NIST CSF 2.0 Pillar Guide · Updated July 2026

NIST CSF 2.0
Practical Guide for 2026

A working walkthrough of the NIST Cybersecurity Framework 2.0 — the six Functions (Govern + Identify/Protect/Detect/Respond/Recover), the four Tiers (Partial → Risk-Informed → Repeatable → Adaptive), Current vs Target Profiles, Implementation Examples, Informative References — anchored to the SEC Reg S-P 2024 / OMB M-22-15 / CISA BOD 23-01 / EU NIS2 adoption mandates and the 2026 enforcement posture for critical infrastructure and regulated industries.

Maintained by ComplianceStack · 2026-07-30 · Citation-ready (Dublin Core & citation_* meta)

On this page

  1. §1 NIST CSF 2.0 vs 1.1 — Why 2.0 Matters
  2. §2 The Six Functions (Govern/Identify/Protect/Detect/Respond/Recover)
  3. §3 The Four Tiers (Partial → Adaptive) and Tiers Grid
  4. §4 Profiles — Current vs Target Across Sectors
  5. §5 Deep Dives — Implementation Examples & Informative References
  6. §6 Adoption Mandates — SEC, OMB, CISA, ONCD, NIS2, States
  7. §7 Pair this guide with the ComplianceStack NIST CSF tools
  8. §8 Frequently Asked Questions

§1 NIST CSF 2.0 vs 1.1 — Why 2.0 Matters

NIST Cybersecurity Framework 2.0 was published February 26, 2024. It is the first major revision since CSF 1.1 (April 2018). CSF 2.0 is universally applicable — not limited to critical infrastructure — and elevates governance to a top-level Function.

The most important structural change in CSF 2.0 is the new Govern (GV) Function. CSF 1.1 relegated cybersecurity governance to a paragraph in the Introduction: "Governance of cybersecurity risk is addressed through the organizational requirements in [Identify function categories]". CSF 2.0 elevates Governance to a first-class Function with seven categories: GV.OC (Organizational Context), GV.RM (Risk Management Strategy), GV.RR (Roles, Responsibilities, and Authorities), GV.PO (Policies, Processes, and Procedures), GV.OV (Oversight), GV.SC (Cybersecurity Supply Chain Risk Management), and the new CSF 2.0 draft category GV.RR-P (Cyber Workforce Management). ComplianceStack tracks the Govern Function as the highest-leverage maturity gap in any CSF 1.1-locked organization.

Second, CSF 2.0 expanded applicability. CSF 1.1 was explicitly aimed at critical infrastructure owners and operators under Presidential Policy Directive 21. CSF 2.0, in direct response to the White House Office of the National Cyber Director (ONCD) May 2024 Request for Information, applies to all organizations regardless of sector — from small businesses to state, local, tribal, and territorial (SLTT) governments to Fortune 500 enterprises. ComplianceStack's CSF 2.0 analyzer therefore prompts for organization size and sector as Profile inputs rather than restricting to critical-infrastructure categories.

Third, CSF 2.0 introduced a searchable online Reference Tool with Implementation Examples and Informative References for every Category subcategory — replacing the static CSF 1.1 Appendix A. Examples are organized by Notional Maturity (the same Tier concept applied at subcategory level). Informative References map every subcategory to NIST SP 800-53 Rev 5 / Rev 6, SP 800-171 Rev 3, ISO/IEC 27001:2022, COBIT 2019, ISA/IEC 62443, the CIS Critical Security Controls v8, and other frameworks. ComplianceStack produces a 800-53 / 800-171 / ISO 27001 / CMMC control-counterpart deliverable for every CSF 2.0 subcategory.

Fourth, CSF 2.0 clarified Current Profile and Target Profile terminology with a Profiles template and quick-start guides for small businesses. Profiles are the most important governance deliverable in any CSF 2.0 program; the Profile is the alignment of Categories and subcategories with the organization's business requirements, risk tolerance, and resources. ComplianceStack treats Current-vs-Target Profile gap as the central gap-assessment output.

Fifth, CSF 2.0 reorganized the language in several Categories. The former PR.AC (Access Control), PR.AT (Awareness and Training), PR.DS (Data Security), PR.IP (Information Protection Processes and Procedures), PR.MA (Maintenance), PR.PT (Protective Technology) categories in CSF 1.1 have been replaced with PR.AA (Identity, Authentication, and Access Control — new emphasis), PR.AT, PR.DS, PR.PS (Platform Security), PR.IR (Technology Infrastructure Resilience), and PR.PI-P (Configuration Management — added). The ID (Identify) categories similarly shifted: ID.AM (Asset Management), ID.RA (Risk Assessment), ID.IM (Improvement), with several CSF 2.0 draft additions. Organizations migrating from CSF 1.1 to 2.0 must map their existing controls to the new Category numbering before running a meaningful gap analysis.

§2 The Six Functions (Govern/Identify/Protect/Detect/Respond/Recover)

CSF 2.0 organizes cybersecurity risk management into six top-level Functions covering 22 Categories and more than 100 subcategories. The Functions are the highest-level structure in the Framework; Categories are the second level; subcategories are the third level; Implementation Examples are the fourth level. ComplianceStack treats the Functions as the macro-level reporting axis in the dashboard view.

Function 1 — Govern (GV)

The new Function in CSF 2.0. Embeds risk governance across every other Function. The Govern Function's seven categories are: GV.OC (Organizational Context — the organization's mission, stakeholder expectations, and legal/regulatory requirements are understood and inform cybersecurity risk management); GV.RM (Risk Management Strategy — the organization's priorities, constraints, risk tolerance, and risk appetite are established and used to support operational risk decisions); GV.RR (Roles, Responsibilities, and Authorities — cybersecurity roles, responsibilities, and authorities are established and communicated to support operational risk decisions); GV.PO (Policies, Processes, and Procedures — organizational cybersecurity policies, processes, and procedures are maintained and communicated to support operational risk decisions); GV.OV (Oversight — the cybersecurity risks of the organization are reviewed and adjusted as the organization changes); GV.SC (Cybersecurity Supply Chain Risk Management — a risk management strategy is established and used to manage cybersecurity risks across the organization's supply chain); and the CSF 2.0 draft category GV.RR-P (Cyber Workforce Management).

Function 2 — Identify (ID)

Develops the organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. Categories: ID.AM (Asset Management — inventories of hardware, software, services, and data are maintained); ID.RA (Risk Assessment — vulnerabilities in assets are identified, validated, and recorded, and threats, both internal and external, are identified and recorded); ID.IM (Improvement — improvement opportunities for the organization are identified and acted upon); and ID.IM-P / ID.RA-P (process-level subcategories added in the CSF 2.0 draft).

Function 3 — Protect (PR)

Develops and implements appropriate safeguards to manage cybersecurity risks. The CSF 2.0 reorganization places PR.AA (Identity, Authentication, and Access Control — the headline 2.0 expansion emphasizing identity as the new perimeter) ahead of the other categories. Categories: PR.AA, PR.AT (Awareness and Training), PR.DS (Data Security — data-at-rest and data-in-transit protections), PR.PS (Platform Security — hardware, software, and services are managed consistent with the organization's risk strategy), PR.IR (Technology Infrastructure Resilience — security architectures are managed with appropriate segmentation, redundancy, and resilience), and PR.PI-P (Configuration Management — process-level controls added in the 2.0 draft).

Function 4 — Detect (DE)

Develops and implements appropriate activities to identify the occurrence of a cybersecurity event. Categories: DE.CM (Continuous Monitoring — assets are monitored for anomalies, indicators of compromise, and other cybersecurity events); DE.AE (Anomaly Detection — detected anomalies are analyzed to characterize the event); and DE.DP (Detection Process — detection processes and procedures are maintained and tested).

Function 5 — Respond (RS)

Develops and implements appropriate activities to take action regarding a detected cybersecurity event. Categories: RS.RP (Response Planning — response processes and procedures are executed and maintained); RS.CO (Communications — coordination with internal and external stakeholders is consistent with response plans); RS.AN (Analysis — analysis is performed to establish what has taken place during an event and the root cause of the event); RS.MI (Mitigation — activities are performed to prevent expansion of an event and to remediate the event); RS.IM (Improvement — response strategies are updated based on lessons learned); and RS.MA-P (Response Management — added in the CSF 2.0 draft).

Function 6 — Recover (RC)

Develops and implements appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity event. Categories: RC.RP (Recovery Planning — recovery processes and procedures are executed and maintained); RC.IM (Improvement — recovery strategies are updated based on lessons learned); RC.CO (Communications — restoration activities are coordinated with internal and external parties); and RC.RP-P (Recovery Management — added in the CSF 2.0 draft).

§3 The Four Tiers (Partial → Adaptive) and Tiers Grid

CSF 2.0's Tiers characterize an organization's cybersecurity risk governance and management maturity. Tiers are not a maturity model to climb — they describe the rigor of an organization's practices from ad hoc (Tier 1) to adaptive and continuously improving (Tier 4). ComplianceStack treats Tier 3 (Repeatable) as the typical 2026 target for regulated enterprises and Tier 4 (Adaptive) as the target for critical-infrastructure / financial-services entities with active regulatory engagement.

Each Tier is characterized across three dimensions: Risk Management Process (how the organization identifies, assesses, and responds to risk), Integrated Risk Management Program (how the organization's risk-management decisions are integrated into enterprise-wide programs), and External Participation (how the organization contributes to and consumes from the broader ecosystem). ComplianceStack's Tier scoring captures all three dimensions per Function.

Tier 1
Partial
Ad hoc
Tier 2
Risk-Informed
Approved
Tier 3
Repeatable
Policy
Tier 4
Adaptive
Culture

§4 Profiles — Current vs Target Across Sectors

A Profile is the alignment of Categories and subcategories with the organization's business requirements, risk tolerance, and resources. The Current Profile reflects what an organization is currently achieving; the Target Profile reflects what it needs to achieve. ComplianceStack pairs every CSF 2.0 gap assessment with both.

Current Profile

The Current Profile is derived by scoring every Category subcategory as Implemented, Partially Implemented, Not Implemented, or Not Applicable. ComplianceStack's free assessment at compliancestack.ai/compliance-pulse produces a Current Profile across all six Functions in under five minutes. The Current Profile is the baseline measurement against which the Target Profile gap (and remediation roadmap) is computed.

Target Profile

The Target Profile should reflect (1) the organization's mission, business objectives, and risk appetite; (2) the regulatory mandates applicable to the organization (SEC Reg S-P, NYDFS Part 500, HIPAA Security Rule, PCI-DSS, EU NIS2); (3) the organization's industry-recognized risk posture (Financial Services, Healthcare, Manufacturing, Energy, Defense, etc.); and (4) the supply-chain obligations imposed by customers, partners, and prime contractors. ComplianceStack treats the Target Profile as a quarterly-deliverable artifact: review and re-approve every 90 days.

Sector Profile Examples

Sector Recomm. Tier Profile Emphasis Anchor Mandate
Financial Services Tier 4 GV.SC, ID.AM, PR.AA, DE.CM, RS.MA SEC Reg S-P (17 CFR §248.30) + NYDFS Part 500
Healthcare Tier 3 ID.AM, PR.DS, DE.AE, RS.MI, RC.RP HIPAA Security Rule (45 CFR §164.308-312) + HITECH
Manufacturing / OT Tier 3 GV.SC, ID.AM, PR.IR, DE.CM, RS.MI NIST SP 800-82 + ISA/IEC 62443
Energy Tier 4 GV.OC, ID.RA, PR.IR, DE.CM, RS.CO NERC CIP + TSA Pipeline Directive + EU NIS2
Defense / Federal Contractor Tier 3 GV.OC, PR.DS, PR.AA, RS.MI CMMC 2.0 + NIST SP 800-171 Rev 3 + DFARS 7012
Public Companies Tier 3 GV.RR, GV.PO, ID.RA, RS.CO SEC Reg S-K Item 106 (cyber risk disclosure) + SEC Reg S-P

ComplianceStack's CSF 2.0 Profile deliverable is sector-aware: the dashboard prompts for sector at intake and surfaces the corresponding Profile emphasis categories and anchor mandates in the Target Profile default.

§5 Deep Dives — Implementation Examples & Informative References

The CSF 2.0 Reference Tool (searchable online catalog at csfr.nist.gov and downloadable spreadsheet) is the substantive content expansion beyond CSF 1.1. Every Category subcategory maps to Implementation Examples (action-level guidance) and Informative References (mapping to other frameworks). ComplianceStack pairs every Current-vs-Target Profile gap with both.

Implementation Examples

Implementation Examples are illustrative, action-level guidance on how an organization might implement a particular subcategory. CSF 2.0 organizes Examples by Notional Maturity (Informative, Planning, Implementation, Risk Management, and Adaptation / Optimization). For example, ID.AM-01 (inventories of hardware managed) lists Examples at the Informative level ("an asset inventory is maintained in a spreadsheet") up to the Optimization level ("the inventory is integrated with configuration management, security orchestration, and continuous monitoring platforms"). ComplianceStack pairs each Current-Profile gap with the appropriate Implementation Example tier and treats the Example text as the remediation guidance for the gap.

Informative References

Sample Subcategory Mapping — ID.AM-01 (Hardware Inventory)

CSF 2.0 subcategory ID.AM-01 ("Inventories of hardware managed by the organization are maintained") maps to: NIST SP 800-53 Rev 5 controls CM-8 (System Component Inventory) and PM-5 (System Inventory); NIST SP 800-171 Rev 3 control 03.01.01 (Accountability); ISO/IEC 27001:2022 Annex A.5.9 (Inventory of information and other associated assets); CIS Critical Security Controls v8 Control 1 (Inventory and Control of Enterprise Assets). The Implementation Examples describe a Tier 1 (Partial) implementation as a manually maintained spreadsheet and a Tier 4 (Adaptive) implementation as a continuous, agent-based inventory integrated with the EDR/SIEM telemetry pipeline.

§6 Adoption Mandates — SEC, OMB, CISA, ONCD, NIS2, States

Six adoption mandates drive U.S. and EU NIST CSF 2.0 adoption in mid-2026. ComplianceStack's CSF 2.0 analyzer maps each mandate to the relevant Function / Category / subcategory and tracks current enforcement posture.

§7 Pair this guide with the ComplianceStack NIST CSF tools

Four ComplianceStack tools pair directly with this pillar guide. The free compliance pulse is the lightweight diagnostic (under 2 minutes, no signup); the multi-framework free assessment scores NIST CSF alongside HIPAA / SOX / GDPR / OSHA / SEC / FINRA; the framework landing page provides the regulatory framing; and ComplianceStack pricing covers audit-ready deliverable upgrades.

Free Multi-Framework Compliance Assessment (with NIST CSF 2.0)

Run the free ComplianceStack assessment at /free-compliance-assessment. Under 2 minutes, no email or signup required. Instant NIST CSF 2.0 risk score across all six Functions (Govern / Identify / Protect / Detect / Respond / Recover), Tier 1-4 maturity per Function, and the top three remediation actions ranked by likelihood × impact — with missing Govern (GV) Function items, missing Current-vs-Target Profile documentation, and Tier 3 Repeatable maturity gaps surfaced as the highest-leverage compliance gaps.

Run the Free NIST CSF 2.0 Assessment →

Compliance Pulse (multi-framework assessment)

The ComplianceStack Compliance Pulse at /compliance-pulse scores NIST CSF 2.0 alongside HIPAA / SOX / GDPR / PCI-DSS / OSHA / SEC in a single 10-question instrument. Useful for any organization whose cybersecurity scope spans CSF 2.0 + HIPAA (healthcare-adjacent SaaS, clinical research organizations, healthcare payment platforms) or CSF 2.0 + PCI-DSS (retailers with cardholder data + back-office systems). Output: every-framework risk score and a cross-framework remediation map paired with Current vs Target Profiles.

Open the Compliance Pulse →

NIST CSF Framework Overview

ComplianceStack's NIST CSF framework landing page at /frameworks gives the regulatory framing, current adoption posture across SEC Reg S-P / OMB M-22-15 / CISA BOD 23-01 / EU NIS2 / NYDFS Part 500 / Texas SB 2188, and cross-links to every NIST-specific ComplianceStack tool.

Open the NIST CSF Framework Page →

ComplianceStack Pricing

Upgrade from the free assessment to a ComplianceStack audit-ready report ($49–$149), remediation action plan ($79), or 90-day roadmap ($299) for documented output that satisfies SEC Reg S-P 17 CFR §248.30 written-policies-and-procedures expectation and OMB M-22-15 annual reporting — defensible at any SEC examination, FCEB agency review, or state AG breach exposure review.

View Pricing →

§8 Frequently Asked Questions

What is NIST CSF 2.0 and what changed from CSF 1.1?
NIST CSF 2.0 was published on February 26, 2024 — the first major revision since CSF 1.1 in April 2018. ComplianceStack tracks five material shifts: First, the new Govern (GV) Function elevates cybersecurity governance to a top-level Function alongside Identify / Protect / Detect / Respond / Recover — CSF 1.1 had buried governance in the Identify function. Second, applicability broadened from critical infrastructure only to all organizations, per the White House ONCD May 2024 Request for Information. Third, the searchable online Reference Tool introduced Implementation Examples organized by Notional Maturity plus Informative References mapping every subcategory to NIST SP 800-53 Rev 5, SP 800-171 Rev 3, ISO/IEC 27001:2022, COBIT 2019, ISA/IEC 62443, and CIS Critical Security Controls v8. Fourth, Current Profile and Target Profile terminology was clarified with a Profiles template and quick-start guides for small businesses. Fifth, Categories were reorganized — PR.AA (Identity, Authentication, and Access Control) replaces the fragmented PR.AC / PR.PT categories in CSF 1.1, and several draft subcategories (GV.RR-P, ID.IM-P, PR.PI-P, RS.MA-P, RC.RP-P) were added for process-management maturity.
What are the six Functions (Govern/Identify/Protect/Detect/Respond/Recover) of NIST CSF 2.0?
CSF 2.0 organizes cybersecurity risk management into six top-level Functions covering 22 Categories and more than 100 subcategories. Function 1 — Govern (GV): organizational context, risk-management strategy, roles, policies, oversight, supply-chain risk management, and cyber workforce management. Function 2 — Identify (ID): asset management, risk assessment, and improvement. Function 3 — Protect (PR): identity / authentication / access control (headline 2.0 expansion), awareness & training, data security, platform security, technology infrastructure resilience, configuration management. Function 4 — Detect (DE): continuous monitoring, anomaly detection, and detection-process management. Function 5 — Respond (RS): response planning, communications, analysis, mitigation, improvement, response management. Function 6 — Recover (RC): recovery planning, improvement, communications, recovery management. ComplianceStack pairs each Function with a Tier 1–4 maturity score for the dashboard view.
What are the four Tiers (Partial / Risk-Informed / Repeatable / Adaptive) and how are Profiles used?
The four Tiers characterize an organization's cybersecurity risk-governance and management maturity. Tier 1 — Partial: processes are ad hoc and reactive. Tier 2 — Risk-Informed: management-approved practices but not enterprise-wide policy. Tier 3 — Repeatable: enterprise-wide formalized policy and standardized processes. Tier 4 — Adaptive: continuous improvement informed by real events and threat intelligence. Each Tier is characterized across three dimensions: Risk Management Process, Integrated Risk Management Program, External Participation. A Profile is the alignment of Categories and subcategories with the organization's business requirements, risk tolerance, and resources. The Current Profile is the organization's current state; the Target Profile is the state needed to manage the organization's specific cybersecurity risk. ComplianceStack's CSF 2.0 analyzer outputs the Current-vs-Target Profile gap with Implementation Examples per subcategory.
What is the relationship between NIST CSF 2.0 and NIST SP 800-53 Rev 5 / SP 800-171 Rev 3 / CMMC 2.0?
NIST CSF 2.0 is a top-level risk-management framework that maps to and references several controls libraries via Informative References. NIST SP 800-53 Rev 5 / Rev 6 is the U.S. federal controls catalog — CSF 2.0 maps every subcategory to 2–4 800-53 controls. NIST SP 800-171 Rev 3 is the contractor-side CUI catalog — CSF 2.0 maps to the 14 800-171 families (Access Control; Awareness and Training; Audit and Accountability; Configuration Management; Identification and Authentication; Incident Response; Maintenance; Media Protection; Personnel Security; Physical Protection; Risk Assessment; Security Assessment; System and Communications Protection; System and Information Integrity). CMMC 2.0 requires Level 2 organizations to satisfy every 800-171 control and aligns the new CMMC Level 3 (Expert) domains with several Govern (GV) categories. ISO/IEC 27001:2022 maps via Annex A controls A.5–A.8. ISA/IEC 62443 maps Operational Technology subcategories to 62443-3-3 and 62443-4-2. CIS Critical Security Controls v8 maps as Implementation Examples for many subcategories. ComplianceStack's reference tool produces the 800-53 / 800-171 / ISO 27001 / CMMC counterpart control list for every CSF 2.0 gap.
Who has adopted NIST CSF 2.0 (SEC Reg S-P, OMB M-22-15, CISA BOD 23-01, ONCD, EU NIS2)?
Five major adoptions drive U.S. and EU CSF 2.0 adoption in mid-2026. SEC Regulation S-P amendments (2024) under 17 CFR §248.30 require broker-dealers, investment advisers, and transfer agents to implement written policies and procedures for incident response and customer notification — SEC's adopting release explicitly cites NIST CSF. OMB Memorandum M-22-15 (February 2022) required every FCEB agency to adopt NIST CSF and report annually on maturity (CSF 2.0 has now superseded CSF 1.1 for that reporting). CISA BOD 23-01 (April 2023) requires FCEB CDM and Asset Management capabilities aligned with the CSF Identify (ID) Function — milestones run through 2025-2026. The White House ONCD May 2024 Request for Information cited CSF 2.0 as the preferred baseline for all organizations (not just critical infrastructure). EU NIS2 Directive 2022/2555 requires essential and important entities to implement cybersecurity risk-management measures aligning with NIST CSF, ISO 27001, or ENISA baseline — fines up to €10M or 2% of global turnover (essential) and €7M or 1.4% (important). State-level mandates (NYDFS Part 500; Texas SB 2188 / SB 261; California SB 1386 / CCPA) layer additional obligations. ComplianceStack's CSF 2.0 analyzer produces a multi-mandate readiness view.
How does an organization run a NIST CSF 2.0 gap assessment with ComplianceStack?
ComplianceStack runs a NIST CSF 2.0 gap assessment in two passes. First, the free compliance pulse at compliancestack.ai/compliance-pulse (under 2 minutes, no signup, no email, scores every Function subcategory, outputs a Current Profile plus Tier 1–4 maturity per Function). The pulse flags missing Govern (GV) Function items, missing Current-vs-Target Profile documentation, and Tier 3 Repeatable maturity gaps as the highest-leverage compliance gaps. Second, escalation to the deep multi-framework free compliance assessment at compliancestack.ai/free-compliance-assessment covering NIST CSF alongside HIPAA / SOX / GDPR / OSHA / SEC / FINRA with full Category / subcategory coverage and a NIST 800-53 / 800-171 / ISO 27001 / CMMC Informative Reference map. The output is a prioritized Function-remediation backlog with breach / civil-penalty exposure estimated at SEC Reg S-P, NYDFS Part 500, Texas SB 2188, California SB 1386 / CCPA, and EU NIS2 Article 21 amounts. ComplianceStack pairs every CSF 2.0 gap assessment with a 90-day implementation roadmap, an Implementation Examples walk-through, and a Current-vs-Target Profile template maintainable as a quarterly update.