NIST CSF 2.0

NIST CSF 2.0 — six words a director can actually hold in their head.

The NIST Cybersecurity Framework 2.0 is voluntary guidance for organising and describing cybersecurity risk. Six Functions, 22 Categories and 106 Subcategories of outcomes — not controls, and not a certification. You use it by writing down where you are, where you need to be, and what the gap costs. Sentinel is where that assessment, the evidence behind each answer and the movement between reassessments live.

Self-service signup opens shortly — we will set you up in the meantime

FrameworksSentinel interface, reproduced

NIST CSF 2.0

In scope
  • NIST CSF 2.0Available
    59 subcategories in the catalogue
Subcategories
59
outcomes assessed
Register
26
controls, four frameworks
Readiness
76
out of 100

Subcategory outcomes assessed, evidenced and rolled up by Function. Figures are from the example workspace used throughout this site; Northstar Manufacturing Ltd. is fictional, and in that workspace CSF is in the catalogue but not yet activated. Readiness against it is a self-assessed position — nobody certifies against CSF, including NIST.

6
Functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER
59
Subcategories — single outcome statements, mapped onto one control register
31
Subcategories in GOVERN alone, more than in any other Function
Available
In the example workspace the framework is in the catalogue, not yet activated — CSF is self-assessed, never certified

Structure

GOVERN was added because it was the part everyone skipped.

Version 1.1 had five Functions and buried governance as a Category inside IDENTIFY, where it was routinely passed over in favour of the technical work. Version 2.0 promoted it to a Function that wraps the other five, and gave it more Subcategories than any of them.

Six Functions, 22 Categories, 59 Subcategories

GV
GOVERNNew in 2.0

6 Categories · 31 Subcategories

53% of all Subcategories

How cybersecurity risk decisions get made, by whom, and against what appetite. The largest Function by Subcategory count, and it wraps the other five rather than sitting beside them.

Organizational Context · Risk Management Strategy · Roles, Responsibilities and Authorities · Policy · Oversight · Cybersecurity Supply Chain Risk Management

ID
IDENTIFYKnow what you have

3 Categories · 21 Subcategories

36% of all Subcategories

Assets, suppliers, data flows and the risks attached to them — plus Improvement, which in 2.0 collects the lessons from tests, exercises and incidents and feeds them back in.

Asset Management · Risk Assessment · Improvement

PR
PROTECTSafeguards

5 Categories · 22 Subcategories

37% of all Subcategories

The safeguards themselves. Access, training, data protection, platform hardening and the resilience of the infrastructure the rest of it runs on.

Identity Management, Authentication and Access Control · Awareness and Training · Data Security · Platform Security · Technology Infrastructure Resilience

DE
DETECTFind it

2 Categories · 11 Subcategories

19% of all Subcategories

Whether anything is being watched, and whether anyone is analysing what comes back. The smallest Function, and usually the emptiest column in a first honest assessment.

Continuous Monitoring · Adverse Event Analysis

RS
RESPONDAct on it

4 Categories · 13 Subcategories

22% of all Subcategories

Managing, analysing, communicating and containing an incident. Note that reporting and communication is its own Category — regulators and customers are part of the response.

Incident Management · Incident Analysis · Incident Response Reporting and Communication · Incident Mitigation

RC
RECOVERGet back

2 Categories · 8 Subcategories

14% of all Subcategories

Restoring operations and telling people the truth while you do it. Separate from RESPOND on purpose: stopping the bleeding and resuming business are different jobs with different owners.

Incident Recovery Plan Execution · Incident Recovery Communication

6 plus 3 plus 5 plus 2 plus 4 plus 2 — 22 Categories; 31 plus 21 plus 22 plus 11 plus 13 plus 8 — 59 Subcategories. A Subcategory is a single outcome statement, such as an inventory of hardware being maintained. It tells you what has to be true and deliberately not how to make it true, which is what Informative References and the Implementation Examples added in 2.0 are for.

Version 2.0

The counts barely moved. The centre of gravity did.

Published in February 2024, and — unlike 1.1 — written for organisations of any size and sector rather than for critical infrastructure. If you assessed against 1.1, most of your work maps across.

5 → 6
Functions

GOVERN was a Category inside IDENTIFY in 1.1. In 2.0 it wraps the other five.

23 → 22
Categories

Reorganised rather than trimmed. Existing 1.1 work maps across with reasonable effort.

108 → 106
Subcategories

Plus Implementation Examples alongside the Informative References, and Quick Start Guides.

So the real transition task is not remapping. It is populating GOVERN — organisational context, risk management strategy, roles and authorities, policy, oversight and supply chain risk — which for most organisations is new material rather than moved material. NIST publishes the framework, the Quick Start Guides and the Informative References reference tool free of charge.

How it is applied

Profiles are the instrument. Tiers are the calibration.

They do different jobs, and only one of them is optional. Read the rows rather than the labels — most of the bad CSF artefacts in circulation come from swapping these two.

Organizational Profiles
What it is
A record of the Subcategory outcomes you are achieving, for a stated scope. You keep two: Current and Target.
What it measures
Outcomes, Subcategory by Subcategory, with the evidence that supports each answer.
Optional?
No. The profile is the instrument; without one there is nothing to compare.
How it is used
The gap between Current and Target is the action plan. That gap is the entire point.
Where the value is
The second profile. Two dated assessments show movement; one shows an opinion.
A useful shortcut
A Community Profile written for your sector is a good starting draft for a Target — not a finished answer.
Failure mode
A colourful heat map with no stated scope, no target and no owner.
Tiers
What it is
Four descriptions — Partial, Risk Informed, Repeatable, Adaptive — of how rigorous your risk governance and management practices are.
What it measures
Rigour and repeatability — not how many Subcategories are ticked.
Optional?
Yes. Tiers are optional in 2.0, and they can legitimately differ across the organisation.
How it is used
Applied to a profile, to calibrate how much rigour your risk actually justifies.
Where the value is
Choosing a Tier because it fits your risk appetite and budget, not because four is higher than two.
A useful shortcut
Higher is not automatically better. Moving up is justified only when the risk reduction is worth the cost.
Failure mode
A uniform Adaptive ambition across the whole organisation that nobody has costed.

A self-declared Tier means exactly as much as the honesty of the assessment behind it, which is the strongest argument for requiring evidence against every claim.

CSF does not tell you what to buy. It tells you what has to be true, and it gives the person who signs the cheque a structure they can question you against.

Which is also its limit. An outcome statement will not tell you which tool, setting or cadence achieves it — that is what the Informative References, the Implementation Examples and prescriptive sets like the CIS Controls are for.

Readiness path

Six steps, and step five is where most CSF programmes die.

Producing a profile feels like finishing. It is not: an assessment nobody converted into dated, owned work is a document about a problem rather than a response to it.

From scope to the second profile

  1. 01

    Scope the Organizational Profile

    Decide what the profile covers — the whole organisation, one subsidiary, one product line. CSF 2.0 is explicit that a profile has a stated scope, and a profile whose scope is “everything, roughly” cannot be measured against anything later.

  2. 02

    Assess the Current Profile

    Walk the Subcategories and record what you are actually achieving today, with the evidence that supports it. A first pass with a lot of honest gaps is a correct first pass. An optimistic one is worse than no profile at all, because decisions get made on it.

  3. 03

    Set the Target Profile

    What outcomes you need, driven by your risks, your sector, your contracts and your obligations — not by a desire for full marks. A Community Profile for your sector is a reasonable starting draft rather than a finished answer.

  4. 04

    Analyse the gap and pick the Tier

    The difference between the two profiles is the gap list. Tiers describe how rigorous your risk governance and management practices are, so choose a Tier because it fits your risk appetite and budget — not because four is higher than two.

  5. 05

    Turn the gap into dated work

    Every gap becomes an action with an owner, a date and a cost. This is the step that separates a governance instrument from a wall chart, and the step most often skipped because the profile itself feels like a deliverable.

  6. 06

    Reassess on a cadence, and report the movement

    Reassess after material change and at a set interval. The valuable artefact is not the profile — it is the second profile, because two data points let you show a board whether the money moved anything.

See how structured assessments work

In Sentinel

A profile that is still true next quarter.

The common failure is not a bad assessment. It is a good assessment in a spreadsheet nobody reopens, so the next one starts from scratch and the movement between them is unmeasurable.

Subcategories as requirements

An outcome statement becomes a control somebody owns.

All six Functions can be held as scope, with Subcategory outcomes mapped onto controls in your register. A control that satisfies a Subcategory usually satisfies an ISO 27001 Annex A control and a SOC 2 criterion too — maintained once, reported three ways.

  • 59 Subcategoriesmapped onto a register of 26 controls shared with ISO 27001, SOC 2 and CIS v8.1
  • Current and target in one placeso the gap is a list you can work rather than a colour on a chart
  • Named owners24 of 26 assigned, and the unowned ones visible

See the control register

ControlsSentinel interface, reproduced
Control LibraryFramework ReadinessTest ScheduleTest HistoryFindings
Operating
18
Needs evidence
6
Not implemented
2
Owners assigned
24/26
  • A.5.1Policies for information security
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    28 Jul 2026
  • A.5.18Access rights
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    26 Jun 2026
  • A.8.5Secure authentication
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    14 Aug 2026
  • + 5 more in the workspace

Evidence

Nobody audits this, which is exactly why you evidence it.

There is no examiner to satisfy, so the only reliable correction for a generous self-assessment is requiring something behind every claim. Evidence carries a status and an expiry date, which is how a rating stops being true out loud rather than quietly.

  • Status and expiryon every item: Accepted, Under Review, Pending, Expired, Missing
  • 1 expired, 1 missingsurfaced continuously in the example workspace
  • Reused by a later programmean ISO 27001 or SOC 2 engagement inherits these artefacts wholesale

See evidence workflows

EvidenceSentinel interface, reproduced

Evidence status

26 controls
  • Accepted41
  • Needs Review2
  • Pending1
  • Expired1
  • Missing1

Register

Expiring first
  • Backup restore test report — Q3 2026
    Control
    A.8.13
    Owner
    Jordan Blake
    Status
    Missing
    Validity
    Due 30 Sep 2026
  • Penetration test report — external (2025)
    Control
    A.8.8
    Owner
    Priya Raman
    Status
    Expired
    Validity
    Expired 20 Jul 2026
  • Privileged account inventory
    Control
    A.8.2
    Owner
    Priya Raman
    Status
    Needs Review
    Validity
    Uploaded 4 Sep 2026
  • + 3 more in the workspace

GOVERN

Oversight is a Subcategory, and it needs an artefact.

GOVERN expects senior oversight of cybersecurity risk. That is evidenced with minutes and a reporting pack, not with a framework diagram — where are we, what changed, and what needs a decision, generated from the register rather than assembled the night before.

  • Readiness by Functionand a Sentinel Score built from nine weighted categories
  • Movement between assessmentswhich is the only thing that answers “is it getting better”
  • Decisions, not statusthe pack ends with what somebody has to approve or formally accept

See executive reporting

Board summarySentinel interface, reproduced
Northstar Manufacturing Ltd. · Security readiness · September 2026

Readiness moved from 68 to 76 since July. One critical risk is open, and the cyber insurance renewal is 96 days out.

76/ 100
Position
Expected
+8 since July
AprSep
What changed
  • Audit readiness up 13 points: the annual awareness campaign completed at 95% and August patch compliance was accepted.
  • Privileged-access testing found shared local admin credentials on six engineering workstations — a finding, and a funded PAM deployment due 15 October.
  • The 2025 external penetration test expired in July; the 2026 test is being booked for October.
Needs a decision
  • Critical risk — ransomware via phishing on plant-floor workstations: approve the treatment or formally accept it with conditions.
  • Two contracts expire inside 90 days: the shipping and EDI portal (20 October) and OT line-controller support (28 November).
  • Finalise the Statement of Applicability before the Stage 1 readiness review on 20 October.
Framework position
  • ISO/IEC 27001:202280% ready
    42 controls in the catalogue
  • SOC 2 (Trust Services Criteria)71% ready
    45 criteria in the catalogue
Insurance renewal

Renews 15 December 2026. 6 of 9 underwriter controls evidenced, 3 partial, 0 not in place.

Evidence

What makes a profile defensible.

There is no examiner, so these are the artefacts that hold up when a board member, a customer or an underwriter asks how you know — and the ones a later ISO 27001 or SOC 2 programme will reuse wholesale.

See how the evidence library handles expiry

Scoped Organizational ProfileFoundational
What the profile covers, stated plainly. Without it, nothing later is comparable.
Risk appetite and tolerance statementFoundational
A GOVERN outcome, and the document that makes “accept this risk” a decision rather than a shrug.
Roles, responsibilities and authoritiesFoundational
Who decides, who executes, and who is accountable to whom for cybersecurity risk.
Asset and data inventoryFoundational
Hardware, software, services, data and the flows between them. The dependency for most of IDENTIFY and PROTECT.
Policy set with review datesRecurring
Approved, communicated, and reviewed on a stated cycle rather than when someone remembers.
Supplier risk criteria and assessmentsRecurring
The supply chain Category is the largest in GOVERN. Most first profiles have almost nothing here.
Monitoring coverage mapRecurring
What is logged, what is monitored, and which assets nobody is watching at all.
Vulnerability and remediation recordsRecurring
The cadence, and proof the cadence happened, with exceptions recorded.
Incident response plan and exercise recordsEvent-driven
A plan with named roles, plus the date it was last exercised and what the exercise changed.
Recovery plan and restoration test resultsEvent-driven
A real restore with a date and a result. RECOVER is where untested assumptions live.
Awareness and training completionTime-bound
By person and date. The artefact most likely to have quietly expired.
Oversight reporting to the boardTime-bound
GOVERN expects senior oversight. Minutes and a reporting pack are how you evidence it.

Straight answers

Honest limitations.

CSF 2.0 is the best free thing in this space. It is also the easiest to perform rather than do.

It buys you no credential
There is no certificate and no accredited scheme. If procurement wants a document signed by an independent party, CSF cannot produce one, however good your profile is.
Outcomes, not instructions
A Subcategory tells you an outcome should be true. It does not say which tool, setting or cadence achieves it — that is what Informative References, Implementation Examples and prescriptive sets like the CIS Controls are for.
Self-assessment drifts generous
Nobody is checking, so ratings inflate. Requiring evidence against every claim is the only reliable correction, and it is unpopular for exactly that reason.
A profile is not a programme
The assessment is cheap and the remediation is not. A profile with no dated, owned actions behind it has documented a problem rather than started on it.

Questions

What people ask once they have read the framework.

Mostly about certification, Tiers, and whether this replaces the framework a customer named.

Can we get certified against NIST CSF 2.0?
No. CSF 2.0 is voluntary guidance and NIST operates no certification or conformity assessment scheme for it, so there is no certificate, no accredited body and no registry. Consultancies will perform an independent CSF assessment and write you a report, which can be genuinely useful, but it is that firm’s opinion rather than a recognised credential. If a customer needs a document from an accredited or licensed third party, ISO 27001 certification or a SOC 2 report is what they are describing, even when they say the word NIST.
What actually changed from version 1.1, and do we need to redo our profile?
The headline change is GOVERN. In 1.1 governance was a Category inside IDENTIFY and was the part most often skipped; 2.0 makes it a Function of its own covering organisational context, risk management strategy, roles and authorities, policy, oversight and supply chain risk. The framework also stopped being aimed at critical infrastructure specifically and is now written for organisations of any size or sector, and it added Implementation Examples alongside Informative References. The counts moved from five Functions, 23 Categories and 108 Subcategories to six, 22 and 106. Existing work maps across with reasonable effort — the real task is populating GOVERN, which is usually new material rather than remapped material.
CSF or CIS Controls? We cannot do both at once.
They answer different questions and the honest answer depends on which question is hurting. CSF 2.0 describes outcomes and gives you the structure and the vocabulary for governance, oversight and board reporting. CIS Controls v8.1 tells you what to configure, in priority order, with prescriptive Safeguards. A small organisation with no programme usually gets more from starting at CIS Implementation Group 1 and using CSF as the reporting frame over the top of it — the Safeguards produce movement, and the Functions explain the movement to people who do not administer systems.
What Tier should we target?
Tiers run from Partial through Risk Informed and Repeatable to Adaptive, and they describe the rigour of your cybersecurity risk governance and management practices rather than how many Subcategories you have ticked. Tiers are optional in 2.0, and the framework is explicit that moving up is worthwhile only when the reduction in risk justifies the cost. Most growing businesses are honestly at Partial or Risk Informed and would get real value from reaching Repeatable in their highest-risk areas, while leaving lower-risk areas where they are. A uniform Tier 4 ambition is almost always a budget conversation nobody has had yet.
Will a CSF profile satisfy a customer questionnaire or an insurance renewal?
Partly, and usefully. A completed profile with evidence behind it answers a large share of a typical questionnaire, because most questionnaires ask about the same outcomes in different words. It will not satisfy a buyer whose vendor policy names a certificate or a report. For an insurance renewal, underwriters ask control-level questions — multi-factor authentication coverage, offline and tested backups, privileged access, endpoint detection, an incident plan someone has read — so CIS Controls maps more directly to what is on the application form, while CSF is the better frame for the risk conversation behind it.
Can CyberWave assess us against CSF and give us a Tier?
Sentinel gives you a structured self-assessment across all six Functions, holds the evidence behind each answer, and reports readiness and movement over time. What it does not do is issue an independent opinion — CyberWave does not audit, certify or attest, and a Tier you record in Sentinel is your organisation’s own assessment. That is the correct status for it: CSF is designed to be self-assessed, and the value comes from doing it honestly and repeatedly rather than from someone else grading it.

Do the first profile honestly, then keep it.

A first pass across the six Functions takes an afternoon and usually surprises whoever commissioned it — most often in DETECT and in the supply chain half of GOVERN.

Book a walkthrough

Self-service signup opens shortly — we will set you up in the meantime

  • Published pricing — no quote-on-request tier
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required