The NIST Cybersecurity Framework (CSF) is one of the most widely used ways to organize a security program. Version 2.0, released by the U.S. National Institute of Standards and Technology in February 2024, made it more useful for organizations of every size.

What is the NIST CSF?

The CSF is a voluntary framework that describes cybersecurity outcomes an organization should aim for. It does not prescribe specific products or settings. Instead, it gives leadership and technical teams a common language for understanding, measuring and improving security.

The six Functions

CSF 2.0 organizes outcomes into six high-level Functions:

FunctionIn plain English
GovernSet the strategy, roles, policies and oversight for managing cybersecurity risk.
IdentifyKnow your assets, data, suppliers and risks.
ProtectPut safeguards in place, such as access control, training and data security.
DetectSpot attacks and problems quickly.
RespondTake action when an incident happens.
RecoverRestore operations and learn from what happened.

What changed in version 2.0?

  • A new Govern Function. Governance moved to the center, reflecting that cybersecurity is a leadership responsibility, not only an IT task.
  • Broader scope. The framework is written for all organizations, not only critical infrastructure.
  • More attention to supply chain risk. Managing the security of vendors and service providers is emphasized.
  • More practical resources. NIST published implementation examples, informative references and quick-start guides, including the Small Business Quick-Start Guide (NIST SP 1300).

Profiles and Tiers

Profiles describe your security posture. A Current Profile shows where you are today; a Target Profile shows where you want to be. The gap between them becomes your roadmap. NIST also publishes Community Profiles: sector-specific starting points that organizations can adopt.

Tiers describe how rigorous your risk management practices are, from Tier 1 (Partial) through Tier 2 (Risk Informed) and Tier 3 (Repeatable) to Tier 4 (Adaptive). Not every organization needs Tier 4; the right target depends on your risks and resources.

How to get started

  1. Assign ownership. Decide who in leadership is accountable for cybersecurity risk.
  2. Inventory what matters. List your critical systems, data and key vendors.
  3. Build a Current Profile. Assess where you stand against each Function.
  4. Set a Target Profile. Choose realistic goals based on your risks, obligations and budget.
  5. Prioritize the gaps. Turn the differences into a phased action plan.
  6. Review regularly. Reassess at least once a year and after major changes.

Why it matters for growing organizations

Customers, insurers and partners increasingly ask how you manage cybersecurity. The NIST CSF gives you a credible, well-known structure to answer those questions, and it maps well to other requirements such as PCI DSS v4.0.1, HIPAA and SOC 2.

CSF 2.0 remains the current version of the framework as of September 2026; version 1.1 has been superseded. For the official framework, quick-start guides and translations, visit NIST's website at nist.gov/cyberframework.