NIST CSF

    NIST CSF 2.0 Explained: The Six Functions and How to Use Them

    Santhosh Kapalavai
    Sep 19, 2026
    NIST CSF
    NIST CSF 2.0 — a practical framework for managing cybersecurity risk, with the six core functions
    NIST CSF 2.0 — a practical framework for managing cybersecurity risk, with the six core functions

    From risk to resilience

    A stronger, more secure and resilient organisation starts with a framework. The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, is the most widely adopted one — flexible enough for a 20-person startup and rigorous enough for a bank.

    The basics

    What is NIST? The National Institute of Standards and Technology is a U.S. government organisation that develops standards, guidelines, frameworks and best practices to help organisations improve technology, cybersecurity, privacy and risk management.

    What is NIST CSF? A flexible framework that helps organisations manage and reduce cybersecurity risk. It provides a common language and structured approach to building organisational cyber resilience.

    • Why was it created?
    • Help organisations understand and manage cybersecurity risk
    • Provide a common language across business and technical teams
    • Prioritise security investments
    • Improve detection, response and recovery capabilities
    • Enhance resilience and build trust with customers and stakeholders

    The six core functions of CSF 2.0

    A continuous and adaptive approach to cybersecurity risk management:

    1. Govern — establish and monitor cybersecurity risk management. *New in 2.0*: it puts leadership accountability, roles, policy and oversight at the centre, recognising that cyber risk is a board-level business risk.
    2. Identify — understand assets, risks and the business environment
    3. Protect — implement safeguards to reduce cybersecurity risk
    4. Detect — identify and analyse potential cybersecurity events
    5. Respond — take action when a cybersecurity incident occurs
    6. Recover — restore affected capabilities and improve resilience

    Who can use NIST CSF?

    CSF is designed to be flexible — usable by organisations of all sizes across all industries: large enterprises, small and medium businesses, government bodies, financial organisations, healthcare, technology companies, cloud-based businesses and third-party supply-chain partners.

    Benefits of using NIST CSF

    • Structured cybersecurity risk management approach
    • Identify and prioritise cybersecurity risks
    • Improve security governance and oversight
    • Strengthen security controls and capabilities
    • Improve detection and response to cybersecurity events
    • Communicate cybersecurity risk effectively to leadership
    • Identify gaps between current and desired cybersecurity state
    • Support continuous improvement and resilience

    NIST CSF vs ISO/IEC 27001

    AspectNIST CSFISO/IEC 27001
    NatureCybersecurity risk management frameworkInformation Security Management System (ISMS) standard
    PurposeHelps manage and reduce cybersecurity riskDefines requirements for establishing, implementing and maintaining an ISMS
    StructureOrganised around 6 core functions (CSF 2.0)Organised around ISMS requirements and Annex A controls
    FlexibilityFlexible and adaptable to any organisationRequirements-based and prescriptive
    CertificationNot a certification standardCertification is available
    FocusFocus on managing cybersecurity riskFocus on establishing a formal ISMS
    Best used forRisk management, maturity assessment, gap analysis, alignmentISMS implementation, compliance, continuous improvement

    Many organisations use both: CSF to assess and communicate maturity, ISO 27001 when customers or regulators demand a certificate. The controls overlap substantially, so work done on one feeds the other.

    Key takeaway: NIST CSF is not just about controls — it is about building a culture of risk management, resilience and continuous improvement.

    IcyberWave helps organisations assess against NIST CSF 2.0 and build the road from current state to target profile. See how CSF maps to certifiable controls in our [ISO 27001 audit checklist](/blog/iso-27001-audit-checklist), or [talk to us](/contact) about a CSF gap assessment.

    Hi! I'm your AI Assistant 💬