NIST Cybersecurity Framework 2.0

The six-function framework that gives organizations and boards a shared language for cyber risk, updated in 2024 with governance at the centre.

StandardNIST CSF 2.0
Applies toAny organization; CSF 2.0 explicitly broadened its audience beyond critical infrastructure to all sectors and sizes.
When it appliesVoluntary; widely used to structure programs, communicate maturity, and frame assessments, including in Canadian public-sector work.

The NIST Cybersecurity Framework is the most widely spoken language in cyber risk. It is not a control catalogue and not certifiable; it is an organizing structure, and its 2.0 revision (2024) made two moves that matter: it dropped the critical-infrastructure framing to address every organization, and it promoted governance to the centre of the model.

The six functions

CSF 2.0 arranges cybersecurity outcomes into six functions. Govern: the 2.0 addition, covering strategy, roles, policy, and oversight, on the argument that unowned security programs fail regardless of tooling. Identify: know your assets, risks, and dependencies. Protect: the controls that prevent bad outcomes. Detect: know when something is happening anyway. Respond: act on it. Recover: restore and learn. Each function breaks into categories and subcategories of outcomes, deliberately written as what, not how, with the how delegated to informative references like the CIS Controls and NIST’s own SP 800-53.

What it is good for

Three uses dominate in practice. Structure: organizing an inherited mess of tools and habits into functions exposes the gaps (organizations discover they have bought Protect three times and Detect never). Communication: profiles and tiers give boards and executives an honest, jargon-light way to see current versus target state, which is why assessments so often deliver findings on a CSF skeleton. And procurement: Canadian public-sector and enterprise RFPs reference CSF alignment often enough that consultancies serving them need fluency, even though “aligned to CSF” is inherently a self-claim, since nothing about the framework is auditable in the certification sense.

Why the security trades should care

The convergence pitch writes itself: physical security firms are increasingly asked where cameras, controllers, and monitoring infrastructure sit in a client’s cyber posture. CSF gives that conversation a respectable frame. Surveillance and access systems are assets to Identify, hardening them is Protect, their logs feed Detect, and an OT-flavoured deployment can lean on IEC 62443 for depth. A consultant who can place physical security systems inside the client’s existing CSF profile speaks the language the client’s CISO already reports in.

What trips people up

Mistaking the framework for a program: CSF names outcomes, and an organization still needs actual controls, which is what catalogue standards are for. Treating tiers as a maturity scorecard to chase rather than a communication device. And skipping Govern because it feels like paperwork, which is precisely the failure 2.0 was revised to call out.

How it fits

Use CSF to structure and communicate, CIS Controls to act, and ISO 27001 when someone needs certified proof. The three stack rather than compete.

Related guides

This is a plain-language guide, not the standard. It paraphrases and interprets; it does not reproduce the text. Requirements change between editions and provinces modify the codes that reference them. For design, installation, or compliance decisions, work from the current official text and your authority having jurisdiction.

References

  1. The NIST Cybersecurity Framework (CSF) 2.0National Institute of Standards and Technology · retrieved 2026-07-24
  2. CSF 2.0 resources, NIST Computer Security Resource CenterNIST CSRC · retrieved 2026-07-24

Last updated 2026-07-24.