What Is NIST CSF?
NIST CSF (National Institute of Standards and Technology Cybersecurity Framework) is a voluntary but widely adopted framework that organizes cybersecurity activities across six functions: Govern, Identify, Protect, Detect, Respond, and Recover. NIST CSF 2.0, released in 2024, added the Govern function and explicitly expanded the framework’s applicability beyond critical infrastructure to organizations of all sizes.
The framework is voluntary. It still ties into rules you may already follow: HHS publishes a crosswalk that maps each HIPAA Security Rule standard to CSF subcategories, and NIST’s own HIPAA guide, SP 800-66r2, links its guidance to the CSF the same way. For most businesses it becomes a hard requirement through a customer or government contract.
The 6 functions of NIST CSF 2.0
The six functions of NIST CSF 2.0 are Govern, Identify, Protect, Detect, Respond, and Recover. Between them they hold 22 categories and 106 subcategories of security outcomes. Govern is the new one. It covers strategy, roles, policy, oversight, and supplier risk, and it shapes how you prioritize the other five (NIST CSWP 29, 2024).
- Govern (GV): Your cybersecurity risk strategy, expectations, and policy are set, communicated, and monitored.
- Identify (ID): You understand your current cybersecurity risk. That means knowing your data, hardware, software, systems, services, people, and suppliers, and spotting where your program needs work.
- Protect (PR): Safeguards are in use. Access control, training, data security, platform security, and resilient infrastructure all sit here.
- Detect (DE): Possible attacks and compromises are found and analyzed.
- Respond (RS): You act on a detected incident. You manage it, analyze it, contain it, and report on it.
- Recover (RC): Assets and operations hit by an incident are restored, and people are kept informed while that happens.
Those definitions are paraphrased from Section 2 of the framework (NIST CSWP 29). The example controls in the table below are adapted from NIST’s Small Business Quick-Start Guide (SP 1300).
| Function | What it covers | Categories | Example controls for a 20-200 person business |
|---|
| Govern | Strategy, roles, policy, oversight, supplier risk | GV.OC Organizational Context; GV.RM Risk Management Strategy; GV.RR Roles, Responsibilities, and Authorities; GV.PO Policy; GV.OV Oversight; GV.SC Cybersecurity Supply Chain Risk Management | Name one person who owns the security program. List the laws and contracts you must meet. Vet vendors before you sign. Decide whether cyber insurance fits. |
| Identify | Assets, risk, improvement | ID.AM Asset Management; ID.RA Risk Assessment; ID.IM Improvement | Keep an inventory of hardware, software, and cloud services. Classify business data. Scan for vulnerabilities. Track threats in a risk register. |
| Protect | Access, training, data, platforms, resilience | PR.AA Identity Management, Authentication, and Access Control; PR.AT Awareness and Training; PR.DS Data Security; PR.PS Platform Security; PR.IR Technology Infrastructure Resilience | MFA on every account that offers it. Access to sensitive data by job role. Scheduled patching. Full-disk encryption on laptops. Backups with tested restores. Phishing training. |
| Detect | Monitoring and event analysis | DE.CM Continuous Monitoring; DE.AE Adverse Event Analysis | Anti-malware or EDR on every server and laptop. Someone watching alerts and logs, in-house or through a provider. |
| Respond | Incident handling | RS.MA Incident Management; RS.AN Incident Analysis; RS.CO Incident Response Reporting and Communication; RS.MI Incident Mitigation | A written incident response plan with named decision makers. Severity triage. Containment steps. A list of who you must notify by law or contract. |
| Recover | Restoration | RC.RP Incident Recovery Plan Execution; RC.CO Incident Recovery Communication | Check backups for integrity before restoring. Restore in business priority order. Write an after-action report. |
Category names and identifiers come from Table 1 of the framework. Counting the subcategories in its Appendix A gives Govern 31, Identify 21, Protect 22, Detect 11, Respond 13, and Recover 8, for 106 in total (NIST CSWP 29, Appendix A).
What changed from CSF 1.1
- Six functions instead of five. CSF 1.1 (April 2018) had Identify, Protect, Detect, Respond, and Recover. Governance (ID.GV) and supply chain risk management (ID.SC) were categories inside Identify (NIST CSF 1.1). In 2.0 they anchor a separate Govern function with six categories.
- A wider audience. Version 1.1 was titled “Framework for Improving Critical Infrastructure Cybersecurity.” CSF 2.0 is written for organizations of all sizes and sectors, including industry, government, academia, and nonprofits (NIST CSWP 29).
- A reorganized core. CSF 1.1 had 23 categories and 108 subcategories. CSF 2.0 has 22 and 106. NIST notes that gaps in the 2.0 numbering mark 1.1 subcategories that were relocated.
- More help putting it to work. NIST added Quick Start Guides, Implementation Examples, and a searchable catalog that maps the CSF to more than 50 other cybersecurity documents (NIST news release, February 26, 2024).
Profiles and Tiers, briefly
A Current Profile records the outcomes you achieve today. A Target Profile records the ones you want. The gap between the two becomes your action plan. Tiers describe how rigorous your risk governance and management practices are: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4). NIST encourages moving up a tier when risks or mandates are greater, or when the cost-benefit math supports it (NIST CSWP 29, Section 3). Not every company needs Tier 4.
How a small or mid-size business can start
NIST wrote its Small Business Quick-Start Guide for businesses with modest or no cybersecurity plans in place. This order of work is drawn from it:
- Name who owns cybersecurity, and list the legal, regulatory, and contract requirements you must meet (GV.RR-02, GV.OC-03).
- Inventory your hardware, software, systems, and services. Then classify your data (ID.AM-01, ID.AM-02, ID.AM-04, ID.AM-07).
- Turn on multifactor authentication wherever it is offered, and change default passwords (PR.AA-03, PR.AA-01).
- Patch on a schedule, encrypt laptops, and test your backups (PR.PS-02, PR.DS-01, PR.DS-11).
- Put anti-malware on every device and get someone watching for suspicious activity. NIST suggests a service provider if you lack the staff (DE.CM-09). Our SOC monitoring and threat hunting service handles that piece.
- Write an incident response plan with named roles, plus a recovery playbook (RS.MA-01, RC.RP-01). See incident response and remediation.
- Write a Current Profile and a Target Profile, then work the gap. NIST’s Organizational Profiles guide (SP 1301) walks through it.
Every guide, including ones on Tiers and supply chain risk, is listed on NIST’s CSF 2.0 Quick Start Guides page. If you would rather have someone map your current controls to the six functions, our compliance and risk management team runs gap assessments. Request an assessment.
Why Choose AdVran for NIST CSF?
NIST CSF 2.0 is the most widely adopted cybersecurity framework globally. Its six functions give your leadership and your auditors the same vocabulary for measuring security maturity, whatever your industry.
1. Maturity Assessment
We run NIST CSF maturity assessments that score your current security against each function and category. You get a list of gaps ranked by business impact.
2. All Six Functions Covered
Our unified MSP/MSSP services are organized along the same six functions. We set security policy, keep asset inventories, protect infrastructure, watch for threats 24/7, respond to incidents, and support recovery.
3. Supply Chain Risk Management
CSF 2.0 added emphasis on supply chain risk. We assess and monitor third-party vendor security, set up supply chain controls, and keep risk registers that satisfy CSF supply chain requirements.
4. Measurable Improvement
We give leadership quarterly CSF maturity scorecards that show progress by function and category, so they can see what the security budget bought from one quarter to the next.
5. Cross-Framework Mapping
NIST CSF maps to ISO 27001, CIS Controls, CMMC, and other frameworks. If you build on CSF with us, the controls you put in place for one requirement carry over to the others.
Frequently Asked Questions About NIST CSF Compliance
What is NIST CSF and is it required?
No law requires it. NIST calls the CSF voluntary guidance. If you already work to the HIPAA Security Rule, you can reuse that work through the HHS crosswalk. Defense contractors answer to a different NIST standard: CMMC Level 2 assesses against SP 800-171, covered on our NIST 800-171 page. And if a customer contract names the CSF, you have to meet it for that customer.
What are the 6 functions of NIST CSF 2.0?
Govern, Identify, Protect, Detect, Respond, and Recover. Govern sets strategy, policy, roles, oversight, and supplier risk. Identify covers assets and risk. Protect covers safeguards such as access control, training, and data security. Detect finds and analyzes possible attacks. Respond manages and contains incidents, and Recover restores operations. Together they contain 22 categories and 106 subcategories (NIST CSWP 29).
What is new in NIST CSF 2.0?
NIST published CSF 2.0 on February 26, 2024, the first major update since the framework was created in 2014. It added the Govern function, opened the framework to organizations of every size and sector instead of focusing on critical infrastructure, and added Quick Start Guides, Implementation Examples, and an online catalog of informative references (NIST, 2024).
Is NIST CSF 2.0 mandatory?
No. NIST describes the CSF as “voluntary guidance” (NIST SP 1300). It becomes a requirement only when something else makes it one, such as a customer contract, a government contract clause, an insurance application, or a regulator that points to it. If a customer asks you to align with NIST CSF, check which version they mean and what evidence they expect to see.
How does NIST CSF relate to other frameworks like CMMC or HIPAA?
NIST CSF gives you the top-level structure that many specific frameworks map to. NIST 800-171 (the basis for CMMC Level 2) maps directly to NIST CSF practices. HIPAA’s Security Rule aligns heavily with the Identify, Protect, and Detect functions. Organizations that build on NIST CSF as their security foundation typically find that meeting specific regulatory requirements is more straightforward because the underlying controls are already in place.
What is a NIST CSF maturity assessment?
A NIST CSF assessment evaluates your organization’s current practices against the framework’s core functions, categories, and subcategories, producing a profile of your current state versus your target state. Maturity tiers (1-4: Partial, Risk Informed, Repeatable, Adaptive) describe how formally practices are set up. We conduct NIST CSF assessments as the starting point for security program development, producing a gap analysis and prioritized remediation roadmap.
Does NIST CSF apply to small businesses in California?
Yes. CSF 2.0 came with a Small Business Quick-Start Guide written for organizations with little or no security staff, and the framework works the same way for a 15-person office as for a large company. A practical first step: write a Current Profile of what you do today, choose a few Target Profile outcomes for the next year, and close the gaps in order of risk.
NIST CSF serves as the foundation that many sector-specific frameworks map to. NIST SP 800-53 provides the detailed security control catalog that federal agencies and contractors implement within the NIST CSF structure. FISMA requires federal agencies and their contractors to use NIST standards including CSF and 800-53. StateRAMP applies NIST-based controls to cloud services procured by state and local government agencies. TISAX adapts similar framework principles for the automotive industry’s information security requirements.