What is the NIST Cybersecurity Framework? CSF 2.0 Explained for Boards and Executives
The NIST Cybersecurity Framework 2.0 organizes cybersecurity into six functions, led by the new Govern function. What it contains, what changed, how it maps to 800-53, and what a CSF profile does and does not prove.
The Six Functions
Govern (GV)
New in 2.0 and placed at the center of the Framework's wheel because it informs the other five. Govern covers organizational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management. It is the function that makes cybersecurity an enterprise risk rather than an IT function: who owns it, how risk appetite is set, how the board is informed, how third parties are governed. Every regulatory development since 2023, from the SEC's governance disclosure requirement to NYDFS's board oversight requirement, lands in this function.
Identify (ID)
Understanding the organization's assets, the risks to them, and the opportunities to improve. Asset management (the inventory every framework eventually demands), risk assessment, and, in 2.0, an explicit Improvement category that captures lessons learned from incidents and assessments.
Protect (PR)
The safeguards. Identity management, authentication, and access control; awareness and training; data security; platform security (the hardening of hardware, software, and services); and technology infrastructure resilience. This is where most of the controls in a catalog like 800-53 map, and where most of a mid-market security budget is spent.
Detect (DE)
Finding anomalies and compromises. Continuous monitoring and adverse event analysis: the logging, alerting, and investigation capability that determines whether an intrusion is found in hours or in months.
Respond (RS)
Acting on detected incidents. Incident management, analysis, reporting and communication (including the regulatory notifications that now carry deadlines measured in hours), and mitigation.
Recover (RC)
Restoring capabilities and communicating during and after recovery. Incident recovery plan execution and recovery communication. The function that ransomware tests.
Categories and Subcategories
Each function divides into categories (22 across the Framework) and each category into subcategories (106) that state a specific outcome. PR.AA-03, for example: users, services, and hardware are authenticated. DE.CM-01: networks and network services are monitored to find potentially adverse events. The subcategories are the level at which the Framework maps to controls, and NIST publishes informative references linking each one to 800-53 controls, CIS Controls safeguards, ISO 27001 controls, and others.
What Changed in CSF 2.0
Scope. Version 1.1 was written for critical infrastructure. Version 2.0 is written for all organizations, of any size, in any sector, and the title dropped the words critical infrastructure. NIST published quick-start guides for small business, for enterprise risk management integration, and for supply chain risk to make the point.
Govern. The addition of a sixth function elevated governance from a scattered set of subcategories to a first-class outcome. Cybersecurity strategy, risk appetite, roles, policy, oversight, and supply chain risk now have a home, and it sits at the center of the Framework. This is the change that made the CSF the natural structure for board reporting and for the SEC's governance disclosures.
Supply chain. Cybersecurity supply chain risk management moved into Govern as a category (GV.SC) with ten subcategories covering supplier selection, contract requirements, monitoring, and incident coordination. SolarWinds, Kaseya, MOVEit, and Change Healthcare are the reason.
Improvement. An explicit Identify category (ID.IM) for learning from assessments, exercises, and incidents.
Implementation examples and references. For the first time, NIST published concrete examples of how to achieve each subcategory and an online reference tool that maps subcategories to controls across multiple catalogs. The Framework became easier to use and harder to misrepresent.
Profiles and Tiers
Profiles
A Profile is the Framework applied to an organization. The Current Profile records which outcomes the organization achieves today and to what degree. The Target Profile records the outcomes it intends to achieve, given its risk appetite, regulatory obligations, and business priorities. The gap between them is the roadmap. NIST and sector bodies also publish Community Profiles: target profiles for a sector (financial services, healthcare, manufacturing) or a use case (ransomware, hybrid work). A mid-market company can adopt a Community Profile as a starting target rather than building one from nothing.
The profile is where the Framework's limit shows. A Current Profile is a self-assessment. It records what the organization believes it achieves. Unless each subcategory's rating is supported by evidence from the environment, the Current Profile is a description of intent, and the gap analysis measures the distance between two plans.
Implementation Tiers
Four tiers, Partial (1), Risk Informed (2), Repeatable (3), and Adaptive (4), describe how rigorously cybersecurity risk governance and management are integrated into the organization's practices. Tier 1 is ad hoc and reactive; Tier 4 is continuous, data-driven, and organization-wide. NIST is explicit that the tiers are not maturity levels for the outcomes and should not be used as a score. They describe the process by which the organization manages risk, not whether any given control works. A Tier 3 organization can be compromised. Many have been.
The CSF and the Control Catalogs
The Framework is deliberately silent on how. It says users must be authenticated; it does not say with what. The how lives in control catalogs, and the Framework's informative references connect the two. Every subcategory maps to:
- NIST SP 800-53. The primary reference. PR.AA-03 maps to IA-2 and its enhancements; DE.CM-01 maps to AU-6, SI-4, and others. An organization that builds its program on 800-53 can generate a CSF profile from the register, because the mapping is published.
- CIS Controls v8. The eighteen controls and 153 safeguards, mapped by CIS to every subcategory. The Benchmarks then say which setting on which platform.
- ISO/IEC 27001 and 27002. Annex A controls mapped for organizations that hold or pursue certification.
- NIST SP 800-171 and CMMC. For defense contractors, the CSF Protect and Detect outcomes correspond to 800-171 requirement families.
The practical pattern: use the CSF to talk to the board and to structure reporting; use a control catalog to build, assess, and remediate; use the published mapping so the same evidence serves both. An organization that tries to assess itself directly against the 106 subcategories, without a control catalog underneath, produces a profile nobody can verify.
Who Uses the CSF, and Why
Federal agencies are required to use it under Executive Order 13800 alongside the Risk Management Framework; the CSF structures the risk narrative and 800-53 supplies the controls.
Public companies use it to structure the annual cybersecurity governance disclosure the SEC has required since 2023. The rule does not mandate a framework, but the disclosure asks about risk management processes, board oversight, and management's role, which is the Govern function, and about how incidents are identified, assessed, and managed, which is Identify through Recover. Registrants that structure the 10-K disclosure around the six functions produce a narrative the SEC staff already understand.
Regulated financial and insurance entities encounter it through state regulators. NYDFS Part 500 guidance and the NAIC Insurance Data Security Model Law both reference NIST frameworks as acceptable structures.
Cyber insurers ask about it on applications and underwriting calls, usually as a proxy for whether the organization has a program at all.
Private equity sponsors use it for portfolio-level reporting, because it is the only vocabulary a software company, a dealership group, and a specialty manufacturer share.
Where the CSF Is Misused
Three patterns recur.
The profile as evidence. An organization completes a Current Profile, rates itself Tier 3, and presents the result to the board or a buyer as proof of posture. The profile is a self-description. Without an assessment of the environment behind each subcategory rating, it proves that management filled in a spreadsheet.
The tier as a score. Tiers describe process integration, not control effectiveness. Reporting we are Tier 3 to a board tells the board how the organization manages risk, not whether MFA is enforced.
The Framework as a program. The CSF is a structure for a program, not the program. An organization that aligns to the CSF but has not implemented a control catalog beneath it has an org chart for a department that does not exist.
Building a Profile a Mid-Market Company Can Defend
Start from a Community Profile. NIST and sector groups have published target profiles for ransomware, for small business, and for several industries. Adopting one as the initial Target Profile saves months and produces a target that regulators and insurers recognize.
Rate the Current Profile from evidence, not opinion. For each subcategory, record the control that achieves it, where the evidence lives, and when it was last verified. A subcategory rated as achieved without a named control and a dated artifact is a hope.
Build the control layer first. Assess the environment against a control catalog, 800-53 or the CIS Controls, and generate the Current Profile from the results through the published mapping. This is the only way a profile can be reproduced by someone else, which is the test of whether it is evidence.
Include compromise state. The Detect function asks whether adverse events are found. A profile that rates Detect as achieved without ever having looked for an intruder is describing the alarm system, not whether anyone is in the house. A compromise assessment belongs in the evidence for DE.CM and DE.AE.
Report the gap, not the tier. The board pack should show, per function, the Current Profile, the Target Profile, the gap, and the owner. The tier can appear as a footnote about process. It should never be the headline.
A Short History
February 2013. Executive Order 13636 directs NIST to develop a voluntary framework for critical infrastructure. February 2014. CSF 1.0 published with five functions. May 2017. Executive Order 13800 requires federal agencies to use it. April 2018. CSF 1.1 adds supply chain, authentication, and vulnerability disclosure outcomes and clarifies the tiers. 2022 to 2023. Two public drafts of 2.0, with the Govern function and the broadened scope. February 26, 2024. CSF 2.0 published with implementation examples, quick-start guides, and the online reference tool. Today. The SEC disclosure rules, NYDFS Part 500's governance requirements, and most cyber insurance applications read as though written against it.
Executive Implications
For a CFO, the CSF is the structure that lets security investment be described in outcome terms a board and an insurer understand, and the mapping that lets the same evidence satisfy the SEC disclosure, the insurance application, and the customer questionnaire. It is also the framework to ask about when a vendor claims alignment: which profile, which tier, and what evidence supports the ratings.
For a General Counsel, the Govern function is a checklist for the governance obligations regulators now impose: defined roles, documented risk appetite, board oversight, supply chain requirements in contracts. An organization that can show its Govern outcomes are achieved has most of the SEC and DFS governance record built.
For a board, the six functions are the agenda, and Govern is the board's own line. The board does not need to know what PR.AA-03 requires. It needs to know, for each function, what management's current-state assessment is, what evidence supports it, and where the gap to target is. A board that has asked for the evidence behind the profile has exercised oversight. One that has accepted the tier has not.
PE Implications
The CSF is the sponsor's framework by default, because it is the one every portco can speak. Three uses.
Portfolio reporting. Six functions, one page per portco, comparable across a platform of unrelated businesses. The Govern row is where the sponsor's own oversight is recorded.
Diligence. A target's CSF profile, if it has one, is management's description of its own posture. Compared against an independent assessment of the environment, the gap is the finding, and the size of the gap measures how much to trust management's other representations.
Exit narrative. A buyer's technical reviewer will structure their assessment around something, and it is usually this. A portco that exits with a current profile, a target profile, evidence behind both, and a control-mapped register underneath has answered the reviewer's questions before they are asked. One that exits with a tier has invited them.
Related Reading
Real-World Example: Colonial Pipeline and the Functions That Were Not Exercised
In May 2021, the DarkSide ransomware group gained access to Colonial Pipeline's network through a legacy VPN account that was no longer in use, was not protected by multi-factor authentication, and whose password had appeared in a prior breach corpus. The intrusion encrypted business systems. Colonial shut down the pipeline that carries roughly 45 percent of the East Coast's fuel as a precaution, paid a $4.4 million ransom, and restored operations over six days while fuel shortages spread across the Southeast.
Read against the Framework, the incident is a tour of the functions. Identify: an account that was not in the asset inventory because nobody knew it still existed. Protect: no MFA on remote access, a credential exposed in a public breach. Detect: no alert on the sign-in. Respond and Recover: a decision to shut down operational systems that were not themselves encrypted, because the organization could not quickly establish whether the intrusion had reached them. And Govern, which did not exist as a function in 2021: the incident led to the first TSA security directives for pipeline operators and helped drive the SEC's disclosure rules, both of which now ask the questions the Govern function contains.
Colonial was not an unsophisticated organization. It would likely have described itself, on a Current Profile, as achieving most of the Protect outcomes. The account that ended the description was outside the inventory. The profile describes what the organization knows about. The assessment finds what it does not.
Functions in NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, Recover. Govern is new, and it moved cybersecurity from an IT responsibility to an enterprise risk the board owns. The Framework describes intended posture. It does not measure current posture, which is the difference between a profile and an assessment.
How Cloudskope Can Help
Cloudskope's cyber risk assessments are structured against the NIST CSF, providing portfolio companies and acquisition targets with a consistent, board-communicable security posture assessment that maps current capabilities against framework requirements and identifies prioritized improvement opportunities.
Where the gap is closure rather than documentation, Cloudskope SARTUS™ is the instrument: a six-day, fixed-fee engagement that spends three days finding what current controls missed across Microsoft 365, Azure, dark web exposure, and active compromise, and three days fixing it. Every finding lands in one risk register mapped to NIST SP 800-53 and the CIS Benchmarks, with a crosswalk to the six CSF 2.0 functions. A CSF profile describes intended posture. SARTUS™ measures the posture that exists today. See how the register maps across frameworks.
.png)