NIST CSF 2.0
Who needs it
Organizations that want a structured, defensible way to baseline and communicate their security posture, especially to a board, without committing to a formal certification process, and companies that need a common framework to align disparate security initiatives.
Key requirements
A current-profile assessment against the six functions and their subcategories, a target-profile defining desired maturity, and a gap-closure plan, typically supported by a maturity tier rating (Partial, Risk Informed, Repeatable, Adaptive).
Cyber/privacy implications
Governance and executive accountability for cyber risk now sit inside the framework itself via the Govern function, not as an afterthought bolted onto a technical control list.
Assessment methodology
Current-profile assessment across all six functions, target-profile definition based on business risk tolerance, tier rating, and a prioritized roadmap to close the gap.
Implementation phases
Baseline
Assess current state across Govern, Identify, Protect, Detect, Respond, Recover.
Target
Define the target profile and tier appropriate to your risk tolerance.
Close the gap
Prioritized roadmap execution with periodic re-assessment.
Evidence & documentation requirements
Current and target profile documentation, maturity tier justification, and a tracked roadmap showing progress against identified gaps, useful as board-reporting material as much as audit evidence.
Common mistakes
Treating NIST CSF as a checklist to complete once rather than a continuous profile to maintain; ignoring the Govern function and focusing only on the original five operational functions, which was a common gap even before 2.0 formalized it.
Related standards
Expert review
FAQ
Request a Maturity Assessment
See your current profile across all six functions before you set a target.
Request a Maturity Assessment →