Compliance Framework · Manufacturing & Automotive

NIST CSF

NIST Cybersecurity Framework 2.0

NIST Cybersecurity Framework

Widely adopted security maturity framework organized around Identify, Protect, Detect, Respond, Recover, and Govern functions.

"A Proven Framework for Measurable Security Maturity"

Applies to

What Is NIST CSF?

NIST CSF (National Institute of Standards and Technology Cybersecurity Framework) is a voluntary but widely adopted framework that organizes cybersecurity activities across six functions: Govern, Identify, Protect, Detect, Respond, and Recover. NIST CSF 2.0, released in 2024, added the Govern function and explicitly expanded the framework’s applicability beyond critical infrastructure to organizations of all sizes.

The framework is voluntary. It still ties into rules you may already follow: HHS publishes a crosswalk that maps each HIPAA Security Rule standard to CSF subcategories, and NIST’s own HIPAA guide, SP 800-66r2, links its guidance to the CSF the same way. For most businesses it becomes a hard requirement through a customer or government contract.

The 6 functions of NIST CSF 2.0

The six functions of NIST CSF 2.0 are Govern, Identify, Protect, Detect, Respond, and Recover. Between them they hold 22 categories and 106 subcategories of security outcomes. Govern is the new one. It covers strategy, roles, policy, oversight, and supplier risk, and it shapes how you prioritize the other five (NIST CSWP 29, 2024).

  • Govern (GV): Your cybersecurity risk strategy, expectations, and policy are set, communicated, and monitored.
  • Identify (ID): You understand your current cybersecurity risk. That means knowing your data, hardware, software, systems, services, people, and suppliers, and spotting where your program needs work.
  • Protect (PR): Safeguards are in use. Access control, training, data security, platform security, and resilient infrastructure all sit here.
  • Detect (DE): Possible attacks and compromises are found and analyzed.
  • Respond (RS): You act on a detected incident. You manage it, analyze it, contain it, and report on it.
  • Recover (RC): Assets and operations hit by an incident are restored, and people are kept informed while that happens.

Those definitions are paraphrased from Section 2 of the framework (NIST CSWP 29). The example controls in the table below are adapted from NIST’s Small Business Quick-Start Guide (SP 1300).

FunctionWhat it coversCategoriesExample controls for a 20-200 person business
GovernStrategy, roles, policy, oversight, supplier riskGV.OC Organizational Context; GV.RM Risk Management Strategy; GV.RR Roles, Responsibilities, and Authorities; GV.PO Policy; GV.OV Oversight; GV.SC Cybersecurity Supply Chain Risk ManagementName one person who owns the security program. List the laws and contracts you must meet. Vet vendors before you sign. Decide whether cyber insurance fits.
IdentifyAssets, risk, improvementID.AM Asset Management; ID.RA Risk Assessment; ID.IM ImprovementKeep an inventory of hardware, software, and cloud services. Classify business data. Scan for vulnerabilities. Track threats in a risk register.
ProtectAccess, training, data, platforms, resiliencePR.AA Identity Management, Authentication, and Access Control; PR.AT Awareness and Training; PR.DS Data Security; PR.PS Platform Security; PR.IR Technology Infrastructure ResilienceMFA on every account that offers it. Access to sensitive data by job role. Scheduled patching. Full-disk encryption on laptops. Backups with tested restores. Phishing training.
DetectMonitoring and event analysisDE.CM Continuous Monitoring; DE.AE Adverse Event AnalysisAnti-malware or EDR on every server and laptop. Someone watching alerts and logs, in-house or through a provider.
RespondIncident handlingRS.MA Incident Management; RS.AN Incident Analysis; RS.CO Incident Response Reporting and Communication; RS.MI Incident MitigationA written incident response plan with named decision makers. Severity triage. Containment steps. A list of who you must notify by law or contract.
RecoverRestorationRC.RP Incident Recovery Plan Execution; RC.CO Incident Recovery CommunicationCheck backups for integrity before restoring. Restore in business priority order. Write an after-action report.

Category names and identifiers come from Table 1 of the framework. Counting the subcategories in its Appendix A gives Govern 31, Identify 21, Protect 22, Detect 11, Respond 13, and Recover 8, for 106 in total (NIST CSWP 29, Appendix A).

What changed from CSF 1.1

  • Six functions instead of five. CSF 1.1 (April 2018) had Identify, Protect, Detect, Respond, and Recover. Governance (ID.GV) and supply chain risk management (ID.SC) were categories inside Identify (NIST CSF 1.1). In 2.0 they anchor a separate Govern function with six categories.
  • A wider audience. Version 1.1 was titled “Framework for Improving Critical Infrastructure Cybersecurity.” CSF 2.0 is written for organizations of all sizes and sectors, including industry, government, academia, and nonprofits (NIST CSWP 29).
  • A reorganized core. CSF 1.1 had 23 categories and 108 subcategories. CSF 2.0 has 22 and 106. NIST notes that gaps in the 2.0 numbering mark 1.1 subcategories that were relocated.
  • More help putting it to work. NIST added Quick Start Guides, Implementation Examples, and a searchable catalog that maps the CSF to more than 50 other cybersecurity documents (NIST news release, February 26, 2024).

Profiles and Tiers, briefly

A Current Profile records the outcomes you achieve today. A Target Profile records the ones you want. The gap between the two becomes your action plan. Tiers describe how rigorous your risk governance and management practices are: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4). NIST encourages moving up a tier when risks or mandates are greater, or when the cost-benefit math supports it (NIST CSWP 29, Section 3). Not every company needs Tier 4.

How a small or mid-size business can start

NIST wrote its Small Business Quick-Start Guide for businesses with modest or no cybersecurity plans in place. This order of work is drawn from it:

  1. Name who owns cybersecurity, and list the legal, regulatory, and contract requirements you must meet (GV.RR-02, GV.OC-03).
  2. Inventory your hardware, software, systems, and services. Then classify your data (ID.AM-01, ID.AM-02, ID.AM-04, ID.AM-07).
  3. Turn on multifactor authentication wherever it is offered, and change default passwords (PR.AA-03, PR.AA-01).
  4. Patch on a schedule, encrypt laptops, and test your backups (PR.PS-02, PR.DS-01, PR.DS-11).
  5. Put anti-malware on every device and get someone watching for suspicious activity. NIST suggests a service provider if you lack the staff (DE.CM-09). Our SOC monitoring and threat hunting service handles that piece.
  6. Write an incident response plan with named roles, plus a recovery playbook (RS.MA-01, RC.RP-01). See incident response and remediation.
  7. Write a Current Profile and a Target Profile, then work the gap. NIST’s Organizational Profiles guide (SP 1301) walks through it.

Every guide, including ones on Tiers and supply chain risk, is listed on NIST’s CSF 2.0 Quick Start Guides page. If you would rather have someone map your current controls to the six functions, our compliance and risk management team runs gap assessments. Request an assessment.

Why Choose AdVran for NIST CSF?

NIST CSF 2.0 is the most widely adopted cybersecurity framework globally. Its six functions give your leadership and your auditors the same vocabulary for measuring security maturity, whatever your industry.

1. Maturity Assessment

We run NIST CSF maturity assessments that score your current security against each function and category. You get a list of gaps ranked by business impact.

2. All Six Functions Covered

Our unified MSP/MSSP services are organized along the same six functions. We set security policy, keep asset inventories, protect infrastructure, watch for threats 24/7, respond to incidents, and support recovery.

3. Supply Chain Risk Management

CSF 2.0 added emphasis on supply chain risk. We assess and monitor third-party vendor security, set up supply chain controls, and keep risk registers that satisfy CSF supply chain requirements.

4. Measurable Improvement

We give leadership quarterly CSF maturity scorecards that show progress by function and category, so they can see what the security budget bought from one quarter to the next.

5. Cross-Framework Mapping

NIST CSF maps to ISO 27001, CIS Controls, CMMC, and other frameworks. If you build on CSF with us, the controls you put in place for one requirement carry over to the others.

Frequently Asked Questions About NIST CSF Compliance

What is NIST CSF and is it required?

No law requires it. NIST calls the CSF voluntary guidance. If you already work to the HIPAA Security Rule, you can reuse that work through the HHS crosswalk. Defense contractors answer to a different NIST standard: CMMC Level 2 assesses against SP 800-171, covered on our NIST 800-171 page. And if a customer contract names the CSF, you have to meet it for that customer.

What are the 6 functions of NIST CSF 2.0?

Govern, Identify, Protect, Detect, Respond, and Recover. Govern sets strategy, policy, roles, oversight, and supplier risk. Identify covers assets and risk. Protect covers safeguards such as access control, training, and data security. Detect finds and analyzes possible attacks. Respond manages and contains incidents, and Recover restores operations. Together they contain 22 categories and 106 subcategories (NIST CSWP 29).

What is new in NIST CSF 2.0?

NIST published CSF 2.0 on February 26, 2024, the first major update since the framework was created in 2014. It added the Govern function, opened the framework to organizations of every size and sector instead of focusing on critical infrastructure, and added Quick Start Guides, Implementation Examples, and an online catalog of informative references (NIST, 2024).

Is NIST CSF 2.0 mandatory?

No. NIST describes the CSF as “voluntary guidance” (NIST SP 1300). It becomes a requirement only when something else makes it one, such as a customer contract, a government contract clause, an insurance application, or a regulator that points to it. If a customer asks you to align with NIST CSF, check which version they mean and what evidence they expect to see.

How does NIST CSF relate to other frameworks like CMMC or HIPAA?

NIST CSF gives you the top-level structure that many specific frameworks map to. NIST 800-171 (the basis for CMMC Level 2) maps directly to NIST CSF practices. HIPAA’s Security Rule aligns heavily with the Identify, Protect, and Detect functions. Organizations that build on NIST CSF as their security foundation typically find that meeting specific regulatory requirements is more straightforward because the underlying controls are already in place.

What is a NIST CSF maturity assessment?

A NIST CSF assessment evaluates your organization’s current practices against the framework’s core functions, categories, and subcategories, producing a profile of your current state versus your target state. Maturity tiers (1-4: Partial, Risk Informed, Repeatable, Adaptive) describe how formally practices are set up. We conduct NIST CSF assessments as the starting point for security program development, producing a gap analysis and prioritized remediation roadmap.

Does NIST CSF apply to small businesses in California?

Yes. CSF 2.0 came with a Small Business Quick-Start Guide written for organizations with little or no security staff, and the framework works the same way for a 15-person office as for a large company. A practical first step: write a Current Profile of what you do today, choose a few Target Profile outcomes for the next year, and close the gaps in order of risk.

NIST CSF serves as the foundation that many sector-specific frameworks map to. NIST SP 800-53 provides the detailed security control catalog that federal agencies and contractors implement within the NIST CSF structure. FISMA requires federal agencies and their contractors to use NIST standards including CSF and 800-53. StateRAMP applies NIST-based controls to cloud services procured by state and local government agencies. TISAX adapts similar framework principles for the automotive industry’s information security requirements.

Self-assessment

NIST CSF 2.0 readiness snapshot

This checks fifteen outcomes taken from the NIST Cybersecurity Framework 2.0 Core, so you can see which basics are in place and which are missing. CSF 2.0 is a set of outcomes rather than a certifiable standard, so this is a self-assessment you score yourself: a high score is not an audit result, a certification, or a compliance opinion.

  1. 1. Is there a written list of who is responsible for cybersecurity decisions at your company, and have the people named on it seen it? higher weight

    GOVERN. CSF 2.0 GV.RR-02: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

  2. 2. Does anyone outside your IT team, such as an owner, partner, or general manager, see a written summary of your cybersecurity risks at least once a year? higher weight

    GOVERN. CSF 2.0 GV.RM-03: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

  3. 3. Do you have a current list of the outside vendors and software providers that hold your data or connect to your systems, marked to show which ones your business could not run without?

    GOVERN. CSF 2.0 GV.SC-04: Suppliers are known and prioritized by criticality

  4. 4. Do you keep an up to date list of every computer, server, phone, and network device your business uses, including equipment used from home? higher weight

    IDENTIFY. CSF 2.0 ID.AM-01: Inventories of hardware managed by the organization are maintained

  5. 5. Does someone check your systems for known security weaknesses on a regular schedule and write down what was found?

    IDENTIFY. CSF 2.0 ID.RA-01: Vulnerabilities in assets are identified, validated, and recorded

  6. 6. Do staff have to pass a second check, such as a code or an app approval, when they sign in to email and other business systems from outside the office? higher weight

    PROTECT. CSF 2.0 PR.AA-03: Users, services, and hardware are authenticated

  7. 7. Have all your staff, including part-time and temporary workers, had security awareness training in the past 12 months?

    PROTECT. CSF 2.0 PR.AT-01: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

  8. 8. In the past year, has anyone restored a file or a system from your backups to prove the backups work? higher weight

    PROTECT. CSF 2.0 PR.DS-11: Backups of data are created, protected, maintained, and tested

  9. 9. Are your operating systems and business applications on versions the vendor still issues security updates for, with anything older replaced or removed?

    PROTECT. CSF 2.0 PR.PS-02: Software is maintained, replaced, and removed commensurate with risk

  10. 10. Is your network watched for suspicious activity at all hours, with alerts going to someone who is expected to look at them, rather than only being checked when something breaks? higher weight

    DETECT. CSF 2.0 DE.CM-01: Networks and network services are monitored to find potentially adverse events

  11. 11. Have you written down what turns a suspicious alert into a declared security incident, and named the people allowed to make that call?

    DETECT. CSF 2.0 DE.AE-08: Incidents are declared when adverse events meet the defined incident criteria

  12. 12. When a security incident happens, do you work through a written response plan that names the outside parties to bring in, such as your insurer, legal counsel, and technical help? higher weight

    RESPOND. CSF 2.0 RS.MA-01: The incident response plan is executed in coordination with relevant third parties once an incident is declared

  13. 13. Once a security incident is declared, do you have a written list of who has to be told, covering staff, affected customers, your insurer, and any regulator, with the deadline that applies to each?

    RESPOND. CSF 2.0 RS.CO-02: Internal and external stakeholders are notified of incidents

  14. 14. Do you have written steps for getting back to normal after an incident, including who decides recovery starts and which systems come back first?

    RECOVER. CSF 2.0 RC.RP-01: The recovery portion of the incident response plan is executed once initiated from the incident response process

  15. 15. While you are recovering from a security incident, does a named person send regular updates to staff, customers, and partners saying what is back and what is still down?

    RECOVER. CSF 2.0 RC.CO-03: Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders

Common questions

NIST CSF compliance.

Don't see yours? Call (714) 694-4573 or email contact@advran.com.

What is NIST CSF and who needs to comply? +

Widely adopted security maturity framework organized around Identify, Protect, Detect, Respond, Recover, and Govern functions.

How does AdVran help with NIST CSF compliance? +

AdVran provides end-to-end NIST CSF compliance management, including gap assessment, control implementation, continuous monitoring, evidence collection, and audit coordination. Our team handles the technical complexity so you can focus on your business.

How long does it take to achieve NIST CSF compliance? +

Timeline depends on your current security posture and the scope of required controls. Most organizations achieve initial compliance within 3-6 months with AdVran's guidance. We provide a detailed timeline during our initial assessment.

What happens if we fail a compliance audit? +

AdVran conducts pre-audit readiness assessments to identify and resolve gaps before the official audit. If issues are found during an audit, we provide immediate remediation support and work with auditors to address findings.