Framework guide
NIST CSF Framework Guide
The NIST Cybersecurity Framework is a voluntary, outcome-based framework for managing cybersecurity risk. Version 2.0, released in February 2024, added Govern as a sixth core function and widened the audience beyond critical infrastructure to organizations of every size.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- CSF 2.0 has six core functions: Govern, Identify, Protect, Detect, Respond, and Recover.
- Govern is new in 2.0 and sits at the centre — it covers strategy, roles, policy, and oversight.
- The framework is voluntary and outcome-based: it describes what to achieve, not how to achieve it.
- There is no NIST CSF certification. Organizations self-assess against implementation tiers and profiles.
- Its outcomes map cleanly onto HIPAA Security Rule safeguards, SOC 2 Common Criteria, and ISO 27001 Annex A.
The six core functions
- Govern — establish and monitor cybersecurity strategy, expectations, roles, and policy. New in 2.0
- Identify — understand assets, suppliers, and the risks to them
- Protect — safeguards for identity, access, data security, awareness, and platform resilience
- Detect — find and analyse anomalies, indicators of compromise, and adverse events
- Respond — contain, analyse, communicate, and mitigate incidents
- Recover — restore assets and operations, and communicate during recovery
Tiers and profiles
Implementation tiers (Partial, Risk Informed, Repeatable, Adaptive) describe the rigour of your risk-management practices. They are not maturity grades to climb for their own sake — the right tier is the one that matches your risk and resources.
Profiles describe your current state and your target state against the framework outcomes. The gap between them is your roadmap, which makes CSF unusually practical for teams that need to prioritise rather than boil the ocean.
How NIST CSF relates to other frameworks
CSF is a risk-management framework rather than an audit standard, so nobody certifies you against it. That is precisely why it maps well onto everything else: its outcomes align with HIPAA Security Rule safeguards, SOC 2 Common Criteria, and ISO 27001 Annex A controls.
Teams commonly use CSF as the organising spine — the shared vocabulary for risk and control coverage — and then produce HIPAA, SOC 2, or ISO 27001 evidence from the same underlying work.
Frequently asked questions
What is the NIST Cybersecurity Framework?
A voluntary, outcome-based framework published by the US National Institute of Standards and Technology for managing cybersecurity risk. It describes outcomes to achieve rather than prescribing specific technologies, which lets organizations of any size and sector apply it.
What changed in NIST CSF 2.0?
Version 2.0, released in February 2024, added Govern as a sixth core function covering strategy, roles, policy, and oversight, and broadened the framework beyond critical infrastructure to organizations of all sizes and sectors.
What are the six NIST CSF functions?
Govern, Identify, Protect, Detect, Respond, and Recover. Govern is new in 2.0 and sits at the centre, informing how the other five are prioritised and overseen.
Can you be certified in NIST CSF?
No. There is no NIST CSF certification or accredited certifying body. Organizations self-assess using implementation tiers and current/target profiles, and use the gap between them as a roadmap.
How does NIST CSF compare to ISO 27001?
ISO 27001 is a certifiable management-system standard with an accredited audit; NIST CSF is a voluntary risk-management framework with no certification. Their control outcomes overlap heavily, so CSF is often used as the organising spine while ISO 27001 or SOC 2 provides the external attestation.