Book an Appointment
GRC · Cyber Risk Framework

NIST Cybersecurity Framework 2.0: a common language for cyber risk

With version 2.0, the NIST Cybersecurity Framework explicitly addresses organizations of every size and sector for the first time – and makes governance a function in its own right. VamiSec uses the CSF as a steering framework that brings ISO/IEC 27001, NIS2 and DORA together in one language.

v2.0published on 26 February 2024 as NIST CSWP 29 – the first full revision of the framework
6functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER
~106subcategories across 22 categories make up the CSF Core
freeavailable at no cost – a voluntary framework, not a certification scheme

What is the NIST Cybersecurity Framework 2.0?

The NIST Cybersecurity Framework (CSF) is the world's most widely used framework for structuring and communicating cyber risk. With version 2.0 (NIST CSWP 29), published on 26 February 2024, the US National Institute of Standards and Technology delivered the first full revision since the framework's inception – and expanded its scope from critical infrastructure to organizations of every size and sector.

The CSF Core is organized into six functions, 22 categories and around 106 subcategories. Organizational Profiles (current/target), Implementation Tiers (1–4) and Informative References – including mappings to ISO/IEC 27001, the CIS Controls and NIST SP 800-53 – turn it into a management instrument: free of charge, not certifiable, yet ideal for communicating maturity and priorities to boards and supervisory bodies.

The six functions of CSF 2.0

GOVERN is new in version 2.0 – it wraps around the five operational functions as the governance layer.

01

GOVERN

New in 2.0: anchors cyber risk in corporate governance – organizational context, risk management strategy, roles and responsibilities, policies, oversight and cybersecurity supply chain risk management.

02

IDENTIFY

Creates transparency about assets, business processes and risks: what are we protecting, and which vulnerabilities and improvement opportunities exist?

03

PROTECT

Covers safeguards such as identity and access management, awareness and training, data security, platform hardening and a resilient technology infrastructure.

04

DETECT

Ensures attacks and anomalies are found and analyzed in time – from continuous monitoring to adverse event analysis.

05

RESPOND

Structures the response to detected incidents: incident management, analysis, reporting and communication, and mitigation.

06

RECOVER

Restores systems and services after an incident – including recovery planning and transparent crisis communication with internal and external stakeholders.

Bridging ISO 27001, NIS2, DORA & CIS Controls

The CSF does not replace regulation – it translates between regulations.

ISO/IEC 27001

The Informative References link CSF subcategories directly to ISO/IEC 27001 controls. Your ISMS provides the evidence, the CSF the management view – ideal where certification and steering need to work together.

NIS2

GOVERN mirrors the management-body accountability of NIS2 Article 20, while the operational functions cover the measures catalogue of Article 21 – from risk management to supply chain security.

DORA

For financial entities, the CSF structures ICT risk management under DORA: IDENTIFY/PROTECT for protection and prevention, DETECT/RESPOND/RECOVER for detection, response and recovery.

CIS Controls

The CIS Controls translate CSF subcategories into prioritized technical safeguards – the fastest route from framework logic to actionable hardening.

Four steps to managed cyber risk

Our approach using Organizational Profiles and Implementation Tiers.

01

Establish the Current Profile

We capture the status quo across the six functions and 22 categories – based on existing evidence, interviews and technical spot checks.

02

Define Target Profile & Tiers

Together with management, we define the Target Profile and the intended Implementation Tier (1–4) – risk-based and aligned with your business model.

03

Build the gap roadmap

The gap between current and target profile becomes a prioritized roadmap with measures, responsibilities, budgets and quick wins.

04

Measure & steer

KPIs per function, regular re-assessments and management reporting make progress visible – and keep cyber risk permanently manageable.

How well do you cover the six CSF functions?

1GOVERN: Is cyber risk firmly anchored in your corporate governance, with clear roles and responsibilities up to executive level?

2IDENTIFY & PROTECT: Do you know all of your assets, and is baseline protection (access, patching, backups, awareness) in place across the organization?

3DETECT & RESPOND: Can you reliably detect attacks, and is your response process documented and tested in practice?

4RECOVER: Have you tested the recovery of critical systems – including well-managed communication with customers, partners and authorities?

This self-check does not replace an assessment; it provides an initial positioning along the CSF functions.

Frequently asked questions about NIST CSF 2.0

Concise answers for decision-makers and security leaders.

Is NIST CSF 2.0 mandatory or certifiable?

No. The CSF is a voluntary, free framework with no certification scheme. It works as a steering and communication instrument – formal evidence continues to come from standards such as ISO/IEC 27001 or regulatory audits.

What is new in version 2.0 compared with CSF 1.1?

The most important addition is the sixth function GOVERN, which bundles governance, strategy, roles, policies and cybersecurity supply chain risk management. The framework now also explicitly addresses all organizations – no longer just critical infrastructure – and is accompanied by Quick-Start Guides, Organizational Profiles and the CSF 2.0 Reference Tool.

We already have ISO 27001 – do we need the CSF at all?

A certified ISMS and the CSF complement each other: ISO/IEC 27001 provides the management system and the evidence, the CSF the function-oriented view for prioritization and board communication. The Informative References connect both worlds without duplicating work.

How does the CSF help with NIS2 and DORA?

The CSF offers a common language: GOVERN addresses management accountability (NIS2 Article 20), while the operational functions structure the measures of NIS2 Article 21 and ICT risk management under DORA. This lets you steer multiple regulations through one consistent target picture.

What does a CSF assessment with VamiSec look like?

We establish your Current Profile along the six functions, jointly define the Target Profile and Tier, and derive a prioritized gap roadmap. The effort depends on scope, locations and existing documentation – we scope it together in an initial consultation.

Ready for a risk-driven security program?

We establish your Current Profile, define targets and deliver the roadmap – pragmatic, prioritized and board-ready.