Back to blog
Frameworks

NIST CSF 2.0 explained: six functions, and why Govern was added

The framework everyone quotes gained a sixth function and dropped "critical infrastructure" from its title. What Govern requires, how Tiers and Profiles actually work, and when CSF is the wrong choice.
GRC Copilot Team
NIST CSF 2.0 explained: six functions, and why Govern was added

The NIST Cybersecurity Framework is the most quoted security framework in existence and one of the least formally adopted - because it certifies nothing. It is a common language for describing and prioritising security outcomes, which is precisely why boards, insurers and regulators reach for it.

Six functions

CSF 2.0 added Govern alongside the original five:

  • Govern (GV) - strategy, expectations and policy. Roles and responsibilities, risk management strategy, supply chain risk management, and oversight. Cuts across all the others.
  • Identify (ID) - understanding assets, risks and the business context.
  • Protect (PR) - safeguards: identity and access, awareness, data security, platform security, resilience.
  • Detect (DE) - finding attacks in progress through monitoring and analysis.
  • Respond (RS) - incident management, analysis, mitigation, communication.
  • Recover (RC) - restoring capability and communicating during recovery.

Under the functions sit categories and subcategories, with subcategories expressing outcomes - "this is true of the organisation" - rather than prescribing how to achieve them. That outcome orientation is the framework's defining property, and the reason it maps cleanly onto every other standard.

Why Govern was added

Governance content existed in 1.1, scattered inside Identify. Elevating it to a function reflected what assessors kept finding: organisations with capable technical controls and no coherent accountability, risk appetite or supply chain oversight above them. Making governance a peer of the technical functions forces it into the same conversation.

The practical effect is that a CSF assessment now surfaces the governance gap explicitly rather than burying it. For most organisations, Govern is the weakest-scoring function on first assessment - and it is also the cheapest to improve, because it is decisions and documentation rather than engineering.

The title also changed. CSF 1.1 was framed around critical infrastructure; 2.0 dropped that framing to state plainly that it is for all organisations, of any size and sector.

Assess against CSF and everything else at once

GRC Copilot scores you across NIST CSF functions and maps the same evidence to ISO 27001, SOC 2 and regional frameworks - one assessment, several outputs.

Tiers are not maturity levels

The four Implementation Tiers - Partial, Risk Informed, Repeatable, Adaptive - describe how rigorously your risk management practices operate, not how good your controls are. Two persistent misunderstandings:

  • Tier 4 is not the goal for everyone. Tiers should be chosen to match risk appetite, threat environment and constraints. A small business at Tier 2 with well-chosen controls may be exactly right.
  • Tiers are not scored per control. They characterise the organisation's approach, which is why quoting "we are Tier 3" without a Profile behind it says very little.

Profiles are where the work happens

A Current Profile records the outcomes you are achieving today. A Target Profile records those you need, given your business requirements, risk appetite and obligations. The gap between them is your prioritised plan - and expressing it in CSF subcategories makes it legible to executives who will never read a control list.

CSF 2.0 also introduced Community Profiles - shared baselines for a sector or use case, which are worth checking before building a Target Profile from scratch.

When CSF is the right choice, and when it is not

Reach for it when you need a common language across technical and executive audiences, you want to prioritise investment by outcome, you are reporting cyber risk to a board, or you need a neutral structure to map several regulatory obligations onto.

Do not reach for it when a customer demands a certificate. CSF has no certification scheme, and no assessor issues one. If a contract requires demonstrated third-party assurance, you need ISO 27001 or SOC 2 - CSF can structure the programme underneath, but it will not satisfy the clause.

The common pattern in practice: use CSF as the internal organising framework and board reporting structure, and certify against ISO 27001 or attest under SOC 2 for external assurance. The two are complementary, and the underlying evidence is largely the same.

Frequently asked questions

Can we get certified against NIST CSF?

No. There is no certification scheme. Third-party assessments against CSF exist and produce a report, but not a recognised certificate.

Is CSF only for US organisations?

No. It is used internationally, and 2.0 explicitly broadened its stated audience beyond US critical infrastructure.

How does CSF relate to NIST SP 800-53?

CSF describes outcomes; 800-53 is a detailed control catalogue. NIST publishes mappings, so 800-53 is one way to implement CSF outcomes - considerably heavier than most non-federal organisations need.

Should we move from 1.1 to 2.0?

Yes, and the migration is mostly restructuring rather than new work - the main effort is populating Govern, where most organisations find genuine gaps.

Key takeaways

  • Six functions now, with Govern elevated to sit alongside the technical five.
  • Tiers describe risk management rigour, not control quality - Tier 4 is not a universal target.
  • Current and Target Profiles are the actual deliverable; the gap is your roadmap.
  • CSF cannot certify - pair it with ISO 27001 or SOC 2 when a customer needs assurance.
#nist-csf #govern #functions #tiers #profiles #csf-2-0