NIST CSF 2.0 Explained: Functions, Profiles, Tiers and Mapping
NIST CSF 2.0 explained - the six functions including Govern, profiles and tiers, mapping to ISO 27001 and CIS Controls, and how to use it outside the US.
By NetGuardUpdated: 8 min readنسخه فارسی

The NIST Cybersecurity Framework (CSF) is a voluntary set of cybersecurity outcomes published by the US National Institute of Standards and Technology to help organizations understand, prioritize and communicate cyber risk. NIST CSF 2.0, released in February 2024, is the current version, and its headline change is a sixth function, Govern, added to the original five.
The framework's value is that it describes what an organization should achieve, not how to achieve it with specific products or settings. That makes it a lightweight, adaptable roadmap that works alongside ISO 27001, CIS Controls and national regulations, including for organizations outside the United States. This guide walks through the structure of CSF 2.0, profiles and tiers, mappings to other standards, and where vulnerability management and hardening fit.
What is NIST CSF 2.0 and what changed?
The first version was published in 2014 with a focus on US critical infrastructure, and version 1.1 followed in 2018. Version 2.0 formally broadens the scope to organizations of every size and sector. The main changes:
- A new Govern function. Risk strategy, roles and responsibilities, policy and oversight, previously scattered, now have their own function.
- Supply chain risk. Managing suppliers and third-party products became a dedicated category under Govern.
- Reorganized categories. For example, Protect now has a Platform Security category covering secure configuration, software maintenance and log generation.
- Supporting resources. Quick Start Guides, Implementation Examples and online Informative References that map CSF outcomes to other standards.
The three-level structure
The CSF Core is hierarchical: 6 Functions, 22 Categories and 106 Subcategories. Each subcategory states one concrete outcome. ID.RA-01, for example, says that vulnerabilities in assets are identified, validated and recorded. This lets you assess the organization in detail while still reporting to the board at a high level.
The six NIST CSF 2.0 functions
The functions are not sequential steps. They run concurrently, with Govern acting as the umbrella over the other five.

| Function | Code | Main categories (high level) |
|---|---|---|
| Govern | GV | Organizational context, risk management strategy, roles and responsibilities, policy, oversight, supply chain risk management |
| Identify | ID | Asset management, risk assessment, improvement |
| Protect | PR | Identity and access control, awareness and training, data security, platform security, infrastructure resilience |
| Detect | DE | Continuous monitoring, adverse event analysis |
| Respond | RS | Incident management, incident analysis, reporting and communication, incident mitigation |
| Recover | RC | Recovery plan execution, recovery communication |
Govern
Govern connects cybersecurity to business objectives: who is accountable, what the organization's risk appetite is, and how policies are set and reviewed. Without it, the other functions tend to become a set of disconnected technical projects.
Identify and Protect
Identify means knowing which assets you have, which vulnerabilities affect them and which risks matter most. Protect means applying safeguards such as strong authentication, access management, data encryption, secure configuration and timely patching.
Detect, Respond and Recover
These three answer the questions that follow an attack: how quickly you notice, how you contain it and how fast you return to normal. Log monitoring, an incident response plan and tested backups all live here.
NIST CSF profiles and tiers
Organizational profiles: current and target
A Profile describes an organization in terms of CSF Core outcomes. The Current Profile shows which outcomes you achieve today; the Target Profile shows where you want to be, given your risks and business priorities. The gap between them becomes your action plan. CSF 2.0 also formalizes Community Profiles, shared baselines that a sector or group can develop for its members.
Implementation tiers
Tiers describe how rigorous and integrated your cybersecurity risk management is. They are not a maturity score for comparing organizations:
- Tier 1 - Partial: risk management is ad hoc and reactive.
- Tier 2 - Risk Informed: practices are approved but not applied organization-wide.
- Tier 3 - Repeatable: policies are formal and regularly updated.
- Tier 4 - Adaptive: the organization continuously improves using lessons learned and indicators.
Using NIST CSF outside the US
CSF is voluntary and is not tied to any law or regulator, so organizations anywhere can adopt it as a reference framework. A common pattern is to use CSF as the shared language for executive reporting, ISO 27001 for the management system and certification, and national requirements for legal obligations. In Iran, for example, organizations use it alongside AFTA security requirements. CSF does not replace those obligations, but it gives you a clean structure for organizing the evidence they require.
A practical way to start:
- Define the scope: the whole organization, one business unit or one critical system.
- Start with Govern: document risk owners, risk appetite and roles.
- Build the Current Profile from interviews, documents and technical evidence such as scan results.
- Define the Target Profile based on risk, legal requirements and budget.
- Prioritize the gaps and write an action plan with owners and deadlines.
- Track progress with measurable indicators and review the profiles periodically.
The full framework and its supporting resources are available on the NIST website.
Mapping NIST CSF to ISO 27001 and CIS Controls
If you already work with ISO 27001 or CIS Controls, much of the CSF work is done. NIST publishes official Informative References online, and CIS Controls v8.1 was updated to align with CSF 2.0. The table shows typical, high-level correspondences:
| CSF function | Example ISO/IEC 27001:2022 controls | Example CIS Controls v8.1 |
|---|---|---|
| Govern | Clauses 4-6, 5.1 policies, 5.19-5.23 suppliers | Control 15 Service Provider Management |
| Identify | 5.9 inventory of assets, 8.8 technical vulnerabilities | Controls 1, 2 and 7 |
| Protect | 5.15 access control, 8.9 configuration management, 8.13 backup | Controls 3, 4, 5, 6 and 14 |
| Detect | 8.15 logging, 8.16 monitoring activities | Controls 8 and 13 |
| Respond | 5.24-5.28 incident management | Control 17 |
| Recover | 5.29 and 5.30 continuity and ICT readiness | Control 11 Data Recovery |
These mappings are neither one-to-one nor complete. Use them to avoid duplicate work, not as proof of compliance.
Where vulnerability management and hardening fit
Vulnerability management and hardening are where the NIST Cybersecurity Framework turns from policy into practice:
- Identify - Asset Management (ID.AM): an up-to-date inventory of hardware, software and services is a prerequisite for every scan and policy.
- Identify - Risk Assessment (ID.RA): vulnerabilities are identified, validated, recorded and prioritized by likelihood of exploitation and business impact. See the vulnerability management lifecycle for the full process.
- Protect - Platform Security (PR.PS): configuration management practices, software maintenance and patching, and removal of unauthorized software. This is the work described in our system hardening guide and in CIS Benchmarks.
- Identify - Improvement (ID.IM) and Detect - Continuous Monitoring (DE.CM): rescanning after fixes, detecting configuration drift and feeding results back into improvement.
Evidence auditors usually ask for
For these outcomes, expect requests for periodic vulnerability scan reports, a secure configuration baseline per system type, compliance percentage against that baseline, mean time to remediate critical vulnerabilities, and records showing fixes were verified by a rescan.
How NetGuard helps with NIST CSF
NetGuard covers the technical side of Identify and Protect: authenticated and unauthenticated vulnerability scanning of servers, network devices, endpoints and databases; configuration audits against CIS Benchmarks and custom baselines; configuration drift detection; external attack surface discovery; and risk-based prioritization using exploit intelligence and asset criticality. Findings map to NIST, ISO 27001 and PCI DSS, reports are available for executives and engineers in English and Persian, and the platform can run on-premises or air-gapped. See the compliance page or contact us for details.
Frequently asked questions
Is there a NIST CSF certification?
No. NIST CSF is a voluntary framework and, unlike ISO 27001, there is no formal certification scheme for it. Organizations self-assess or engage an independent assessor to evaluate their current and target profiles. If you need a certificate to show customers or regulators, the usual approach is to structure the program with CSF and certify the management system against ISO 27001.
What is the difference between NIST CSF and ISO 27001?
ISO 27001 is the international standard for an information security management system (ISMS), with auditable requirements, 93 Annex A controls and a certification path. NIST CSF describes desired outcomes in six functions and leaves more freedom in how you implement them. They complement each other: CSF simplifies reporting to leadership, while ISO 27001 formalizes the management system and its improvement cycle.
What is the Govern function in NIST CSF 2.0?
Govern is the function added in version 2.0. It covers how an organization's cybersecurity strategy, expectations and policy are established, communicated and monitored. Its categories include organizational context, risk management strategy, roles and responsibilities, policy, oversight and cybersecurity supply chain risk management. Its purpose is to treat cybersecurity as part of enterprise risk management rather than as a purely technical topic.
Can organizations outside the US use NIST CSF?
Yes. CSF is free, voluntary and technology-neutral, and it is widely used outside the United States. Organizations can adopt it as a reference framework for structuring their security program and reporting to leadership while still meeting local regulations and standards such as ISO 27001. It does not replace legal obligations in any country; it simply helps organize the work and evidence they require.
How do I start implementing NIST CSF?
Start by defining scope and completing the Govern basics: risk owners, risk appetite and roles. Then build a Current Profile from real evidence such as your asset inventory and vulnerability scan results, define a Target Profile, and prioritize the gaps by risk. NIST's Quick Start Guides, including one aimed at small businesses, are a practical entry point.
- #NIST CSF 2.0
- #NIST Cybersecurity Framework
- #NIST CSF Govern function
- #NIST CSF profiles
- #NIST CSF tiers
- #NIST CSF ISO 27001 mapping




