Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

NIST Cybersecurity Framework (CSF) 2.0 Compliance Guide

The National Institute of Standards and Technology (NIST), part of the US Department of Commerce, published the Cybersecurity Framework (CSF) 2.0 on February 26, 2024. The CSF does not introduce new standards or controls. It organizes cybersecurity outcomes into six Functions (Govern, Identify, Protect, Detect, Respond and Recover) and points to leading practices developed by organizations like NIST and the International Organization for Standardization (ISO). The CSF helps organizations identify, implement and improve cybersecurity practices, and it creates a common language for internal and external communication about cybersecurity risk.

The CSF is designed to evolve with changes in cybersecurity threats, processes and technologies. Because it describes outcomes rather than prescriptive controls, organizations need a control framework to implement and assess it, and ComplianceForge recommends the Secure Controls Framework (SCF) for that role. Businesses in regulated industries should also monitor how regulators and examiners reference the CSF in their review processes.

Spectrum NIST CSF Policies Standards Procedures
Key Takeaways - NIST Cybersecurity Framework 2.0
  • NIST CSF is a voluntary, risk-based framework applicable to any organization. Any size, any industry.
  • CSF 2.0 adds a sixth function, Govern, joining Identify, Protect, Detect, Respond and Recover.
  • ComplianceForge recommends the Secure Controls Framework (SCF) as the best framework to implement NIST CSF 2.0, because the CSF defines outcomes and the SCF provides the controls to meet them.
  • NIST does not certify against the CSF, but the SCR CAP offers a third-party certification path for NIST CSF 2.0 using SCF controls.
  • ComplianceForge offers four tiers. Good (policies and standards), Better (plus procedures), Great (plus risk management, IR, COOP, etc.), Awesome (comprehensive documentation solution).
  • All products are editable in Word, Excel and PowerPoint, customized with your logo, and delivered the same day.
  • The CSF is designed to evolve with threats. Organizations adopting it are better positioned for future compliance requirements.
Overview

What Is NIST CSF 2.0?

NIST CSF 2.0 is the current version of the NIST Cybersecurity Framework (CSF), a voluntary, risk-based approach developed by the National Institute of Standards and Technology (NIST) to help organizations manage cybersecurity risk in a structured and scalable way. NIST published CSF 2.0 on February 26, 2024. The CSF:

  • Is a high-level framework that is applicable to any organization, regardless of its size or industry;
  • Focuses on governing, identifying, protecting, detecting, responding to and recovering from cybersecurity risks; and
  • Is flexible, so organizations can adapt and implement it to fit their specific needs and risk profiles using a risk-based approach.

NIST CSF 2.0 organizes cybersecurity outcomes into six Functions, 22 Categories and 106 Subcategories. CSF 2.0 added the Govern Function to the original five Functions:

  • Govern (GV): the organization's cybersecurity risk management strategy, expectations and policy are established, communicated and monitored
  • Identify (ID): the organization's current cybersecurity risks are understood
  • Protect (PR): safeguards to manage the organization's cybersecurity risks are used
  • Detect (DE): possible cybersecurity attacks and compromises are found and analyzed
  • Respond (RS): actions regarding a detected cybersecurity incident are taken
  • Recover (RC): assets and operations affected by a cybersecurity incident are restored

The NIST CSF comprises a risk-based compilation of guidelines that can help organizations identify, implement and improve cybersecurity practices and creates a common language for internal and external communication of cybersecurity issues. The NIST CSF is designed to evolve with changes in cybersecurity threats, processes and technologies.

When you look at it from a sliding scale of good, better, great or awesome, we have a few options for you to meet your needs and budget to align your company with the NIST Cybersecurity Framework (NIST CSF). The product names you see in the various packages below map into the matrix shown above to show you how that maps into NIST CSF. If you manage compliance in a GRC platform, see our premium GRC content.

$ 1,980.00 USD
Policies & Standards - NIST CSF 2.0
This version of the Cybersecurity & Data Protection Program (CDPP) is based on the NIST Cybersecurity Framework 2.0 (NIST CSF 2.0) framework. It contains the necessary NIST CSF policies and standards that help achieve compliance with NIST CSF. You get fully-editable Microsoft Word and Excel documents that you can customize for your specific needs.
Included Products:
No items found.
Contains:
Word
Excel
PowerPoint
PDF
Examples:
Word Example
Excel Example
See Individual Products
$ 5,344.00 USD
PSP Bundle 1: NIST CSF 2.0
This is a bundle that includes two (2) ComplianceForge products that are focused on operationalizing the NIST Cybersecurity Framework (NIST CSF).
Contains:
Word
Excel
PowerPoint
PDF
Examples:
Word Example
Excel Example
See Individual Products
$ 19,670.00 USD
CFD Bundle 1: NIST CSF 2.0
This is a bundle that includes ten (10) ComplianceForge products that are focused on operationalizing the NIST Cybersecurity Framework (NIST CSF).
Best Framework For NIST CSF 2.0

What Is The Best Framework To Implement NIST CSF 2.0?

ComplianceForge recommends the Secure Controls Framework (SCF) as the best framework to implement NIST CSF 2.0. The CSF describes cybersecurity outcomes (6 Functions, 22 Categories and 106 Subcategories), but it does not include prescriptive controls. The SCF is a free metaframework with 1,500+ controls across 34 domains that are mapped to 200+ laws, regulations and frameworks, so one set of controls can show how you achieve NIST CSF 2.0 outcomes while also addressing your other obligations.

Outcomes Need Controls
NIST CSF 2.0 Subcategories are outcome statements (e.g., GV.PO-01 for cybersecurity policy). They do not tell you which controls to operate or how to prove them. The SCF provides the prescriptive controls that turn each outcome you target into something you can implement, evidence and assess.
Subcategory Mapping With STRM
The SCF publishes a Set Theory Relationship Mapping (STRM) for NIST CSF 2.0 that maps CSF 2.0 Subcategories (e.g., GV.OC-01) to SCF controls. STRM is the methodology described in NIST IR 8477, and each mapping states the relationship (equal, subset of, superset of, intersects with or no relationship) so you can explain to an assessor why a control supports an outcome.
Built For The Govern Function
CSF 2.0 added the Govern Function, which covers organizational context, risk management strategy, roles and responsibilities, policy, oversight and cybersecurity supply chain risk management. SCF controls for governance, risk management and third-party management give you concrete requirements for these outcomes.
One Control Set, Many Obligations
The SCF maps its controls to 200+ laws, regulations and frameworks. Evidence you produce for NIST CSF 2.0 can also support ISO 27001, NIST SP 800-171, SOC 2, CMMC and state privacy laws, instead of running parallel compliance programs.
Certifiable Through The SCR CAP
NIST does not certify organizations against the CSF. Under the Secure, Compliant & Resilient Conformity Assessment Program (SCR CAP), with The Cyber AB as its Accreditation Body, an accredited SCR Third-Party Assessment Organization (3PAO) can assess your SCF controls for an SCR certification for NIST CSF 2.0. Learn about NIST CSF certification.
Free To Use
The SCF is free to use under a Creative Commons license, so there is no framework licensing cost to adopt it as your common control set.
How ComplianceForge Uses The SCF

ComplianceForge is an authorized SCF Licensed Content Provider (LCP). Our SCF-based policies and standards (SCRP) and procedures (CSOP) give you editable documentation that is already aligned to SCF controls, so your evidence traces back to NIST CSF 2.0 Subcategories through the SCF mappings. If you want documentation organized by the six CSF Functions, our NIST CSF 2.0 CDPP is built on the SCF taxonomy and pairs with our NIST CSF 2.0 procedures. You can review the mapping in the SCF's NIST CSF 2.0 STRM.

What Problems Are There?

What Problem Does ComplianceForge Solve?

Lack of In House Security Experience

Writing security documentation is a skill that many good cybersecurity professionals simply are not proficient at and avoid the task at all costs. Tasking your security analysts and engineers to write comprehensive documentation means you are actively taking them away from protecting and defending your network, which is not a wise use of their time. ComplianceForge offers cybersecurity documentation solutions that can save your organization significant time and money!

Compliance Requirements

It is increasingly common for companies to use the NIST CSF as the baseline for compliance expectations. Our products are designed with compliance in mind, since they focus on leading security frameworks to address reasonably-expected security requirements, such as the NIST CSF. Our Security, Compliance & Resilience Program (SCRP) and NIST CSF 2.0 Cybersecurity & Data Protection Program (CDPP) map the NIST CSF and other leading compliance frameworks so you can clearly see what is required!

Audit Failures

Security documentation does not age gracefully like a fine wine. Outdated documentation leads to gaps that expose organizations to audit failures and system compromises. Our documentation provides mapping to leading security frameworks to show you exactly what is required to both stay secure and compliant. Being editable documentation, you are able to easily maintain it as your needs or technologies change.  

Vendor Requirements

It is very common for clients and partners to request evidence of a security program and this includes policies and standards. Our documentation solutions provide this evidence!

How Does ComplianceForge Help?

Clear Solutions For NIST CSF 2.0 Documentation

Clear Documentation

ComplianceForge provides comprehensive documentation that can prove your security program exists. This equates to a time saving of hundreds of hours and tens of thousands of dollars in staff and consultant expenses!

Time Savings

Our cybersecurity documentation can provide your organization with a semi-customized solution that requires minimal resources to fine tune for your organization's specific needs.

Alignment With Leading Practices

Our documentation is mapped to the NIST CSF, as well as other leading security frameworks!

Path To Showing Compliance

NIST CSF 2.0 As Evidence Of Due Care

The NIST CSF is commonly referenced by regulators, industry groups and customer contracts as a benchmark for what “reasonable” cybersecurity looks like. Some state laws go further. For example, the Ohio Data Protection Act provides an affirmative defense to certain data breach tort claims for businesses whose cybersecurity programs reasonably conform to recognized frameworks, including the NIST CSF. If an organization's security practices are questioned after an incident, documented alignment with NIST CSF 2.0 can help show due diligence and due care, while having no recognized framework can make those practices harder to defend. CSF 2.0 also makes leadership accountable for cybersecurity risk through the Govern Function, so corporate officers and boards should treat CSF alignment as part of their oversight responsibilities.

NIST CSF Diagram
Common Questions

Frequently-Asked Questions

Here are answers to common questions about NIST CSF 2.0:

What changed in NIST CSF 2.0?
NIST CSF 2.0, released on February 26, 2024, added a sixth Function called Govern and broadened the framework's audience from critical infrastructure to industry, government, academia and nonprofit organizations. Govern covers organizational context, risk management strategy, roles and responsibilities, policy, oversight and cybersecurity supply chain risk management. The title also changed, since earlier versions were called the Framework for Improving Critical Infrastructure Cybersecurity. The other five Functions are Identify, Protect, Detect, Respond and Recover.
How many categories and subcategories are in NIST CSF 2.0?
NIST CSF 2.0 has 6 Functions, 22 Categories and 106 Subcategories. The Govern Function alone contains 6 Categories, including the new Cybersecurity Supply Chain Risk Management Category (GV.SC), which has 10 Subcategories. Each Subcategory is an outcome statement rather than a prescriptive control. For example, GV.PO-01 covers establishing a policy for managing cybersecurity risks, but it does not say how that policy must be written or enforced.
What are the NIST CSF implementation tiers?
NIST CSF Tiers describe the rigor of an organization's cybersecurity risk governance and management practices. There are four Tiers: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3) and Adaptive (Tier 4). NIST states that Tiers should complement an organization's cybersecurity risk management methodology rather than replace it. An organization can use the Tiers to inform its Current and Target Profiles and decide how formal and consistent its practices need to be.
Does NIST CSF 2.0 include specific security controls?
No, NIST CSF 2.0 describes cybersecurity outcomes, and NIST states that it does not prescribe how those outcomes should be achieved. To implement it, you need a control set that turns each Subcategory into testable requirements. NIST publishes informative references and mappings that connect CSF outcomes to sources such as NIST SP 800-53. The Secure Controls Framework (SCF) is a practical option because it maps CSF 2.0 Subcategories to SCF controls and also covers ISO 27001 and NIST SP 800-171.
Does ComplianceForge offer NIST CSF 2.0 policy templates?
Yes, ComplianceForge offers NIST CSF 2.0 policies and standards as fully editable Microsoft Word and Excel documents, and we deliver them the same day you purchase. If you also need procedures, you can choose PSP Bundle 1: NIST CSF 2.0, and CFD Bundle 1: NIST CSF 2.0 adds risk management, incident response, business continuity and data privacy documentation. If you're working with several frameworks, you can use our SCF-based SCRP and CSOP instead, whose evidence traces to CSF 2.0 Subcategories through SCF mappings.