NIST Cybersecurity Framework (CSF) 2.0, released February 26, 2024, is an updated version of NIST’s voluntary cybersecurity framework that adds a sixth function, Govern, and broadens applicability beyond critical infrastructure to organizations of any size or sector.
NIST CSF 2.0 updates the original five-function framework by adding Govern as a sixth function, which addresses organizational cybersecurity governance, risk strategy, and oversight. Released February 26, 2024, CSF 2.0 also broadens its scope beyond critical infrastructure, making it applicable to organizations of any size, sector, or maturity level.
Key Takeaways
- NIST CSF 2.0 was released February 26, 2024, updating the original 2014 framework for the first time in a decade.
- The new Govern function addresses cybersecurity governance, risk management strategy, roles, policy, and oversight, elevating cybersecurity to an organization-wide, leadership-level concern.
- CSF 2.0 dropped the “critical infrastructure” framing from its title and scope, positioning the framework for organizations of any size or sector, not just critical infrastructure operators.
- CSF 2.0 includes expanded implementation examples and Informative References mapping the framework to other standards, including ISO 27001 and NIST SP 800-53.
- Like its predecessor, CSF 2.0 remains voluntary and non-regulatory, functioning as a common vocabulary and risk management structure rather than a compliance mandate in itself.
What Are the Six Functions of NIST CSF 2.0?
| Function | Focus |
|---|---|
| Govern (new in 2.0) | Organizational cybersecurity strategy, roles, policy, and risk oversight |
| Identify | Asset management, risk assessment, and understanding the organization’s risk context |
| Protect | Identity management, access control, training, and data security safeguards |
| Detect | Continuous monitoring and timely discovery of anomalies and security events |
| Respond | Incident response planning, communication, and mitigation |
| Recover | Recovery planning, improvements, and communication following an incident |
Why Was the Govern Function Added In CSF 2.0?
The original five-function framework focused heavily on technical and operational security activities, but did not explicitly address how an organization’s leadership sets cybersecurity strategy, assigns roles and responsibilities, or oversees risk at a governance level. Govern was added to close that gap, reflecting a broader industry shift toward treating cybersecurity as a board-level governance responsibility rather than a purely technical function, echoed in other frameworks and regulations that have added similar leadership-accountability provisions.
How is CSF 2.0 Different from CSF 1.1?
- Added the Govern function as a sixth core function, not present in CSF 1.1’s five-function structure.
- Broadened applicability beyond critical infrastructure to organizations of any size, sector, or cybersecurity maturity level.
- Expanded implementation examples and quick-start guides tailored to different organization types, including small businesses.
- Updated Informative References mapping CSF 2.0 outcomes to other frameworks and standards, including ISO/IEC 27001 and NIST SP 800-53.
Is NIST CSF 2.0 mandatory?
No. Like its predecessor, CSF 2.0 remains a voluntary, non-regulatory framework. Organizations adopt it because it provides a common vocabulary and structured approach to managing cybersecurity risk, and because many customers, partners, and cyber insurers now expect to see CSF alignment, even without a specific legal mandate requiring it.
How Encryption Consulting Helps
How Encryption Consulting HelpsCompliance Advisory Services help organizations map existing controls to all six NIST CSF 2.0 functions, including the new Govern function, and identify where cryptography and key management controls fit within the Protect function specifically. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
When was NIST CSF 2.0 released?
NIST released CSF 2.0 on February 26, 2024, the first major update to the Cybersecurity Framework since its original 2014 release.
What is the new function added in CSF 2.0?
Govern is the new sixth function added in CSF 2.0, covering organizational cybersecurity strategy, risk management roles, policy, and oversight, distinct from the original five functions: Identify, Protect, Detect, Respond, and Recover.
Does NIST CSF 2.0 apply to small businesses?
Yes. Unlike the original framework’s critical-infrastructure framing, CSF 2.0 explicitly broadens applicability to organizations of any size and sector, and includes quick-start guides and implementation examples aimed at smaller organizations.
Is NIST CSF 2.0 a compliance requirement?
No, CSF 2.0 remains voluntary and non-regulatory. It provides a common structure and vocabulary for managing cybersecurity risk, though many customers, partners, and insurers increasingly expect organizations to demonstrate alignment with it.
Map Your Controls to NIST CSF 2.0
Take the next step Compliance Advisory Services help you map existing controls, including cryptography and key management, to all six NIST CSF 2.0 functions. Assess your encryption strategy against CSF 2.0 today.
