← ALL FRAMEWORKS

NIST Cybersecurity Framework (CSF)

Information Security

Issued by National Institute of Standards and Technology (NIST)

NIST Cybersecurity Framework (CSF) 2.0, published February 2024, organizes cybersecurity risk management around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover — the 2.0 revision added Govern as a new function and broadened the framework's scope beyond critical infrastructure to organizations of any size or sector. It's not a certifiable standard; organizations self-assess and reference it through industry-specific "Profiles" and maturity "Tiers" rather than pursuing formal certification. It's widely adopted across US industry and government and commonly mapped to other frameworks (ISO 27001, SOC 2) in vendor security questionnaires, given NIST's central role in defining most US cybersecurity control baselines.

Get notified the moment NIST Cybersecurity Framework (CSF) actually changes — reviewed by a human before it ever reaches you.

Get started free

Most recent update

minor

The NIST CSF Updates Archive gained two new entries since the last check: the final version of the CSF 2.0 Informative References Quick-Start Guide has been published (explaining how to find, filter, and apply informative references using NIST tools, with AI-supported use cases), and CSF 2.0 has now been translated into Arabic.

VIEW SOURCE ↗

▸ 1 EARLIER UPDATE IN THE FULL HISTORY

The complete change log for NIST Cybersecurity Framework (CSF) — every confirmed update, with severity and source — is included in every account, free ones too.

Sign up free to see the full history