Skip to content
05/14FrameworkSupported in Compscan

NIST Cybersecurity Framework (NIST CSF 2.0)

A risk-management framework that structures security around six functions.

What it is

NIST CSF organizes cybersecurity into Govern, Identify, Protect, Detect, Respond, Recover. CSF 2.0 (2024) added Govern and is explicitly intended for organizations of any size or sector. It's outcome-oriented rather than prescriptive — it tells you what good looks like and lets you choose how to get there, which makes it a strong common language across teams and with leadership.

Certifiable?

No official certification — used for self-assessment and program structure.

Where it's used

US-centric in origin but widely adopted globally.

Effort level

Flexible; scales to the maturity you target.

Typical trigger

Leadership wants a coherent way to talk about and prioritize risk.

Related frameworks

A structuring layer that maps down to CIS Controls and NIST 800-53.

Why it matters

NIST CSF provides a common language for discussing cybersecurity risk across technical, management, and executive levels. It helps organizations understand their current posture, set target states, and communicate progress in business terms.

When is it needed?

When leadership asks 'where do we stand on cybersecurity?', when building or restructuring a security program, when you need a framework that scales from startup to enterprise, or when communicating risk to a board.

Use cases

  • Structuring a security program from scratch
  • Reporting cybersecurity posture to the board
  • Conducting gap assessments against a neutral framework
  • Aligning multiple teams under a shared model
  • Mapping existing controls to a recognized structure

Who asks for it?

  • CISOs and security leadership for program structure
  • Board members wanting risk visibility
  • US government agencies and contractors
  • Insurance providers assessing program maturity
  • Industry groups recommending baseline frameworks

Benefits

  • Outcome-oriented — describes 'what good looks like' without being prescriptive
  • Scales from small business to critical infrastructure
  • Free, open, and maintained by NIST
  • CSF 2.0 adds Govern function for leadership accountability
  • Maps to CIS Controls, 800-53, ISO 27001 for deeper implementation
  • Widely recognized across industries and borders

Legal requirements

Not legally mandated for most private organizations, but executive orders have required it for US federal agencies. Increasingly referenced in sector-specific regulations and insurance questionnaires.

Key control areas

Govern: organizational context, risk strategy, oversight
Identify: asset management, risk assessment, supply chain
Protect: access control, awareness, data security
Detect: continuous monitoring, anomaly detection
Respond: incident management, analysis, mitigation
Recover: recovery planning, communications, improvements

Want to see how Compscan maps your environment to NIST Cybersecurity Framework (NIST CSF 2.0)?