Skip to main content
Category: Standards and Frameworks

NIST Cybersecurity Framework 2.0

Also known as: NIST CSF 2.0, NIST CSF 2.0, Cybersecurity Framework 2.0, CSF 2.0, NIST CSWP 29
Simply put

The NIST Cybersecurity Framework 2.0 is a set of voluntary guidance published by the U.S. National Institute of Standards and Technology to help organizations manage and reduce cybersecurity risk. It is designed to be used by industry, government agencies, and other organizations of varying sizes and sectors. Unlike a certification or an attestation, it is a reference framework rather than something an organization is formally certified or audited against.

Formal definition

NIST CSF 2.0, published February 26, 2024 as NIST Cybersecurity White Paper (CSWP) 29, provides guidance to industry, government agencies, and other organizations for managing cybersecurity risk. It functions as a voluntary framework and reference resource rather than a certifiable standard or an examination framework; organizations are not certified against it in the way ISO/IEC 27001 certification is granted, nor is it the subject of a CPA attestation as with SOC 2. NIST maintains supplementary resources for CSF 2.0, including Informative References that map framework outcomes to other standards and guidance, with a Quick-Start Guide describing how to find, filter, and apply those references. Mappings between CSF 2.0 and frameworks such as SOC 2 or ISO 27001 may be possible but are typically partial, and alignment with CSF 2.0 does not by itself satisfy the requirements of those other frameworks.

Why it matters

Cybersecurity risk cuts across organizations of every size and sector, but many teams lack a common vocabulary for describing what they are trying to achieve and how mature their efforts are. NIST CSF 2.0 matters because it offers a widely recognized, voluntary reference point that helps industry, government agencies, and other organizations frame cybersecurity outcomes in consistent terms. Because it is guidance rather than a certifiable standard or an examination framework, it can be adopted flexibly and used to organize risk-management activities without committing an organization to a particular audit or certification pathway.

For compliance and GRC professionals, CSF 2.0 is often valuable as a structuring layer that sits alongside the frameworks they are formally assessed against. NIST maintains supplementary resources, including Informative References that map framework outcomes to other standards and guidance, which can help teams see conceptual relationships between CSF 2.0 and frameworks such as SOC 2 or ISO/IEC 27001. This can support internal planning and communication with leadership, even though the framework itself does not produce a report or a certificate.

It is important to keep the boundaries clear. Alignment with CSF 2.0 does not by itself satisfy the requirements of SOC 2 or ISO 27001, and mappings between CSF 2.0 and those frameworks are typically partial rather than one-to-one. Organizations should treat CSF 2.0 as a reference resource for managing and reducing cybersecurity risk, and rely on the specific applicable frameworks when a formal attestation or certification is required.

Who it's relevant to

GRC and Compliance Managers
Compliance managers can use CSF 2.0 as a voluntary structuring reference to organize cybersecurity risk-management activities and communicate them to leadership. Because it is guidance rather than a certifiable standard, it is often used alongside the frameworks an organization is formally assessed against, with the understanding that alignment with CSF 2.0 does not by itself satisfy SOC 2 or ISO 27001 requirements.
Security Engineers and Architects
Security engineers can draw on CSF 2.0 and its Informative References to relate cybersecurity outcomes to other standards and guidance, using the Quick-Start Guide to find, filter, and apply those references. This can support internal design and planning work, though the framework produces no certificate or attestation on its own.
Auditors and Assessors
Auditors and assessors working under SOC 2 or ISO 27001 may encounter CSF 2.0 as a reference an organization uses to frame its risk-management approach. It is important to recognize that CSF 2.0 is not a framework organizations are audited or certified against, and that any mapping between it and formal frameworks is typically partial.
Government Agencies and Cross-Sector Organizations
CSF 2.0 is designed for use by industry, government agencies, and other organizations of varying sizes and sectors. Its voluntary, flexible nature makes it useful as a common reference point for describing and prioritizing cybersecurity outcomes across diverse environments.

Inside NIST CSF 2.0

Core Functions
NIST CSF 2.0 organizes cybersecurity outcomes into a set of high-level Functions. The 2.0 revision added Govern to the previously established Identify, Protect, Detect, Respond, and Recover Functions, elevating governance, roles, and risk management strategy to a first-class element of the framework.
Govern Function
Introduced in the 2.0 revision, this Function addresses organizational context, risk management strategy, roles and responsibilities, policy, and oversight. It emphasizes that cybersecurity is a component of enterprise risk management rather than a purely technical concern.
Categories and Subcategories
Each Function is broken down into Categories and, beneath those, Subcategories that express specific desired outcomes. These outcome statements are intended to be technology- and sector-neutral so organizations can apply them according to their own context.
Profiles
Profiles describe an organization's current or target cybersecurity posture by selecting the outcomes relevant to its mission, risk tolerance, and resources. They support gap analysis between a Current Profile and a Target Profile.
Tiers
Implementation Tiers characterize the rigor and maturity of an organization's cybersecurity risk management practices along a range, helping contextualize how outcomes are pursued rather than prescribing a required level.
Voluntary, Non-Certifiable Framework
NIST CSF 2.0 is a voluntary framework of guidance, not a certifiable standard. Unlike ISO/IEC 27001, there is no accredited certification body that issues a certificate against it, and unlike SOC 2, it does not result in a CPA attestation report.

Common questions

Answers to the questions practitioners most commonly ask about NIST CSF 2.0.

Does achieving NIST CSF 2.0 alignment mean my organization is certified against the framework?
No. NIST CSF 2.0 is a voluntary framework rather than a certifiable standard, and there is no accredited certification issued for it in the way ISO/IEC 27001 certification is issued by an accredited certification body. Organizations use the framework to assess and improve their cybersecurity posture and can describe their alignment, but this typically does not produce a certificate or an attestation report. If you require a formal third-party outcome, that would generally come through a separate mechanism such as an ISO 27001 certification or a SOC 2 examination performed by a licensed CPA firm.
Can I use NIST CSF 2.0 as a direct substitute for SOC 2 or ISO 27001?
Not directly. NIST CSF 2.0 serves a different purpose than a SOC 2 report or an ISO 27001 certification, and using one does not automatically satisfy the others. Mapping between the framework and either SOC 2 Trust Services Criteria or ISO 27001 clauses and Annex A controls is possible but partial, so alignment with the framework does not on its own produce a SOC 2 attestation or an ISO 27001 certification. Many organizations use the framework alongside these other efforts rather than as a replacement, depending on their objectives and stakeholder expectations.
How do I decide which parts of NIST CSF 2.0 apply to my organization?
Scoping typically begins by identifying the systems, services, and business functions you want to address, then using the framework's structure to organize your current and target states. Because the framework is designed to be adaptable, the specific outcomes you prioritize depend on your risk profile, sector, and organizational objectives rather than a fixed mandatory list. In most engagements, organizations tailor their use to their own context, and the boundaries you set will shape which activities and outcomes are considered in scope.
How does NIST CSF 2.0 relate to a formal risk assessment?
The framework is generally used to inform and organize risk-based decisions rather than to replace a dedicated risk assessment process. In practice, organizations often pair their use of the framework with their existing risk management activities, which helps prioritize which outcomes to pursue and how. If you also maintain an ISO 27001 ISMS, note that its clauses require a risk assessment and a Statement of Applicability that drives Annex A control selection; the framework can complement that work but does not, on its own, satisfy those distinct ISMS requirements.
Who within an organization is typically responsible for implementing NIST CSF 2.0?
Responsibility usually spans multiple roles, and the framework is often used by GRC professionals, security engineers, and leadership together rather than by a single owner. Governance-related activities commonly involve senior stakeholders, while operational outcomes are typically addressed by security and IT teams. The exact allocation depends on your organization's size, structure, and how you choose to integrate the framework into existing programs, so there is no single mandatory ownership model.
How should I document my use of NIST CSF 2.0 to support other compliance efforts?
Documentation approaches vary, but organizations often record their current state, target state, and prioritized activities so the work can be referenced by other programs. Because mapping to SOC 2 or ISO 27001 is partial, it is generally helpful to maintain clear records of how your framework activities relate to the specific Trust Services Criteria or ISO 27001 clauses and Annex A controls you are pursuing. Keep in mind that such documentation supports internal alignment and does not by itself produce a SOC 2 report or an ISO 27001 certification, both of which require their respective independent processes.

Common misconceptions

An organization can become 'certified' in NIST CSF 2.0 the way it certifies to ISO/IEC 27001.
NIST CSF 2.0 is voluntary guidance and is not certifiable. There is no accredited certification body issuing certificates against it, and it produces neither an ISO-style certification nor a SOC 2-style attestation report. Any assurance around its use typically comes from internal assessment or a separate engagement.
Adopting NIST CSF 2.0 automatically satisfies SOC 2 or ISO/IEC 27001 requirements.
Mapping between NIST CSF 2.0 and other frameworks is possible but partial. Satisfying the CSF's outcomes does not automatically meet the Trust Services Criteria examined in a SOC 2 report or the ISMS requirements in clauses 4 through 10 of ISO/IEC 27001. Each framework has its own scope, evidence expectations, and assessment path.
The framework prescribes specific mandatory controls that every organization must implement.
NIST CSF 2.0 expresses desired outcomes at the Subcategory level rather than mandating a fixed control set. Organizations typically select and prioritize outcomes through Profiles based on their mission, risk tolerance, and resources, so what is emphasized varies by context.

Best practices

Begin by establishing a Current Profile and a Target Profile so that gaps between existing and desired cybersecurity outcomes can be identified and prioritized based on risk.
Give explicit attention to the Govern Function introduced in the 2.0 revision, ensuring cybersecurity roles, policies, and risk management strategy are integrated into enterprise risk management.
Use Implementation Tiers to characterize the rigor of your risk management practices rather than treating a higher Tier as a mandatory target.
Where you also pursue SOC 2 or ISO/IEC 27001, map CSF outcomes to those frameworks deliberately and treat the mapping as partial rather than assuming one satisfies another.
Document how each selected Subcategory outcome is met so the framework's guidance can support, but not replace, any separate attestation or certification engagement.
Revisit Profiles periodically as scope, risk tolerance, and resources change, since the outcomes relevant to your organization can shift over time.