NIST CSF 2.0 — Cybersecurity Framework

NIST CSF, mapped to your evidence.

Six functions. Twenty-two categories. Over a hundred subcategories. The de-facto meta-framework for cybersecurity — and the one most other frameworks already crosswalk to. The Agency keeps your CSF profile live across the whole portfolio, vendors included.

What is the NIST Cybersecurity Framework?

The NIST Cybersecurity Framework — CSF — is a voluntary framework published by the US National Institute of Standards and Technology for organising and communicating cybersecurity risk management. It is not a control catalogue and not a certification. It is a common structure and vocabulary, which is precisely why so many other frameworks crosswalk to it.

CSF 2.0, released in February 2024, is the first major revision since 2014 and made two consequential changes. It added a sixth function, Govern, alongside the original five — Identify, Protect, Detect, Respond and Recover — elevating governance, roles, policy and supply chain risk management from a category to a top-level concern. And it dropped the "critical infrastructure" framing: version 1.1 was aimed at that sector, while 2.0 is explicitly written for organisations of any size or type.

The framework is used through Profiles: a Current Profile describing what you do today, a Target Profile describing where you intend to be, and the gap between them as the plan. Tiers 1 to 4 — Partial, Risk Informed, Repeatable, Adaptive — describe how rigorously the practices are governed, and are deliberately not maturity levels to be climbed for their own sake.

Voluntary on paper, it is load-bearing in practice: US federal agencies work to it, suppliers are asked about it, and ISO 27001, SOC 2, FFIEC and CMMC all map to it — which makes it the usual translation layer when one control set has to answer to another.

The numbers your team already knows.

NIST CSF is voluntary on paper but load-bearing in practice — federal agencies require it, US suppliers expect it, and most other frameworks (ISO 27001, SOC 2, FFIEC, CMMC) explicitly map to it. Maintaining a current profile by hand is the problem.

6 functions
Govern, Identify, Protect, Detect, Respond, Recover
CSF 2.0 added Govern
100+
Subcategories to evidence across the framework
And growing
4 tiers
Partial → Risk-informed → Repeatable → Adaptive
CSF maturity model

ARIA, TARA, VANCE — your living CSF profile.

Three of The Agency's leads keep CSF evidence current, the profile mapped against your target tier, and the audit-ready output composed from live data — not last quarter's snapshot.

ARIA avatar
ARIA
Evidence & Document Intelligence

Every subcategory, mapped to evidence. ARIA reads SOC 2 reports, ISO certs, policies and trust pages, and maps each artefact against the CSF subcategories and the 157 Universal Controls — your profile reflects what you actually have.

What you get
  • CSF 2.0 subcategory mapping kept current
  • Cross-framework crosswalks — ISO 27001, SOC 2, FFIEC, CMMC
  • Vendor evidence ingested and mapped automatically
TARA avatar
TARA
Tiering & Remediation

Your tier, watched continuously. TARA assesses every vendor's CSF profile against your target tier, flags drift, and opens SLA-bound remediation when controls fall short — so the maturity level you committed to actually holds.

What you get
  • Continuous tier assessment across the portfolio
  • Drift detection on subcategories that fall below target
  • Treatment plans with deadlines and SLA tracking
VANCE avatar
VANCE
Audit Composition

Profile reports composed from live data. VANCE generates current-state and target-state CSF profiles on demand — formatted for boards, auditors and federal agencies expecting CSF outputs (NIST 800-171, FedRAMP, CMMC).

What you get
  • Current-state and target-state CSF profiles on demand
  • Crosswalk reports to ISO 27001, SOC 2, CMMC and 800-171
  • Tamper-evident audit trail per output

Four shifts you'll feel at the next profile review.

NIST CSF stops being a once-a-year mapping exercise and becomes a continuous evidence layer that reflects current vendor posture across all six functions.

Profile stays live across the portfolio

Subcategories map to evidence automatically. When a vendor changes posture or attestation, the profile updates the same week.

Crosswalks come for free

Once mapped to CSF, the same evidence answers ISO 27001, SOC 2, CMMC and 800-171 questions. The mapping has already been done.

Tier drift surfaces automatically

TARA flags vendors whose CSF tier drops below your target — you stop discovering it during the next review and start acting on it inside SLA.

Federal-grade outputs land on demand

When the agency or prime contractor asks for a CSF profile, VANCE composes it from current data — not from a report writer waiting for someone to update the spreadsheet.

We crosswalked our entire vendor portfolio to NIST CSF in two weeks. The CMMC and 800-171 work that used to take a quarter now ships from the same evidence pack.

JT
CISO
US federal contractor

What teams ask about NIST CSF.

What changed in 2.0, how it differs from the other NIST publications, and what it means for third-party risk.

What changed in NIST CSF 2.0?
Two things that matter. A sixth function, Govern, was added and placed at the centre rather than in sequence — it covers organisational context, risk management strategy, roles and responsibilities, policy, oversight and cybersecurity supply chain risk management, which was promoted out of Identify. And the scope broadened: 1.1 was framed for critical infrastructure, while 2.0 is written for any organisation. NIST also added implementation examples and quick-start guides, which is the practical difference most teams notice first.
Is NIST CSF the same as NIST 800-53 or 800-171?
No. CSF is a framework — an organising structure and vocabulary, with no control requirements of its own. SP 800-53 is the control catalogue for federal information systems, and it is large. SP 800-171 is the narrower set of 110 requirements for protecting controlled unclassified information in non-federal systems, and it is the one that reaches defence contractors through DFARS and CMMC. CSF tells you what outcomes to organise around; 800-53 and 800-171 tell you what to implement. See our NIST 800-171 page for the contractual side.
Can you be certified against NIST CSF?
No. There is no certification, no accredited body and no certificate — a claim of "NIST CSF certified" should be treated as a red flag when it appears in a vendor's evidence. What exists is self-assessment against a Profile, and third-party assessments performed by consultancies, which produce a report rather than a certificate. This is a real difference from ISO 27001 when you are weighing what a vendor has actually demonstrated.
What does NIST CSF say about third-party and supply chain risk?
Under 2.0 it sits in Govern, as the GV.SC category — cybersecurity supply chain risk management. It asks for a supply chain risk programme with named roles, suppliers identified and prioritised by criticality, security requirements written into contracts, due diligence before engagement, ongoing monitoring through the relationship, supplier incidents planned for in your own response and recovery, and suppliers handled properly at termination. The move from a subcategory in 1.1 to a governance-level category in 2.0 was deliberate, and it tracks how examiners now talk about the subject.

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.