently. Implementation Examples are non-exhaustive illustrations, Informative References are mappings whose coverage can be partial, and characterize the rigor of risk governance and management practices.
Define the organizational, system, service, supplier, or threat-scenario scope; use GOVERN to establish context and direction; and address all six Functions together across relevant IT, operational technology, Internet of Things, cloud, mobile, and AI environments. Build a from outcomes achieved now, select and prioritize a , analyze the gaps, and choose actions and evidence that fit the organization's risks and requirements.
Choose the next CSF 2.0 decision
New to the framework? Start with what CSF 2.0 is, what it does not require by itself, and how the six Functions work together. Then build Profiles, choose implementation evidence, and use comparisons only after your scope and desired outcomes are clear.
Start here: framework, scope, and governance
Understand the Core, why GOVERN informs the other five Functions, and how NIST guidance differs from a certification or a legal, contractual, or policy requirement that separately calls for CSF use.
Profiles, gaps, and priorities
Define a useful boundary, gather policies and risk information, document the Current Profile, select and prioritize the Target Profile, and turn the gap analysis into an action plan.
Implementation and evidence
Select context-appropriate actions, connect evidence to specific Subcategory outcomes, and check the scope of each mapping instead of treating examples or references as complete control baselines.
Compare CSF with controls, standards, and RMF
See when CSF outcomes can organize risk communication and when a control catalog, management-system standard, or system life-cycle process supplies a different kind of structure.
Answer a focused implementation question
Use the FAQ for direct answers about Tiers, GOVERN, supplier risk, board reporting, Profiles, examples, and evidence mapping.
Turn selected CSF outcomes and Profile gaps into owned work
Keep the Profile scope, selected outcomes, supporting evidence, gap decisions, owners, and review triggers together so teams can explain the current posture, the desired state, and the reason for each priority.
- Define whether the Profile covers the enterprise, a business unit, a system, a supplier relationship, or a specific threat scenario.
- Record Current and judgments at outcome level and preserve the evidence and assumptions behind them.
- Prioritize gaps using mission objectives, stakeholder expectations, the threat landscape, requirements, risk appetite and tolerance, and available resources.
- Set organization-defined review points and update the Profile and action plan when risks, technologies, requirements, scope, or implementation evidence materially change; CSF 2.0 itself sets no universal certification deadline or recurring assessment interval.