Skip to main content

FRAMEWORKS & CERTIFICATIONS

What Is NIST CSF 2.0?

DEFINITION

NIST CSF 2.0 is the current version of the NIST Cybersecurity Framework, a voluntary risk management framework organized into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Released in 2024, it extends the framework beyond critical infrastructure to organizations of every size and sector, and elevates governance and supply chain risk management to first-class concerns.

NIST CSF 2.0 is the National Institute of Standards and Technology's flagship cybersecurity framework, replacing version 1.1. It organizes security outcomes into six functions, with the new Govern function covering strategy, roles and responsibilities, policy, and supply chain risk. The framework is descriptive rather than prescriptive. It defines the outcomes a program should achieve and leaves the choice of specific controls to the organization, which is why it pairs well with prescriptive catalogs like the CIS Controls.

Regulators, cyber insurers, and enterprise customers frequently ask mid-market companies to describe their security program as aligned to NIST CSF. It also serves as the base layer for sector-specific profiles, including the CRI Profile used in financial services.

For a mid-market company, the practical implication is that CSF 2.0 adoption does not require new tooling, but it does require an honest current-state assessment and a target profile to be meaningful. Z Cyber's NIST CSF services cover that assessment and roadmap work, and the NIST CSF 2.0 compliance checklist walks through the six functions in detail.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →