Back to Guides
Guide16 September 2026

What Is the NIST Cybersecurity Framework and How Do You Apply It in 2025?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is the NIST Cybersecurity Framework (CSF 2.0)?
  3. How is the CSF 2.0 structured?
  4. What are the Implementation Tiers and why do they matter?
  5. How do I build a Current and Target Profile?
  6. Where do I find concrete controls for each Sub - category?
  7. How does CSF 2.0 address supply - chain and privacy?
  8. Practical steps to adopt CSF 2.0 in 2025
  9. How can I measure progress over time?
  10. Frequently asked questions

Key takeaways

What is the NIST Cybersecurity Framework (CSF 2.0)?

The NIST CSF 2.0 is the latest edition of the voluntary, sector - neutral framework released on 26 Feb 2024. It does not prescribe specific technical controls; instead it defines outcomes and links each outcome to external standards such as NIST SP 800 - 53 or ISO 27001. Organizations adopt it to understand, assess, prioritize, and communicate cybersecurity risk.

How is the CSF 2.0 structured?

The Core of CSF 2.0 is a three - level taxonomy:

  1. 6 Functions - Govern, Identify, Protect, Detect, Respond, Recover (Govern is new in 2.0).
  2. 22 Categories - high - level groupings under each Function (down from 23 in CSF 1.1).
  3. 106 Sub - categories - specific outcomes that can be measured (down from 108). Each Sub - category points to informative references so you can pick concrete controls that satisfy the outcome.

What are the Implementation Tiers and why do they matter?

Implementation Tiers describe the rigor of an organization’s risk - governance and management practices. The four tiers are:

How do I build a Current and Target Profile?

  1. Select the Functions, Categories, and Sub - categories that are relevant to your business context.
  2. Assess each Sub - category against your existing practices and mark it as Not Implemented, Partially Implemented, or Fully Implemented - this is your Current Profile.
  3. Define a Desired State for each Sub - category based on risk appetite, regulatory requirements, and resource constraints - this becomes your Target Profile.
  4. Gap Analysis - compare the two profiles to prioritize remediation efforts. Focus first on high - impact gaps that affect the Govern function, as leadership buy - in drives all other improvements.

Where do I find concrete controls for each Sub - category?

Every Sub - category includes a list of informative references. For example, the sub - category PR.DS - 1: Data-at-rest is protected links to NIST SP 800 - 53 SC - 28 and ISO 27001 A.10.1. Use those references to select controls that match your technology stack and compliance obligations.

How does CSF 2.0 address supply - chain and privacy?

CSF 2.0 expands supply - chain risk management with new categories such as GV.SC - 04 (supply - chain risk governance) and GV.SC - 06 (supplier - related privacy). Privacy considerations are woven throughout all Functions, ensuring that data - handling practices are evaluated alongside traditional security controls.

Practical steps to adopt CSF 2.0 in 2025

StepActionOutput
1Download the official CSF 2.0 PDF (CSWP 29)Full reference document
2Review the Small - Business Quick - Start Guide (if applicable)High - level overview
3Conduct a workshop with leadership to define risk appetite and governance goals (Govern function)Governance charter
4Map relevant Sub - categories to existing controls using informative referencesControl mapping spreadsheet
5Populate a Current Profile in a simple matrix (Function → Category → Sub - category)Current profile matrix
6Define a Target Profile aligned with business objectives and regulatory driversTarget profile matrix
7Perform gap analysis and prioritize remediation based on impact and effortPrioritized remediation list
8Implement selected controls, then reassess to update the Current ProfileUpdated profile and evidence of control implementation
9Review and upgrade your Implementation Tier as processes become repeatable or adaptiveNew tier designation

How can I measure progress over time?

Frequently asked questions

Does CSF 2.0 replace existing regulations? No. It is a voluntary framework that can be layered on top of regulations such as GDPR, HIPAA, or industry - specific mandates.

Do I need to implement every Sub - category? No. You select the Sub - categories that align with your risk profile and compliance needs. The framework’s flexibility lets you focus on what matters most.

Is the Govern function only for large enterprises? No. Governance is essential for any organization; the Quick - Start Guide shows how small businesses can adopt basic governance practices.

How does CSF 2.0 relate to other frameworks like ISO 27001? CSF 2.0’s informative references map directly to ISO 27001 controls, making it easy to use CSF as a high - level risk view while relying on ISO 27001 for detailed implementation.


For deeper guidance, see NIST’s official CSF 2.0 publication and the Small - Business Quick - Start Guide.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary