Guide

NIST CSF 2.0, explained

For organisations baselining their security posture

The NIST Cybersecurity Framework is the most widely used way to describe an organisation's security posture in one shared language. Version 2.0, released in February 2024, expanded it from critical infrastructure to organisations of every size and sector, and added governance as a first-class concern. It is not a certification - it is the map customers, boards and regulators increasingly expect you to be able to point at.

The six functions

CSF 2.0 organises security outcomes into six functions, each broken into categories and subcategories:

Two ideas make the framework practical. Tiers (1 Partial to 4 Adaptive) describe how rigorous and repeatable your risk management is. Profiles capture where you are now against where you have decided to be - the gap between the two is your security roadmap, stated in a form a board can approve.

The sensible order of work

How Assura helps

Assura includes a guided NIST CSF 2.0 assessment among its 20 frameworks. You answer in plain English, attach evidence as you go, and Assura scores each outcome with written reasoning. When you finish you get the full picture in one pass:

Baseline your posture with Assura

Related guides: Cyber Essentials · ISO 27001 · SOC 2