NIST Cybersecurity Framework (CSF) 2.0: A Practical Implementation Guide
The CSF is the foundational cybersecurity framework nearly every U.S. regulator, cyber insurer, and enterprise procurement team references — and it is a different document from the NIST AI Risk Management Framework. This guide covers the six CSF 2.0 functions, how the two frameworks relate, and a practical way to measure your maturity.
Schedule a Consultation →The NIST Cybersecurity Framework (CSF) 2.0, published by the National Institute of Standards and Technology on February 26, 2024, is a voluntary, sector-agnostic framework for managing cybersecurity risk. Unlike its 2014 and 2018 predecessors, which were written primarily for critical infrastructure operators, CSF 2.0 was explicitly broadened for organizations of any size, sector, or maturity level — including the mid-market regulated organizations that make up most of the U.S. economy. It is not a certification and it is not audited the way SOC 2 or CMMC are; it is a common vocabulary and structure for describing, assessing, and improving a cybersecurity program.
The Baseline Everyone Is Quietly Measuring You Against
CSF adoption is voluntary, but it has become the default reference point in places that are not voluntary at all. Cyber insurance underwriting questionnaires map their control questions to CSF categories. State breach-notification and data-security statutes increasingly cite CSF alignment as a safe-harbor factor. Enterprise vendor risk assessments and board-level security reporting both lean on its six-function structure because it gives non-technical stakeholders a shared way to talk about risk without requiring them to read control-by-control audit language.
For a healthcare group, manufacturer, financial services firm, or defense subcontractor already juggling HIPAA, GLBA, or CMMC obligations, CSF is not one more compliance program to run in parallel — it is the organizing structure most of those programs already borrow from underneath.
The Six CSF 2.0 Functions
CSF 1.1 organized risk management around five functions. CSF 2.0 added a sixth — Govern — and positioned it at the center, because a program that identifies, protects, detects, responds, and recovers without a governance layer directing it tends to drift into a checklist with no owner.
GOVERN
New in 2.0. Establishes and monitors risk management strategy, roles, policy, and supply-chain risk oversight. Sits at the center and informs the other five.
IDENTIFY
Understand assets, data, systems, and the risks to them — asset management, risk assessment, and improvement planning.
PROTECT
Safeguards to manage risk — access control, awareness and training, data security, and platform hardening.
DETECT
Timely discovery of anomalies and adverse events through continuous monitoring.
RESPOND
Actions taken once an incident is detected — response planning, analysis, mitigation, and communication.
RECOVER
Timely restoration of operations and capabilities, with continuous improvement fed back into the program.
CSF 2.0 Is Not the AI RMF
These are two different NIST publications solving two different problems, and mid-market security leaders regularly conflate them because both are voluntary, both use a small set of named functions, and both come from the same agency. The Cybersecurity Framework is the general-purpose risk framework for any information system — networks, applications, cloud infrastructure, identity, data. It organizes work around the six functions above and asks: is this system’s confidentiality, integrity, and availability adequately protected and governed?
The NIST AI Risk Management Framework (AI RMF), published in January 2023, is purpose-built for a narrower and different problem: the trustworthiness of AI systems specifically. It uses four functions — Govern, Map, Measure, Manage — and asks a different set of questions, centered on whether an AI system is valid and reliable, safe, secure and resilient, accountable and transparent, explainable, privacy-enhanced, and fair with harmful bias managed. A model can run on infrastructure that is fully CSF-compliant and still fail every one of those AI-specific tests.
In practice the two are layered, not competing. CSF is the foundation — the identity, access, logging, and incident-response controls an AI system inherits from the infrastructure it runs on. AI RMF sits on top of that foundation and governs the AI-specific risks CSF was never built to address, like model drift, training-data bias, and adversarial prompt manipulation. Organizations that have only implemented one are missing half the picture; see our NIST AI RMF implementation guide for the AI-specific layer.
A Practical Maturity-Assessment Approach
CSF 2.0 measures maturity two ways, and confusing them is a common early mistake. Organizational Profiles describe outcomes — a Current Profile documenting which of the roughly 100 subcategory outcomes across the six functions you actually achieve today, and a Target Profile documenting which ones you need to achieve, prioritized by business risk. Implementation Tiers describe rigor — not what you do, but how consistently and formally you do it, on a four-point scale from Tier 1 (Partial, informal and reactive) through Tier 2 (Risk-Informed), Tier 3 (Repeatable, documented and consistently applied), to Tier 4 (Adaptive, data-driven and integrated with business strategy).
A workable first assessment runs in five steps: scope the engagement to the business units and systems in play; build the Current Profile by scoring each subcategory against evidence, not aspiration; assign a Tier based on how consistently governance and risk decisions actually happen; build a Target Profile prioritized by what a real risk assessment says matters most, not by which subcategories are easiest to close; and turn the gap between the two profiles into a sequenced action plan with owners and dates. NIST’s own CSF 2.0 resource center and its published Quick-Start Guide for using the Tiers are the right starting reference documents for any team running this exercise for the first time; the full framework text is available as NIST.CSWP.29.
The output that matters is not a maturity score for its own sake — it is a prioritized, owned backlog that a board or an auditor can be shown, and that maps cleanly to whatever adjacent obligation (SOC 2, CMMC, HIPAA, an AI governance program) is driving the underlying work.
Ready to Build a CSF Profile That Survives Scrutiny?
Armorstack builds CSF 2.0 Current and Target Profiles for mid-market regulated organizations, maps them into SOC 2, HIPAA, and CMMC evidence, and runs the program as a managed service so the profile stays current instead of going stale after the first assessment.
Schedule a Consultation →