NIST released version 2.0 of its Cybersecurity Framework (CSF) on February 26, 2024, the first major revision since version 1.1 in 2018. The headline change is a sixth function, Govern, which covers how your organization sets, communicates and monitors its cybersecurity strategy, expectations and policy. In practical terms, Govern asks you to show that leadership owns cyber risk, that roles and policies are clear, that someone is checking whether the strategy works, and that supplier risk is managed on purpose rather than by accident.

What changed in NIST CSF 2.0?

CSF 2.0 keeps the outcome-based structure people know from earlier versions, but it reorganizes and broadens the framework. The main changes are:

  • A sixth function. The Core now has six functions: Govern, Identify, Protect, Detect, Respond and Recover.
  • A wider audience. Version 1.1 was titled Framework for Improving Critical Infrastructure Cybersecurity. Version 2.0 is simply The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29), and NIST says it is meant for organizations of any size and sector, not only critical infrastructure.
  • Governance pulled into one place. Several governance-related categories that sat under Identify in 1.1 (business environment, governance, risk management strategy and supply chain risk management) now live under Govern, and they have been expanded.
  • More supporting material. NIST published quick-start guides, implementation examples, a searchable CSF 2.0 Reference Tool and a catalog of informative references alongside the framework.

You can read the framework itself in the CSF 2.0 publication and NIST's summary in its release announcement.

What is the Govern function in NIST CSF 2.0?

NIST describes Govern this way: "The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored."

In the framework's diagram, Govern sits in the center of the wheel, with the other five functions around it. NIST explains the placement directly: Govern "informs how an organization will implement the other five Functions." Identify, Protect, Detect, Respond and Recover describe what you do. Govern describes who decides, on what basis, and how you know it's working.

The six Govern categories

Govern contains six categories and 31 subcategories.

ID Category What it asks of you
GV.OC Organizational Context Understand your mission, stakeholders, dependencies and legal, regulatory and contractual requirements
GV.RM Risk Management Strategy Set priorities, constraints, risk appetite and risk tolerance, and use them to guide decisions
GV.RR Roles, Responsibilities, and Authorities Make people accountable for cyber risk, and give them the authority and resources to act
GV.PO Policy Establish, communicate, enforce and regularly review cybersecurity policy
GV.OV Oversight Review whether the strategy is producing results and adjust it
GV.SC Cybersecurity Supply Chain Risk Management Run a deliberate program for managing risk from suppliers and other third parties

A few subcategories are worth reading word for word, because they set the tone for the rest:

  • GV.RR-01: "Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving."
  • GV.RM-02: "Risk appetite and risk tolerance statements are established, communicated, and maintained."
  • GV.RM-03: "Cybersecurity risk management activities and outcomes are included in enterprise risk management processes."
  • GV.RR-03: "Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies."
  • GV.SC-04: "Suppliers are known and prioritized by criticality."

The supply chain category is the largest in Govern, with ten subcategories. They cover the full relationship with a supplier, from due diligence before signing, through contract requirements and ongoing monitoring, to what happens after the relationship ends.

Why did NIST add a Govern function?

Governance was never absent from the CSF. In version 1.1 it was spread across several Identify categories, where it was easy to treat as background rather than as a set of outcomes to achieve.

Giving governance its own function does three things. It signals that cybersecurity is a leadership responsibility, not only a technical one. It ties cyber risk to enterprise risk management, so security decisions get weighed against other business risks using the same language. And it makes oversight explicit: having a strategy isn't enough, and someone has to review whether it's working.

In practice, security teams now have a framework-backed reason to ask executives for overdue decisions, such as defining acceptable risk or funding the controls needed to stay within it.

What does Govern mean for small and mid-sized organizations?

CSF 2.0 is outcome-based. It tells you what a good result looks like, not which tools or procedures to use. That flexibility matters for smaller teams, because Govern doesn't require a board committee or a dedicated GRC function.

What it does require is clarity. For a 200-person company, meeting Govern might look like this:

  • A named executive who is accountable for cyber risk and reports on it to leadership at a set interval.
  • A short written statement of how much risk the business is willing to accept in areas such as downtime, data exposure and regulatory penalties.
  • A list of the legal, regulatory and contractual security obligations the company has actually agreed to.
  • Policies that match how the business operates today, with a review date and an owner.
  • A ranked list of suppliers, with the most critical ones reviewed before contracts are signed and at intervals afterward.
  • Security built into HR processes such as onboarding, role changes and departures (GV.RR-04).

None of this is exotic. The difference is that CSF 2.0 now calls these outcomes out by name, so gaps are harder to overlook.

How do organizational profiles and tiers work in CSF 2.0?

Profiles and tiers are the two tools NIST gives you to apply the framework to your situation. Both carry over from version 1.1 but are described more clearly in 2.0.

Organizational profiles

An organizational profile describes your cybersecurity posture in terms of CSF outcomes. There are two kinds:

  • A Current Profile records which outcomes you achieve today and to what extent.
  • A Target Profile records the outcomes you want to achieve, prioritized for your objectives and any changes you expect.

CSF 2.0 lays out a five-step cycle for building and using profiles:

  1. Scope the profile, and document the facts and assumptions behind it.
  2. Gather the information needed to prepare it, such as policies, risk priorities and requirements.
  3. Create the profile by selecting the CSF outcomes that apply and recording where you stand.
  4. Analyze the gaps between the Current and Target Profiles and build an action plan.
  5. Implement the plan and update the profiles as you go.

NIST also describes Community Profiles, which are baselines of CSF outcomes published for groups with shared interests, such as a sector or a type of technology. A Community Profile can be a useful starting point for your own Target Profile.

Tiers

Tiers describe how rigorous your cybersecurity risk governance and management practices are. There are four:

  1. Partial: ad hoc and largely reactive.
  2. Risk Informed: risk-aware, but not applied consistently across the organization.
  3. Repeatable: formally approved policies that are applied consistently and kept up to date.
  4. Adaptive: practices that adjust based on lessons learned and changes in risk.

Tiers aren't a scoreboard where Tier 4 is always the goal. The right tier depends on your risk and resources. A small professional services firm might reasonably aim for Repeatable, while an organization that other businesses depend on may need to be Adaptive in some areas.

What supporting resources came with CSF 2.0?

NIST shipped supplementary resources alongside the framework. For day-to-day work, they're often more useful than the framework document itself.

  • Quick-start guides. Short documents aimed at specific audiences. At release, the small business guide (NIST SP 1300) and a guide to creating and using organizational profiles (NIST SP 1301) were published in final form. Guides on enterprise risk management and on cybersecurity supply chain risk management were released as drafts.
  • Implementation examples. NIST calls these "concise, action-oriented, notional illustrations" of ways to achieve each outcome. They're examples, not requirements.
  • Informative references. Mappings between CSF outcomes and other standards and guidelines. NIST says organizations can cross-reference the CSF to more than 50 other cybersecurity documents.
  • CSF 2.0 Reference Tool. A searchable, exportable view of the Core in both human-readable and machine-readable formats.

How to put the Govern function into practice

The fastest route is to treat Govern as your first profile exercise. Here's the sequence we suggest:

  1. Confirm who owns cyber risk. Name the accountable executive, agree on how often they'll review risk with leadership, and write it down.
  2. Document your context. Record your mission, key stakeholders, critical services, dependencies and the security obligations in your contracts and regulations (GV.OC).
  3. Draft risk appetite and tolerance statements. Keep them short and specific enough to guide real decisions. "We will not accept more than four hours of downtime for customer-facing systems" is more useful than "We have a low appetite for risk."
  4. Map roles and authorities. Clarify who approves exceptions, who can accept risk, and who has budget authority for security (GV.RR).
  5. Review your policies. Check that each policy reflects current operations, has an owner, and has a review date (GV.PO).
  6. Set up oversight. Pick a small number of measures that show whether the strategy is working, and review them on a fixed schedule (GV.OV).
  7. Inventory and rank suppliers. Start with the vendors whose failure or compromise would hurt most, then build security requirements into their contracts and reviews (GV.SC).
  8. Record your Current and Target Profiles for Govern. Use the gap between them to build a prioritized, funded action plan.

Keep the first pass small. A Govern profile that fits on a few pages and gets reviewed every quarter is worth more than a thorough one nobody opens.

Frequently asked questions

Is NIST CSF 2.0 mandatory?

No. The CSF is a voluntary framework. Customers, partners or sector bodies may ask you to show alignment with it, but the framework itself imposes no legal requirement.

We already use CSF 1.1. Do we need to start over?

No. Most outcomes carry forward, although some have been reworded, merged or moved. The biggest structural change is that governance and supply chain outcomes from Identify now sit under Govern. Plan to remap your existing profile rather than rebuild it.

Does Govern replace ISO 27001 or other frameworks?

No. The CSF describes outcomes and points to other standards through its informative references. Many organizations use the CSF as a common language for leadership while running a certifiable standard or a control catalog underneath it.

Is the Govern function only for large enterprises?

No. NIST broadened CSF 2.0 specifically to reach organizations of all sizes, and published a small business quick-start guide at launch. Smaller organizations can meet Govern outcomes with lightweight documents and a regular leadership review.

Key takeaways

  • CSF 2.0, released February 26, 2024, adds Govern as a sixth function at the center of the framework.
  • Govern has six categories: organizational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management.
  • The framework now explicitly targets organizations of every size and sector.
  • Profiles and tiers are your tools for turning Govern into a plan. Start with a Current and Target Profile for Govern alone.
  • Use the quick-start guides and implementation examples. They're practical, and they save time.