A working walkthrough of the NIST Cybersecurity Framework 2.0 — the six Functions (Govern + Identify/Protect/Detect/Respond/Recover), the four Tiers (Partial → Risk-Informed → Repeatable → Adaptive), Current vs Target Profiles, Implementation Examples, Informative References — anchored to the SEC Reg S-P 2024 / OMB M-22-15 / CISA BOD 23-01 / EU NIS2 adoption mandates and the 2026 enforcement posture for critical infrastructure and regulated industries.
NIST Cybersecurity Framework 2.0 was published February 26, 2024. It is the first major revision since CSF 1.1 (April 2018). CSF 2.0 is universally applicable — not limited to critical infrastructure — and elevates governance to a top-level Function.
The most important structural change in CSF 2.0 is the new Govern (GV) Function. CSF 1.1 relegated cybersecurity governance to a paragraph in the Introduction: "Governance of cybersecurity risk is addressed through the organizational requirements in [Identify function categories]". CSF 2.0 elevates Governance to a first-class Function with seven categories: GV.OC (Organizational Context), GV.RM (Risk Management Strategy), GV.RR (Roles, Responsibilities, and Authorities), GV.PO (Policies, Processes, and Procedures), GV.OV (Oversight), GV.SC (Cybersecurity Supply Chain Risk Management), and the new CSF 2.0 draft category GV.RR-P (Cyber Workforce Management). ComplianceStack tracks the Govern Function as the highest-leverage maturity gap in any CSF 1.1-locked organization.
Second, CSF 2.0 expanded applicability. CSF 1.1 was explicitly aimed at critical infrastructure owners and operators under Presidential Policy Directive 21. CSF 2.0, in direct response to the White House Office of the National Cyber Director (ONCD) May 2024 Request for Information, applies to all organizations regardless of sector — from small businesses to state, local, tribal, and territorial (SLTT) governments to Fortune 500 enterprises. ComplianceStack's CSF 2.0 analyzer therefore prompts for organization size and sector as Profile inputs rather than restricting to critical-infrastructure categories.
Third, CSF 2.0 introduced a searchable online Reference Tool with Implementation Examples and Informative References for every Category subcategory — replacing the static CSF 1.1 Appendix A. Examples are organized by Notional Maturity (the same Tier concept applied at subcategory level). Informative References map every subcategory to NIST SP 800-53 Rev 5 / Rev 6, SP 800-171 Rev 3, ISO/IEC 27001:2022, COBIT 2019, ISA/IEC 62443, the CIS Critical Security Controls v8, and other frameworks. ComplianceStack produces a 800-53 / 800-171 / ISO 27001 / CMMC control-counterpart deliverable for every CSF 2.0 subcategory.
Fourth, CSF 2.0 clarified Current Profile and Target Profile terminology with a Profiles template and quick-start guides for small businesses. Profiles are the most important governance deliverable in any CSF 2.0 program; the Profile is the alignment of Categories and subcategories with the organization's business requirements, risk tolerance, and resources. ComplianceStack treats Current-vs-Target Profile gap as the central gap-assessment output.
Fifth, CSF 2.0 reorganized the language in several Categories. The former PR.AC (Access Control), PR.AT (Awareness and Training), PR.DS (Data Security), PR.IP (Information Protection Processes and Procedures), PR.MA (Maintenance), PR.PT (Protective Technology) categories in CSF 1.1 have been replaced with PR.AA (Identity, Authentication, and Access Control — new emphasis), PR.AT, PR.DS, PR.PS (Platform Security), PR.IR (Technology Infrastructure Resilience), and PR.PI-P (Configuration Management — added). The ID (Identify) categories similarly shifted: ID.AM (Asset Management), ID.RA (Risk Assessment), ID.IM (Improvement), with several CSF 2.0 draft additions. Organizations migrating from CSF 1.1 to 2.0 must map their existing controls to the new Category numbering before running a meaningful gap analysis.
CSF 2.0 organizes cybersecurity risk management into six top-level Functions covering 22 Categories and more than 100 subcategories. The Functions are the highest-level structure in the Framework; Categories are the second level; subcategories are the third level; Implementation Examples are the fourth level. ComplianceStack treats the Functions as the macro-level reporting axis in the dashboard view.
The new Function in CSF 2.0. Embeds risk governance across every other Function. The Govern Function's seven categories are: GV.OC (Organizational Context — the organization's mission, stakeholder expectations, and legal/regulatory requirements are understood and inform cybersecurity risk management); GV.RM (Risk Management Strategy — the organization's priorities, constraints, risk tolerance, and risk appetite are established and used to support operational risk decisions); GV.RR (Roles, Responsibilities, and Authorities — cybersecurity roles, responsibilities, and authorities are established and communicated to support operational risk decisions); GV.PO (Policies, Processes, and Procedures — organizational cybersecurity policies, processes, and procedures are maintained and communicated to support operational risk decisions); GV.OV (Oversight — the cybersecurity risks of the organization are reviewed and adjusted as the organization changes); GV.SC (Cybersecurity Supply Chain Risk Management — a risk management strategy is established and used to manage cybersecurity risks across the organization's supply chain); and the CSF 2.0 draft category GV.RR-P (Cyber Workforce Management).
Develops the organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. Categories: ID.AM (Asset Management — inventories of hardware, software, services, and data are maintained); ID.RA (Risk Assessment — vulnerabilities in assets are identified, validated, and recorded, and threats, both internal and external, are identified and recorded); ID.IM (Improvement — improvement opportunities for the organization are identified and acted upon); and ID.IM-P / ID.RA-P (process-level subcategories added in the CSF 2.0 draft).
Develops and implements appropriate safeguards to manage cybersecurity risks. The CSF 2.0 reorganization places PR.AA (Identity, Authentication, and Access Control — the headline 2.0 expansion emphasizing identity as the new perimeter) ahead of the other categories. Categories: PR.AA, PR.AT (Awareness and Training), PR.DS (Data Security — data-at-rest and data-in-transit protections), PR.PS (Platform Security — hardware, software, and services are managed consistent with the organization's risk strategy), PR.IR (Technology Infrastructure Resilience — security architectures are managed with appropriate segmentation, redundancy, and resilience), and PR.PI-P (Configuration Management — process-level controls added in the 2.0 draft).
Develops and implements appropriate activities to identify the occurrence of a cybersecurity event. Categories: DE.CM (Continuous Monitoring — assets are monitored for anomalies, indicators of compromise, and other cybersecurity events); DE.AE (Anomaly Detection — detected anomalies are analyzed to characterize the event); and DE.DP (Detection Process — detection processes and procedures are maintained and tested).
Develops and implements appropriate activities to take action regarding a detected cybersecurity event. Categories: RS.RP (Response Planning — response processes and procedures are executed and maintained); RS.CO (Communications — coordination with internal and external stakeholders is consistent with response plans); RS.AN (Analysis — analysis is performed to establish what has taken place during an event and the root cause of the event); RS.MI (Mitigation — activities are performed to prevent expansion of an event and to remediate the event); RS.IM (Improvement — response strategies are updated based on lessons learned); and RS.MA-P (Response Management — added in the CSF 2.0 draft).
Develops and implements appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity event. Categories: RC.RP (Recovery Planning — recovery processes and procedures are executed and maintained); RC.IM (Improvement — recovery strategies are updated based on lessons learned); RC.CO (Communications — restoration activities are coordinated with internal and external parties); and RC.RP-P (Recovery Management — added in the CSF 2.0 draft).
CSF 2.0's Tiers characterize an organization's cybersecurity risk governance and management maturity. Tiers are not a maturity model to climb — they describe the rigor of an organization's practices from ad hoc (Tier 1) to adaptive and continuously improving (Tier 4). ComplianceStack treats Tier 3 (Repeatable) as the typical 2026 target for regulated enterprises and Tier 4 (Adaptive) as the target for critical-infrastructure / financial-services entities with active regulatory engagement.
Each Tier is characterized across three dimensions: Risk Management Process (how the organization identifies, assesses, and responds to risk), Integrated Risk Management Program (how the organization's risk-management decisions are integrated into enterprise-wide programs), and External Participation (how the organization contributes to and consumes from the broader ecosystem). ComplianceStack's Tier scoring captures all three dimensions per Function.
A Profile is the alignment of Categories and subcategories with the organization's business requirements, risk tolerance, and resources. The Current Profile reflects what an organization is currently achieving; the Target Profile reflects what it needs to achieve. ComplianceStack pairs every CSF 2.0 gap assessment with both.
The Current Profile is derived by scoring every Category subcategory as Implemented, Partially Implemented, Not Implemented, or Not Applicable. ComplianceStack's free assessment at compliancestack.ai/compliance-pulse produces a Current Profile across all six Functions in under five minutes. The Current Profile is the baseline measurement against which the Target Profile gap (and remediation roadmap) is computed.
The Target Profile should reflect (1) the organization's mission, business objectives, and risk appetite; (2) the regulatory mandates applicable to the organization (SEC Reg S-P, NYDFS Part 500, HIPAA Security Rule, PCI-DSS, EU NIS2); (3) the organization's industry-recognized risk posture (Financial Services, Healthcare, Manufacturing, Energy, Defense, etc.); and (4) the supply-chain obligations imposed by customers, partners, and prime contractors. ComplianceStack treats the Target Profile as a quarterly-deliverable artifact: review and re-approve every 90 days.
| Sector | Recomm. Tier | Profile Emphasis | Anchor Mandate |
|---|---|---|---|
| Financial Services | Tier 4 | GV.SC, ID.AM, PR.AA, DE.CM, RS.MA | SEC Reg S-P (17 CFR §248.30) + NYDFS Part 500 |
| Healthcare | Tier 3 | ID.AM, PR.DS, DE.AE, RS.MI, RC.RP | HIPAA Security Rule (45 CFR §164.308-312) + HITECH |
| Manufacturing / OT | Tier 3 | GV.SC, ID.AM, PR.IR, DE.CM, RS.MI | NIST SP 800-82 + ISA/IEC 62443 |
| Energy | Tier 4 | GV.OC, ID.RA, PR.IR, DE.CM, RS.CO | NERC CIP + TSA Pipeline Directive + EU NIS2 |
| Defense / Federal Contractor | Tier 3 | GV.OC, PR.DS, PR.AA, RS.MI | CMMC 2.0 + NIST SP 800-171 Rev 3 + DFARS 7012 |
| Public Companies | Tier 3 | GV.RR, GV.PO, ID.RA, RS.CO | SEC Reg S-K Item 106 (cyber risk disclosure) + SEC Reg S-P |
ComplianceStack's CSF 2.0 Profile deliverable is sector-aware: the dashboard prompts for sector at intake and surfaces the corresponding Profile emphasis categories and anchor mandates in the Target Profile default.
The CSF 2.0 Reference Tool (searchable online catalog at csfr.nist.gov and downloadable spreadsheet) is the substantive content expansion beyond CSF 1.1. Every Category subcategory maps to Implementation Examples (action-level guidance) and Informative References (mapping to other frameworks). ComplianceStack pairs every Current-vs-Target Profile gap with both.
Implementation Examples are illustrative, action-level guidance on how an organization might implement a particular subcategory. CSF 2.0 organizes Examples by Notional Maturity (Informative, Planning, Implementation, Risk Management, and Adaptation / Optimization). For example, ID.AM-01 (inventories of hardware managed) lists Examples at the Informative level ("an asset inventory is maintained in a spreadsheet") up to the Optimization level ("the inventory is integrated with configuration management, security orchestration, and continuous monitoring platforms"). ComplianceStack pairs each Current-Profile gap with the appropriate Implementation Example tier and treats the Example text as the remediation guidance for the gap.
CSF 2.0 subcategory ID.AM-01 ("Inventories of hardware managed by the organization are maintained") maps to: NIST SP 800-53 Rev 5 controls CM-8 (System Component Inventory) and PM-5 (System Inventory); NIST SP 800-171 Rev 3 control 03.01.01 (Accountability); ISO/IEC 27001:2022 Annex A.5.9 (Inventory of information and other associated assets); CIS Critical Security Controls v8 Control 1 (Inventory and Control of Enterprise Assets). The Implementation Examples describe a Tier 1 (Partial) implementation as a manually maintained spreadsheet and a Tier 4 (Adaptive) implementation as a continuous, agent-based inventory integrated with the EDR/SIEM telemetry pipeline.
Six adoption mandates drive U.S. and EU NIST CSF 2.0 adoption in mid-2026. ComplianceStack's CSF 2.0 analyzer maps each mandate to the relevant Function / Category / subcategory and tracks current enforcement posture.
Four ComplianceStack tools pair directly with this pillar guide. The free compliance pulse is the lightweight diagnostic (under 2 minutes, no signup); the multi-framework free assessment scores NIST CSF alongside HIPAA / SOX / GDPR / OSHA / SEC / FINRA; the framework landing page provides the regulatory framing; and ComplianceStack pricing covers audit-ready deliverable upgrades.
Run the free ComplianceStack assessment at /free-compliance-assessment. Under 2 minutes, no email or signup required. Instant NIST CSF 2.0 risk score across all six Functions (Govern / Identify / Protect / Detect / Respond / Recover), Tier 1-4 maturity per Function, and the top three remediation actions ranked by likelihood × impact — with missing Govern (GV) Function items, missing Current-vs-Target Profile documentation, and Tier 3 Repeatable maturity gaps surfaced as the highest-leverage compliance gaps.
Run the Free NIST CSF 2.0 Assessment →The ComplianceStack Compliance Pulse at /compliance-pulse scores NIST CSF 2.0 alongside HIPAA / SOX / GDPR / PCI-DSS / OSHA / SEC in a single 10-question instrument. Useful for any organization whose cybersecurity scope spans CSF 2.0 + HIPAA (healthcare-adjacent SaaS, clinical research organizations, healthcare payment platforms) or CSF 2.0 + PCI-DSS (retailers with cardholder data + back-office systems). Output: every-framework risk score and a cross-framework remediation map paired with Current vs Target Profiles.
Open the Compliance Pulse →ComplianceStack's NIST CSF framework landing page at /frameworks gives the regulatory framing, current adoption posture across SEC Reg S-P / OMB M-22-15 / CISA BOD 23-01 / EU NIS2 / NYDFS Part 500 / Texas SB 2188, and cross-links to every NIST-specific ComplianceStack tool.
Open the NIST CSF Framework Page →Upgrade from the free assessment to a ComplianceStack audit-ready report ($49–$149), remediation action plan ($79), or 90-day roadmap ($299) for documented output that satisfies SEC Reg S-P 17 CFR §248.30 written-policies-and-procedures expectation and OMB M-22-15 annual reporting — defensible at any SEC examination, FCEB agency review, or state AG breach exposure review.
View Pricing →