NIST CSF 2.0 — Cybersecurity Framework

The voluntary US cybersecurity framework, organised around six functions since version 2.0 added Govern. Widely used as a strategic backbone.

National Institute of Standards and Technology (NIST), United States Department of Commerce. Voluntary framework — not a certification scheme.

What it is

The NIST Cybersecurity Framework is a voluntary, risk-based framework for organising cybersecurity activity, published by the US National Institute of Standards and Technology. Version 2.0 organises it around six functions:

  • Govern — added in 2.0, covering strategy, roles, policy, risk tolerance and supply chain oversight.
  • Identify — understanding assets, risks and dependencies.
  • Protect — safeguards for critical services.
  • Detect — finding events when they occur.
  • Respond — acting on detected incidents.
  • Recover — restoring capability afterwards.

The addition of GOVERN in version 2.0 was the substantive change. It recognises what practitioners already knew: security programmes fail on accountability, policy and supply chain oversight more often than on technical controls.

The framework works through profiles — a current profile describing where you are and a target profile describing where you need to be, with the gap between them forming the roadmap. Nothing requires uniform maturity across all six functions, which is what makes it genuinely risk-based.

It is not certifiable. There is no NIST CSF certificate. It is a framework for organising and communicating security posture, not a scheme for demonstrating it to third parties.

Who it's for

Organisations needing a strategic structure

Where the problem is that security activity is uncoordinated rather than absent, and the six functions give it shape.

Boards and executives

Profile comparison over time communicates progress in a way a control checklist does not, which makes it unusually good for governance reporting.

WA Government entities and their suppliers

Where the WA Government Cyber Security Policy integrates NIST CSF directly alongside the Essential Eight and the ASD ISM.

Australian organisations with US exposure

Where NIST frameworks are the common reference point in security conversations with US counterparties.

Organisations mapping between frameworks

CSF is widely used as the neutral structure that other frameworks map into, which makes it useful for anyone juggling several obligations.

Why implement it

  • It organises without prescribing. The functions give a programme structure while leaving control selection to your risk, which suits organisations with mixed obligations.
  • Govern reflects reality. Version 2.0 elevated the thing that actually determines whether security programmes work.
  • Profiles make progress visible. Current versus target, reassessed over time, is materially better board reporting than a maturity score in isolation.
  • It is a mapping hub. Most other frameworks map to CSF, making it the practical structure for an organisation holding several obligations at once.
  • It is embedded in Australian policy. WA's cyber security policy integrates it directly, so for those entities this is not a foreign framework but a named reference.

How implementation works

1. Establish the current profile

Where the organisation actually sits across the six functions today, assessed against evidence.

2. Define the target profile

Where it needs to be, driven by risk, sector and obligations rather than by an aspiration to score highly everywhere. Not every function needs the same maturity.

3. Analyse the gap

The distance between profiles, prioritised by risk reduction rather than by ease.

4. Build governance first

The GOVERN function exists because programmes fail on accountability more often than on technique. Roles, policy, risk tolerance and supply chain oversight come before control work.

5. Implement across the functions

Identify, Protect, Detect, Respond and Recover, with technical implementation often driven by CIS Controls or the Essential Eight underneath.

6. Reassess and report

Profile comparison over time is what makes CSF genuinely good for board reporting — it shows movement rather than a static rating.

How Soveriq helps

Soveriq uses NIST CSF where an organisation needs a coherent structure and a way to report progress to a board, rather than a certificate. Current profile, target profile, and a roadmap between them, with technical implementation driven by CIS Controls or the Essential Eight underneath.

Where a certifiable obligation also exists, we map the CSF work into ISO 27001 so the same programme serves both. For WA government entities, the policy already integrates CSF, so this is not a parallel effort.

Being direct about what this is. There is no NIST CSF certificate. If what you need is evidence for a customer or a tender, we will tell you to pursue ISO 27001 instead, and use CSF as the organising structure rather than the deliverable.

What the engagement looks like

  • Module 01 — Gap analysis against the six functions, with current and target profiles.
  • Module 02 — Build. Governance structure, control implementation and the roadmap between profiles.
  • Module 05 — Continuous compliance and periodic reassessment against the target profile.

Modules 03 and 04 do not apply in the certification sense. Where the work supports an ISO 27001 certification or a jurisdictional obligation, those modules apply to that programme.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

Can we be certified against NIST CSF?

No. There is no certification scheme and no certificate. If you need something to show a buyer, that is ISO 27001. NIST CSF is for organising and communicating your security posture.

What changed in CSF 2.0?

The most significant addition is the GOVERN function, which elevates governance, roles, policy and supply chain risk to sit alongside the original five. It reflects a recognition that most security programmes fail on governance rather than on technique.

NIST CSF or ISO 27001?

Different purposes. CSF is a voluntary framework for structuring and communicating; ISO 27001 is a certifiable management system. If a customer or tender demands evidence, you need 27001. If you need a way to organise a programme and report it to a board, CSF does that better. Using both is coherent and common.

Is it relevant in Australia?

Yes, and increasingly so. The WA Government Cyber Security Policy integrates it directly, and it is widely used by Australian enterprises as a reporting structure regardless of jurisdiction.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope