BLOG
NIST CSF 2.0 The Six Functions Explained Without the Jargon
Published 12 August 2026 ยท By P Larner
Frameworks & Standards#cyber security framework#maturity#governance#profiles#NIST CSF
NIST CSF 2.0: The Six Functions Explained Without the Jargon
Illustration for: NIST CSF 2.0: The Six Functions Explained Without the Jargon
NIST published version 2.0 of its Cybersecurity Framework in February 2024, the first full revision since the original appeared in 2014. The scope is now every organisation, not just US critical infrastructure, and there is a sixth function called Govern. This article explains what each function actually covers, what changed from 1.1, and how a small team can put the framework to work without hiring consultants.
A short history, and what the CSF is not
The CSF grew out of a 2013 US executive order asking NIST to produce a voluntary framework for critical infrastructure. Version 1.0 arrived in 2014, and 1.1 followed in 2018 with modest additions around supply chain and self-assessment. Adoption spread well beyond the US, including plenty of UK organisations that use it internally even while certifying against ISO 27001.
Two things it is not. It is not a certification standard, because nobody can audit you โagainst the CSFโ in the way a UKAS-accredited body certifies you against ISO 27001. And it is not a control catalogue with prescriptive settings. It is a taxonomy of outcomes, meaning a shared structure for describing what good looks like, assessing where you are, and reporting to people who do not read firewall configs.
The six functions in plain terms
The framework core has six functions, which break down into 22 categories and 106 subcategory outcomes.
- Govern (GV) decides who owns cyber risk and how decisions get made. Risk appetite, policy, roles and responsibilities, oversight, and supply chain risk strategy all live here. This is the โwho is accountable and why do we careโ function.
- Identify (ID) is about knowing what you have and what threatens it. Asset inventories, risk assessments, and identifying improvements. You cannot protect a server nobody has recorded.
- Protect (PR) holds the controls that reduce the likelihood or impact of a bad day. Identity and access management, awareness training, data security, platform hardening, and resilient technology infrastructure.
- Detect (DE) is about spotting adverse events quickly. Continuous monitoring and the analysis needed to tell a genuine incident from noise.
- Respond (RS) covers what you do once an incident is confirmed. Incident management, analysis, internal and external reporting, and containment.
- Recover (RC) restores services and communicates honestly while you do it. Restoration planning and incident recovery communications.
Hierarchy diagram of the NIST CSF 2.0 core with six function blocks at the top, a band of 22 categories in the middle and 106 subcategory outcomes at the bottom, and Govern highlighted and informing the other five functions
The CSF 2.0 core, where six functions break down into 22 categories and 106 subcategory outcomes, with Govern informing the other five.
Each subcategory is an outcome statement, not a control. The outcome ID.AM-01, โInventories of hardware managed by the organization are maintainedโ, tells you the end state and leaves the how to you.
What changed from 1.1
The headline change is Govern. In 1.1, governance content sat awkwardly inside Identify and was easy to skip. Pulling it out into its own function was a deliberate signal that cyber risk is a business risk owned by leadership, not a technical hobby delegated to the IT manager. In practice, the Govern outcomes are where board reporting, risk appetite statements and policy ownership get anchored.
Supply chain also got a serious upgrade. GV.SC is a dedicated category with ten outcomes covering supplier due diligence, contractual security requirements, incident notification obligations and termination handling. Given how many 2023 and 2024 incidents arrived through suppliers, this emphasis is overdue rather than fashionable.
Three other changes are worth knowing.
- The title dropped โcritical infrastructureโ. The framework now explicitly targets organisations of any size and sector.
- NIST published implementation examples for every subcategory, plus quick-start guides for small businesses and for supply chain risk. These are genuinely useful and free.
- Informative references, meaning the mappings to ISO 27001, SP 800-53, CIS Controls and others, moved online so they can be updated without a new framework version.
Profiles and tiers, minus the mystery
Profiles sound grander than they are. A current profile is your honest assessment of each outcome today. A target profile is where you need to be, based on your risk, sector and obligations. The gap between the two is your improvement roadmap. NIST also publishes community profiles for specific sectors and technologies, which save you deciding priorities from scratch.
Grouped bar chart comparing illustrative current and target profile maturity scores across the six CSF functions, with the largest gap bridged by an arrow on Govern
A current profile beside a target profile, where the gaps, biggest here on Govern, become the improvement roadmap.
Tiers (1 Partial, 2 Risk Informed, 3 Repeatable, 4 Adaptive) describe how rigorous your overall risk governance is, not a per-control maturity score. A common mistake is treating Tier 4 as the goal. For most organisations, Tier 3 is a sensible and defensible target, and Tier 4 across the board is a waste of money. Pick a tier deliberately and write down why.
How a small team actually uses it
Here is a worked example. A three-person security function in a 400-person company can do this in about two weeks of part-time effort.
- Build a spreadsheet with the 106 outcomes, one row each. Add columns for status (achieved, partial, not achieved), evidence, owner and target.
- Timebox the assessment to half a day per function, starting with Govern. Be honest. โPartialโ with a note is more useful than a generous โachievedโ.
- Map existing work rather than duplicating it. If you already run ISO 27001 Annex A controls or the CIS Controls, use the published mappings and reuse your evidence.
- Pick no more than ten gaps for the next quarter, weighted by risk, and assign owners with dates.
- Report to the board using the six functions as headings. Six bars on one slide beats forty rows of RAG status, and executives grasp Govern-to-Recover intuitively.
Five-step flowchart of a small teamโs two-week CSF assessment, from building the 106-row spreadsheet to a one-slide board report, with a return arrow from step five back to step two labelled repeat every 6 to 12 months
Five steps and about two weeks of part-time effort, then repeat the assessment every six to twelve months.
Repeat the assessment every six or twelve months. The value is in the trend line, not the first snapshot.
Where it fits alongside other frameworks
The CSF is an organising structure, so it coexists happily with almost everything. ISO 27001 gives you a certifiable management system, while the CSF gives you a way to describe coverage and maturity. The CIS Controls give you prescriptive technical steps for the Protect and Detect outcomes. UK operators of essential services will find the NCSC Cyber Assessment Framework closer to their regulatory reality, but the two map reasonably well and plenty of organisations use CSF internally and CAF for the regulator.
Making a start
Download the framework document, which runs to around 30 pages and is far shorter than its reputation suggests. Read the Govern function first and score yourselves against it this week, because that is where most gaps with real consequences hide. Then build the spreadsheet, run the half-day-per-function assessment, and take one slide of results to your next leadership meeting. You will get more traction from that slide than from any amount of technical reporting, and you will have a defensible answer the next time someone asks what your security programme is actually based on.
NIST CSF 2.0 posture dashboard in RaptorGRC
NIST CSF 2.0 posture tracking in RaptorGRC.
Run your GRC programme in your own network.
RaptorGRC Community Edition is free โ every module, offline licence activation, nothing phones home.
Register / Download Contact us