NIST Cybersecurity Framework 2.0 Explained: Functions & Implementation
The NIST Cybersecurity Framework (CSF) is a voluntary set of guidelines published by the National Institute of Standards and Technology to help organisations identify, manage and reduce cybersecurity risk. Version 2.0, released in February 2024, expanded the framework to six core functions – Govern, Identify, Protect, Detect, Respond and Recover – and broadened its scope to organisations of every size and sector worldwide.
The NIST Cybersecurity Framework is a voluntary set of guidelines, standards and best practices published by the National Institute of Standards and Technology to help organisations manage and reduce cybersecurity risk. Version 2.0, released in February 2024, expanded the framework from five functions to six, added a new Govern function, and explicitly addressed organisations of every size and sector, not just critical infrastructure. It is the closest thing to a universal language for cybersecurity risk management that exists today.
- NIST CSF 2.0 shipped in February 2024, the first major revision since version 1.1 in 2018.
- The framework now has six core functions: Govern, Identify, Protect, Detect, Respond and Recover.
- Govern is the headline addition – it anchors every other function in organisational strategy and accountability.
- NIST CSF is voluntary for most organisations, but US federal agencies must align with it under OMB guidance, and Indian regulated sectors increasingly reference it alongside ISO 27001.
- Framework fluency is now a hard skill for GRC analysts, security architects and CISO-track professionals across India and globally.
What Is the NIST Cybersecurity Framework and Why Does It Matter?
NIST first published the Cybersecurity Framework in 2014 following a US Executive Order focused on protecting critical infrastructure. The idea was straightforward: give organisations a common vocabulary and a structured way to think about cyber risk, without mandating specific technologies or controls.
It caught on fast. A 2023 ISACA State of Cybersecurity Survey found that 49% of organisations globally use NIST CSF as their primary cybersecurity framework, making it the single most widely adopted framework ahead of ISO 27001 and CIS Controls. In India, the Reserve Bank of India’s cybersecurity guidelines for banks and the SEBI Cyber Security and Cyber Resilience Framework both draw on NIST CSF concepts, which means Indian GRC professionals cannot afford to ignore it.
The framework is built around three components. The Core defines desired cybersecurity outcomes. Profiles let an organisation map its current state against a target state. Tiers (1 through 4) describe how mature and integrated an organisation’s risk management practices are, from informal and reactive at Tier 1 to adaptive and continuously improving at Tier 4.
If you are building or reviewing an enterprise security programme, our guide on how to build an enterprise cybersecurity framework walks through the structural decisions you will face before you even open the CSF document.
What Changed in NIST CSF 2.0: The Six Functions Explained
Version 1.1 had five functions: Identify, Protect, Detect, Respond, Recover. They formed a cycle, but critics argued the framework lacked explicit guidance on governance – the decisions about who owns risk, how policies get made and how cybersecurity connects to business objectives. CSF 2.0 fixes that directly.
The New Govern Function
Govern sits at the centre of the 2.0 framework, not at the start of a linear list. It covers organisational context, risk management strategy, roles and responsibilities, policies and oversight. The message is clear: everything else the framework asks you to do depends on having leadership accountability and a defined risk appetite first.
For Indian organisations navigating the Digital Personal Data Protection Act 2023 and RBI’s updated Master Direction on IT Governance, the Govern function maps almost directly onto board-level obligations that already exist in regulation.
The Remaining Five Functions
- Identify – understand your assets, business environment, supply chain risks and vulnerabilities.
- Protect – implement safeguards: access control, data security, training, secure configuration.
- Detect – develop the ability to find cybersecurity events quickly, including anomalies and continuous monitoring.
- Respond – plan and execute your response when an incident occurs: containment, analysis, communication.
- Recover – restore capabilities after an incident and incorporate lessons learned.
CSF 2.0 also introduced implementation examples for each subcategory, something practitioners had been asking for since 2014. These are concrete, actionable steps rather than abstract outcomes, which makes the framework far more usable for teams that do not have a dedicated GRC function.
Other Key Changes from 1.1 to 2.0
| Feature | CSF 1.1 (2018) | CSF 2.0 (2024) |
|---|---|---|
| Core functions | 5 (Identify, Protect, Detect, Respond, Recover) | 6 (adds Govern) |
| Target audience | Critical infrastructure sectors | All organisations, all sectors, all sizes |
| Supply chain risk | Mentioned briefly | Dedicated subcategories under Govern and Identify |
| Implementation guidance | Informative references only | Implementation examples per subcategory |
| Online resources | PDF-centric | Searchable online reference tool at csrc.nist.gov |
| Profile templates | Organisation-defined | Community profiles available for specific sectors |
The supply chain additions are significant. According to Verizon’s 2024 Data Breach Investigations Report, 15% of breaches involved a third party, up from 9% the previous year. CSF 2.0’s explicit treatment of supply chain risk reflects where real-world threats are actually moving.
How to Implement NIST CSF 2.0: A Five-Step Path
Adoption does not have to mean a multi-year transformation project. Most organisations benefit from a phased approach that builds momentum without overwhelming the team.
Step 1: Scope and Prioritise
Decide which systems, business units or data types you are addressing first. A hospital in Bengaluru might start with its patient data systems. A fintech startup in Mumbai might begin with its payment processing environment. You do not have to address everything in the first cycle.
Step 2: Build Your Current Profile
Map your existing controls and practices against the CSF 2.0 subcategories. Be honest. The gap between where you are and where you want to be is exactly what the framework is designed to surface, not hide.
Step 3: Conduct a Risk Assessment and Set a Target Profile
Use your risk assessment to define your target profile: what outcomes does the business actually need? A Tier 2 posture might be entirely appropriate for a small SaaS company. A Tier 4 posture is more likely required for a bank or telecom operator subject to SEBI or TRAI oversight.
Step 4: Create and Execute an Action Plan
Prioritise the gaps between your current and target profiles by risk level and cost. Assign owners. Set timelines. This is where the Govern function earns its place – without clear ownership and leadership buy-in, action plans stall at the first budget cycle.
If your organisation is also implementing Zero Trust principles alongside CSF, our article on Zero Trust architecture and the future of enterprise security explains how the two approaches complement each other in practice.
Step 5: Review, Communicate and Improve
CSF is a continuous cycle, not a one-time audit. Schedule regular profile reviews, report progress to leadership in business terms and adjust your target profile as threats and business context change. NIST’s own CSF 2.0 documentation recommends reviewing your profile at least annually and after any significant incident or organisational change.
For organisations operating under DORA or looking to align with financial sector resilience requirements, our DORA compliance and cybersecurity training guide covers how operational resilience frameworks intersect with CSF 2.0 obligations.
Building this kind of structured, framework-driven expertise is exactly what the GRC programme at 3.0 University is designed to develop. Whether you are aiming for a GRC analyst role or a security architect position, understanding how to apply CSF 2.0 in real organisational contexts is one of the most transferable skills you can build right now.
NIST CSF vs ISO 27001: Which Should Your Organisation Use?
This is one of the most common questions security and compliance teams ask, and the honest answer is: they are not mutually exclusive, but they serve different primary purposes.
What ISO 27001 Does
ISO 27001 is a certifiable standard. Pass the audit, get the certificate. It is built around an Information Security Management System (ISMS) and follows a Plan-Do-Check-Act cycle. Many Indian IT services companies, particularly those serving European clients under GDPR, pursue ISO 27001 certification because customers and regulators explicitly ask for it.
What NIST CSF Does
NIST CSF is a risk management framework, not a certifiable standard. There is no NIST CSF certificate. Its value is in giving you a structured, outcome-focused way to understand and communicate your cybersecurity posture. It is more flexible and arguably more practical for organisations that need to improve their security programme before they are ready for a formal audit.
Choosing Between Them
| Consideration | NIST CSF 2.0 | ISO 27001:2022 |
|---|---|---|
| Certification available? | No | Yes |
| Mandatory for any sector? | US federal agencies; referenced by RBI, SEBI | Required by some EU contracts and regulated sectors |
| Flexibility | High – outcome-based, not prescriptive | Moderate – structured clauses and Annex A controls |
| Supply chain coverage | Strong in CSF 2.0 | Covered in ISO 27001:2022 updates |
| Best for | Risk communication, programme building, US-linked entities | Client assurance, regulated industries, EU market access |
| Cost to implement | Lower (no audit fees) | Higher (certification body fees, ongoing surveillance audits) |
According to the ISO Survey of Management System Standard Certifications 2023, over 70,000 ISO 27001 certificates were issued globally, with India ranking among the top five countries for new certifications. That reflects genuine market demand. But many of those certified organisations also use NIST CSF internally for day-to-day risk management because the two frameworks map well onto each other.
The practical recommendation: if your clients or regulators require a certificate, pursue ISO 27001. If you need a framework to improve your security programme and communicate risk to the board, start with NIST CSF 2.0. If you can do both, the overlap in controls means you are not doing double the work.
Professionals who understand both frameworks command significantly better roles in GRC and security architecture. 3.0 University’s GRC programme covers both NIST CSF 2.0 and ISO 27001 in the context of real implementation scenarios, giving you the practical fluency that hiring managers in Indian and global organisations are actively looking for.
Frequently Asked Questions
What is the NIST Cybersecurity Framework?
The NIST Cybersecurity Framework is a voluntary set of guidelines developed by the National Institute of Standards and Technology to help organisations manage cybersecurity risk. It provides a common language and structured approach built around core functions, profiles and tiers. Version 2.0, released in February 2024, expanded its scope to all organisations regardless of size or sector.
What changed in NIST CSF 2.0?
CSF 2.0 added a sixth core function called Govern, which covers risk strategy, roles, accountability and organisational context. It expanded the target audience beyond critical infrastructure to all sectors. It introduced implementation examples for each subcategory, strengthened supply chain risk guidance and launched an online searchable reference tool to replace the static PDF approach of version 1.1.
What are the six functions of NIST CSF 2.0?
The six functions are Govern, Identify, Protect, Detect, Respond and Recover. Govern is the new addition in 2.0 and sits at the centre of the framework. The other five carry over from version 1.1 with updated subcategories and implementation examples. Together they cover the full lifecycle of cybersecurity risk management from strategy through incident recovery.
What is the difference between NIST CSF and ISO 27001?
ISO 27001 is a certifiable standard that results in a formal certificate after an external audit. NIST CSF is a flexible risk management framework with no certification. Use ISO 27001 when clients or regulators require proof of compliance. Use NIST CSF to build or improve your security programme and communicate risk to leadership. Many organisations use both, as the controls overlap significantly.
Is NIST CSF mandatory in India?
NIST CSF is voluntary for most organisations globally. In India it is not directly mandated, but the RBI’s cybersecurity framework for banks and SEBI’s cyber resilience guidelines reference NIST CSF concepts closely. Regulated Indian entities in finance and telecom effectively treat alignment with it as a compliance expectation, making it a practical requirement for GRC professionals in those sectors.
Last updated: July 2026. Reviewed by the 3University editorial team.


