Artifact GuideGLOBALNIST CSF 2.0

NIST CSF 2.0 Core Functions Guide

Use the six Functions as connected groups of cybersecurity outcomes, not as project phases or six summary scores. GOVERN sets context and direction; all six Functions inform the organization's Current and Target Profiles.

Choose relevant outcomes at Category and Subcategory level, assign accountable owners, identify context-appropriate implementation and evidence, and track gaps through the Profile action plan.

Author
Sorena AI
Published
Feb 26, 2024
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Feb 26, 2024
Updated Jul 24, 2026
Overview

Published in NIST CSF 2.0 on February 26, 2024, the is a sector-, country-, and technology-neutral taxonomy of cybersecurity outcomes arranged as Functions, Categories, and Subcategories. Its six Functions - GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER - are not sequential project phases or a checklist. Address them concurrently: GOVERN informs priorities for the other five, while the full set covers preparation, protection, detection, incident handling, and restoration.

Section 1

What each Function covers

Functions are the highest level of the Core. CSF 2.0 divides them into 22 Categories and then into more specific outcomes. Use the Function level to communicate the shape of the program; use Categories and Subcategories to make implementation, ownership, evidence, and gap decisions.

The Core applies to all information and communications technology used by the organization, including information technology, operational technology, and Internet of Things, as well as cloud, mobile, and artificial intelligence environments. A specific can cover the entire organization or a narrower boundary such as financial systems, a supplier relationship, or a ransomware scenario; exclusions should be explicit so Function-level claims are not read as enterprise-wide.

  • GOVERN (GV), six Categories: understand organizational context; establish risk strategy, roles, policy, and oversight; and manage cybersecurity supply-chain risk.
  • IDENTIFY (ID), three Categories: manage assets, assess current cybersecurity risk, and identify improvements across all Functions.
  • PROTECT (PR), five Categories: manage identity and access, awareness and training, data security, platform security, and technology infrastructure resilience.
  • DETECT (DE), two Categories: continuously monitor assets and analyze adverse events to determine whether incidents have occurred.
  • RESPOND (RS), four Categories: manage, analyze, report, communicate about, and mitigate declared incidents.
  • RECOVER (RC), two Categories: execute recovery plans, restore affected assets and operations, and coordinate recovery communications.
Section 2

Run the Functions concurrently

The order and visual size of Functions, Categories, and Subcategories do not establish sequence or importance. NIST says GOVERN, IDENTIFY, PROTECT, and DETECT actions should happen continuously. RESPOND and RECOVER capabilities should remain ready and operate when incidents occur.

Dependencies run in both directions. Asset and risk information from IDENTIFY shapes safeguards under PROTECT. Planning and testing under GOVERN and IDENTIFY support DETECT, RESPOND, and RECOVER. Incident and exercise findings feed the IDENTIFY Improvement Category and can change governance priorities, policies, and the Target Profile.

  • Set the boundary: name the organization, business unit, system, service, supplier relationship, technology environment, or threat scenario in scope.
  • Gather context: mission objectives, stakeholder expectations, dependencies, requirements, threat information, risk appetite and tolerance, business impacts, policies, tools, and work roles.
  • Select outcomes: document relevant Subcategories, the current state, the desired state, priorities, assumptions, and any outcome left outside the Profile.
  • Preserve the connection: link each selected outcome to its owner, implementation, evidence, gap decision, and reassessment trigger.
Section 3

Assign evidence at outcome level

The CSF describes desired outcomes but does not prescribe how to achieve them. Select evidence that shows the outcome for the defined scope and period. A policy may support a GOVERN outcome, for example, but technical records, tests, and monitoring may be needed to support related PROTECT or DETECT outcomes.

The examples below are evidence choices, not NIST requirements. The appropriate record depends on the selected , technology, risk, external requirements, and the conclusion the organization needs to support.

  • GOVERN: approved risk strategy, appetite and tolerance statements, assigned authorities, current policies, oversight records, and supplier-risk decisions.
  • IDENTIFY: asset and supplier inventories, data-flow records, risk assessments, vulnerability records, risk-response decisions, test findings, and improvement actions.
  • PROTECT: identity and access records, training completion, data-protection configurations, backup tests, platform baselines, change records, and resilience tests.
  • DETECT: monitoring coverage, alert logic, event correlation, analysis records, incident criteria, and records showing when an adverse event was declared an incident.
  • RESPOND: incident declarations, triage and escalation records, investigation provenance, required notifications, stakeholder communications, containment, and eradication records.
  • RECOVER: recovery initiation criteria, restoration priorities, verified backups, restored-asset integrity checks, operational acceptance, closure records, and recovery communications.
Section 4

Avoid Function-level shortcuts

A Function-level percentage can hide materially different outcomes, risks, and evidence. If the organization uses scores, retain the -level judgments, weighting method, scope, evidence, exceptions, and uncertainty. Report significant gaps directly instead of relying on an average.

Keep the Core separate from supporting resources. Informative References map relationships to other content and may provide only partial coverage. Implementation Examples illustrate possible actions and are neither exhaustive nor a required baseline.

  • Do not treat GOVERN as a one-time first phase; governance decisions and oversight continue while the other Functions operate.
  • Do not treat RESPOND and RECOVER as dormant documentation; keep the capabilities ready and test or exercise them according to the organization's risks and requirements.
  • Do not infer that a control satisfies an entire because it appears in an Informative Reference.
  • Do not call a Current Profile a failure list or a Target Profile a universal baseline; both depend on the selected scope and organizational context.
  • Do not use Tiers as certification levels. They characterize rigor and can inform Profiles, but they do not replace the organization's risk-management method.
Section 5

Turn the Core into a Profile and action plan

NIST gives a five-step Profile process: scope the Profile, gather information, create it, analyze gaps and create an action plan, then implement the plan and update the Profile. Repeat the process when risks, requirements, technologies, evidence, or organizational context change.

A Current Profile records outcomes achieved or being attempted and how or to what extent they are achieved. A Target Profile contains selected and prioritized desired outcomes. A Community Profile can inform the Target Profile, but the organization still has to tailor it to its own scope, mission, stakeholders, threats, and requirements.

  • Step 1 | Scope | Record the boundary, purpose, stakeholders, assumptions, dependencies, and decision owner.
  • Step 2 | Gather | Collect priorities, resources, risk direction, business impacts, requirements, policies, practices, tools, and work-role information.
  • Step 3 | Profile | At selected Subcategories, record the current state, desired state, priority, owner, evidence, and rationale.
  • Step 4 | Analyze | Compare Current and Target Profiles, assess the risk implications, and create a prioritized action plan with owners and tracked decisions.
  • Step 5 | Implement and update | Complete or revise actions, reassess evidence and outcomes, communicate progress, and update the Profile.
Primary sources

References and citations

nist.gov
Referenced sections
  • Official NIST tool for exploring and exporting the Core, Informative References, and Implementation Examples.
doi.org
Referenced sections
  • Section 3 defines Current, Target, Community, and Organizational Profiles and provides the five-step process for creating, comparing, implementing, and updating them.
Related guides

Explore more topics

How should teams handle evidence mapping under NIST CSF 2.0?
Map policies, configurations, tests, logs, approvals, and operating records to specific NIST CSF 2.0 outcomes without treating a reference or policy as proof of performance.
How should teams handle implementation examples under NIST CSF 2.0?
Use NIST CSF 2.0 Implementation Examples as optional, non-exhaustive ways to help achieve a Subcategory outcome, then tailor and test the chosen practice.
How should teams handle supplier risk under NIST CSF 2.0?
Apply NIST CSF 2.0 supplier-risk outcomes across selection, contracting, monitoring, incident coordination, and relationship exit, with effort based on criticality and risk.
How should teams handle target profiles under NIST CSF 2.0?
Build a NIST CSF 2.0 Target Profile by selecting and prioritizing desired Core outcomes, then turn Current-to-Target gaps into owned risk actions.
How should teams handle tiers under NIST CSF 2.0?
Use NIST CSF 2.0 Tiers to characterize risk governance and management rigor for a defined scope without turning them into certification levels or a universal maturity score.
NIST CSF 2.0 current and target profile template: operating columns and evidence rows
A field-by-field NIST CSF 2.0 Current and Target Profile worksheet for compatible outcome comparisons, evidence, gaps, and action plans.
NIST CSF 2.0 Current vs Target Profile Template
Build a NIST CSF 2.0 Current and Target Profile with a defined scope, outcome-level evidence, priorities, owners, milestones, and reassessment triggers.
NIST CSF 2.0 Evidence Mapping Workflow
Map a NIST CSF 2.0 outcome to evidence, test what the record proves, document gaps, and assign the next risk decision.
NIST CSF 2.0 FAQ: practical implementation questions
Direct answers on NIST CSF 2.0 Tiers, GOVERN, Profiles, supplier risk, Implementation Examples, evidence mapping, and board reporting.
NIST CSF 2.0 GOVERN Function FAQ
Start the NIST CSF 2.0 GOVERN function by naming decision owners, risk strategy, policy expectations, oversight cadence, and supplier-risk accountability before mapping controls.
NIST CSF 2.0 Governance and Metrics Guide
Connect NIST CSF 2.0 GOVERN outcomes to decisions, owners, risk appetite, and metrics without inventing a single maturity score.
NIST CSF 2.0 Implementation Examples Guide
Use NIST CSF 2.0 Implementation Examples as optional prompts, adapt them to one scoped outcome, and define evidence that tests the result.
NIST CSF 2.0 Profile Workshop Template
A fill-in NIST CSF 2.0 Profile workshop template for scope, roles, outcome decisions, evidence gaps, approvals, and follow-up.
NIST CSF 2.0 Profile Workshop Workflow
Prepare and run a NIST CSF 2.0 Profile workshop that produces scoped outcome decisions, evidence requests, and an owned gap plan.
NIST CSF 2.0 Requirements Mapping Guide
Build a traceable mapping from applicable requirements to NIST CSF 2.0 outcomes, controls, evidence, gaps, and owners without treating the mapping as proof of compliance.
NIST CSF 2.0 vs CIS Controls v8.1: Mapping and Gap Analysis
Map CSF 2.0 outcomes to CIS Controls v8.1 safeguards without confusing a crosswalk with implementation evidence or full outcome achievement.
NIST CSF 2.0 vs CIS Controls v8.1: Which to Use
Choose CSF 2.0 for outcome-based risk governance, CIS Controls v8.1 for prioritized safeguards, or combine them with separate claims and evidence.
NIST CSF 2.0 vs ISO/IEC 27001:2022: Which to Use
Choose CSF 2.0 for outcome-based cyber-risk governance or ISO/IEC 27001:2022 for a requirements-based ISMS and possible certification.
NIST CSF 2.0 vs NIST RMF: practical side-by-side comparison
Decide when to use NIST CSF 2.0 outcomes and Profiles, when to use the seven-step NIST RMF process, and how to connect their evidence.
NIST CSF 2.0 vs SP 800-53 Rev. 5: control mapping and coverage gaps
Map CSF 2.0 outcomes to SP 800-53 Rev. 5 controls while preserving scope, tailoring, assessment, and partial-coverage limits.
NIST CSF 2.0 vs SP 800-53 Rev. 5: Which to Use
Choose CSF 2.0 for outcome-based cybersecurity governance or SP 800-53 Rev. 5 for control selection, tailoring, implementation, and assessment.
NIST CSF 2.0: step-by-step workflow for building current and target profiles
Build compatible NIST CSF 2.0 Current and Target Profiles, analyze each gap, and turn the comparison into a risk-informed action plan.
What should an NIST CSF 2.0 Current Profile include to be useful for audits and risk decisions?
A useful CSF 2.0 Current Profile should show current outcomes, accountable owners, supporting evidence, known gaps, dependencies, and review dates. It should be specific enough that a reviewer can understand what is true today without re-interviewing every team.
Which NIST CSF 2.0 metrics are useful for board and executive reporting?
Use board-level CSF 2.0 metrics that show risk decisions, business impact, target-profile gaps, and progress against priorities. Avoid only reporting control counts; executives need to see whether cybersecurity outcomes are improving in the context of organizational objectives.