- NIST CSF is a voluntary, risk-based framework applicable to any organization. Any size, any industry.
- CSF 2.0 adds a sixth function, Govern, joining Identify, Protect, Detect, Respond and Recover.
- ComplianceForge recommends the Secure Controls Framework (SCF) as the best framework to implement NIST CSF 2.0, because the CSF defines outcomes and the SCF provides the controls to meet them.
- NIST does not certify against the CSF, but the SCR CAP offers a third-party certification path for NIST CSF 2.0 using SCF controls.
- ComplianceForge offers four tiers. Good (policies and standards), Better (plus procedures), Great (plus risk management, IR, COOP, etc.), Awesome (comprehensive documentation solution).
- All products are editable in Word, Excel and PowerPoint, customized with your logo, and delivered the same day.
- The CSF is designed to evolve with threats. Organizations adopting it are better positioned for future compliance requirements.
What Is NIST CSF 2.0?
NIST CSF 2.0 is the current version of the NIST Cybersecurity Framework (CSF), a voluntary, risk-based approach developed by the National Institute of Standards and Technology (NIST) to help organizations manage cybersecurity risk in a structured and scalable way. NIST published CSF 2.0 on February 26, 2024. The CSF:
- Is a high-level framework that is applicable to any organization, regardless of its size or industry;
- Focuses on governing, identifying, protecting, detecting, responding to and recovering from cybersecurity risks; and
- Is flexible, so organizations can adapt and implement it to fit their specific needs and risk profiles using a risk-based approach.
NIST CSF 2.0 organizes cybersecurity outcomes into six Functions, 22 Categories and 106 Subcategories. CSF 2.0 added the Govern Function to the original five Functions:
- Govern (GV): the organization's cybersecurity risk management strategy, expectations and policy are established, communicated and monitored
- Identify (ID): the organization's current cybersecurity risks are understood
- Protect (PR): safeguards to manage the organization's cybersecurity risks are used
- Detect (DE): possible cybersecurity attacks and compromises are found and analyzed
- Respond (RS): actions regarding a detected cybersecurity incident are taken
- Recover (RC): assets and operations affected by a cybersecurity incident are restored
The NIST CSF comprises a risk-based compilation of guidelines that can help organizations identify, implement and improve cybersecurity practices and creates a common language for internal and external communication of cybersecurity issues. The NIST CSF is designed to evolve with changes in cybersecurity threats, processes and technologies.
When you look at it from a sliding scale of good, better, great or awesome, we have a few options for you to meet your needs and budget to align your company with the NIST Cybersecurity Framework (NIST CSF). The product names you see in the various packages below map into the matrix shown above to show you how that maps into NIST CSF. If you manage compliance in a GRC platform, see our premium GRC content.




What Is The Best Framework To Implement NIST CSF 2.0?
ComplianceForge recommends the Secure Controls Framework (SCF) as the best framework to implement NIST CSF 2.0. The CSF describes cybersecurity outcomes (6 Functions, 22 Categories and 106 Subcategories), but it does not include prescriptive controls. The SCF is a free metaframework with 1,500+ controls across 34 domains that are mapped to 200+ laws, regulations and frameworks, so one set of controls can show how you achieve NIST CSF 2.0 outcomes while also addressing your other obligations.
ComplianceForge is an authorized SCF Licensed Content Provider (LCP). Our SCF-based policies and standards (SCRP) and procedures (CSOP) give you editable documentation that is already aligned to SCF controls, so your evidence traces back to NIST CSF 2.0 Subcategories through the SCF mappings. If you want documentation organized by the six CSF Functions, our NIST CSF 2.0 CDPP is built on the SCF taxonomy and pairs with our NIST CSF 2.0 procedures. You can review the mapping in the SCF's NIST CSF 2.0 STRM.
What Problem Does ComplianceForge Solve?
Lack of In House Security Experience
Writing security documentation is a skill that many good cybersecurity professionals simply are not proficient at and avoid the task at all costs. Tasking your security analysts and engineers to write comprehensive documentation means you are actively taking them away from protecting and defending your network, which is not a wise use of their time. ComplianceForge offers cybersecurity documentation solutions that can save your organization significant time and money!
Compliance Requirements
It is increasingly common for companies to use the NIST CSF as the baseline for compliance expectations. Our products are designed with compliance in mind, since they focus on leading security frameworks to address reasonably-expected security requirements, such as the NIST CSF. Our Security, Compliance & Resilience Program (SCRP) and NIST CSF 2.0 Cybersecurity & Data Protection Program (CDPP) map the NIST CSF and other leading compliance frameworks so you can clearly see what is required!
Audit Failures
Security documentation does not age gracefully like a fine wine. Outdated documentation leads to gaps that expose organizations to audit failures and system compromises. Our documentation provides mapping to leading security frameworks to show you exactly what is required to both stay secure and compliant. Being editable documentation, you are able to easily maintain it as your needs or technologies change.
Vendor Requirements
It is very common for clients and partners to request evidence of a security program and this includes policies and standards. Our documentation solutions provide this evidence!
Clear Solutions For NIST CSF 2.0 Documentation
Clear Documentation
ComplianceForge provides comprehensive documentation that can prove your security program exists. This equates to a time saving of hundreds of hours and tens of thousands of dollars in staff and consultant expenses!
Time Savings
Our cybersecurity documentation can provide your organization with a semi-customized solution that requires minimal resources to fine tune for your organization's specific needs.
Alignment With Leading Practices
Our documentation is mapped to the NIST CSF, as well as other leading security frameworks!
NIST CSF 2.0 As Evidence Of Due Care
The NIST CSF is commonly referenced by regulators, industry groups and customer contracts as a benchmark for what “reasonable” cybersecurity looks like. Some state laws go further. For example, the Ohio Data Protection Act provides an affirmative defense to certain data breach tort claims for businesses whose cybersecurity programs reasonably conform to recognized frameworks, including the NIST CSF. If an organization's security practices are questioned after an incident, documented alignment with NIST CSF 2.0 can help show due diligence and due care, while having no recognized framework can make those practices harder to defend. CSF 2.0 also makes leadership accountable for cybersecurity risk through the Govern Function, so corporate officers and boards should treat CSF alignment as part of their oversight responsibilities.

Frequently-Asked Questions
Here are answers to common questions about NIST CSF 2.0:

