The NIST Cybersecurity Framework — CSF — is a voluntary framework published by the US National Institute of Standards and Technology for organising and communicating cybersecurity risk management. It is not a control catalogue and not a certification. It is a common structure and vocabulary, which is precisely why so many other frameworks crosswalk to it.
CSF 2.0, released in February 2024, is the first major revision since 2014 and made two consequential changes. It added a sixth function, Govern, alongside the original five — Identify, Protect, Detect, Respond and Recover — elevating governance, roles, policy and supply chain risk management from a category to a top-level concern. And it dropped the "critical infrastructure" framing: version 1.1 was aimed at that sector, while 2.0 is explicitly written for organisations of any size or type.
The framework is used through Profiles: a Current Profile describing what you do today, a Target Profile describing where you intend to be, and the gap between them as the plan. Tiers 1 to 4 — Partial, Risk Informed, Repeatable, Adaptive — describe how rigorously the practices are governed, and are deliberately not maturity levels to be climbed for their own sake.
Voluntary on paper, it is load-bearing in practice: US federal agencies work to it, suppliers are asked about it, and ISO 27001, SOC 2, FFIEC and CMMC all map to it — which makes it the usual translation layer when one control set has to answer to another.