NIST CSF 2.0, explained
For organisations baselining their security posture
The NIST Cybersecurity Framework is the most widely used way to describe an organisation's security posture in one shared language. Version 2.0, released in February 2024, expanded it from critical infrastructure to organisations of every size and sector, and added governance as a first-class concern. It is not a certification - it is the map customers, boards and regulators increasingly expect you to be able to point at.
The six functions
CSF 2.0 organises security outcomes into six functions, each broken into categories and subcategories:
- Govern - new in 2.0: risk strategy, roles and responsibilities, policy, oversight, and supply-chain risk management.
- Identify - know your assets, your risks and your improvement priorities.
- Protect - access control, awareness training, data security, platform hardening and resilient infrastructure.
- Detect - continuous monitoring and analysis that spots adverse events early.
- Respond - incident management, analysis, communication and mitigation.
- Recover - restoring operations and communicating honestly while you do.
Two ideas make the framework practical. Tiers (1 Partial to 4 Adaptive) describe how rigorous and repeatable your risk management is. Profiles capture where you are now against where you have decided to be - the gap between the two is your security roadmap, stated in a form a board can approve.
The sensible order of work
- 1. Baseline honestly. Assess your current profile across all six functions before deciding targets - most organisations discover Govern and Recover are far weaker than Protect.
- 2. Set the target profile from business risk, not from a wish to score well. Not everything needs Tier 4.
- 3. Close the gaps in priority order, starting where the distance between current and target is largest on the risks that matter most.
- 4. Keep evidence as you go - the framework is voluntary, but the customers and insurers who ask about it want proof, not assertions.
- 5. Re-assess on a cadence. The value of CSF is trend, not snapshot: posture this quarter against last, gaps closing or not.
How Assura helps
Assura includes a guided NIST CSF 2.0 assessment among its 20 frameworks. You answer in plain English, attach evidence as you go, and Assura scores each outcome with written reasoning. When you finish you get the full picture in one pass:
- a scored posture view across all six functions - your current profile, ready to put in front of a board or customer;
- a prioritised gap list and remediation plan, ranked by severity;
- a live risk register that tracks each fix through to done;
- and because Assura maps controls across frameworks, your CSF work pre-fills its counterparts when you take on ISO 27001, SOC 2 or Cyber Essentials - and vice versa.
Baseline your posture with Assura
Related guides: Cyber Essentials · ISO 27001 · SOC 2