Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What is the NIST Cybersecurity Framework (CSF 2.0)?
- How is the CSF 2.0 structured?
- What are the Implementation Tiers and why do they matter?
- How do I build a Current and Target Profile?
- Where do I find concrete controls for each Sub - category?
- How does CSF 2.0 address supply - chain and privacy?
- Practical steps to adopt CSF 2.0 in 2025
- How can I measure progress over time?
- Frequently asked questions
Key takeaways
- CSF 2.0 adds a Govern function and reduces the taxonomy to 6 Functions, 22 Categories, 106 Sub - categories.
- Four Implementation Tiers (Partial, Risk - Informed, Repeatable, Adaptive) describe the maturity of risk - governance practices.
- Create a Current and Target profile to map your organization’s state and define a road - map.
- Use the informative references (e.g., NIST SP 800 - 53, ISO 27001) to select concrete controls for each Sub - category.
- Start with the free NIST Quick - Start Guide for small businesses, then expand to a full profile for enterprise use.
What is the NIST Cybersecurity Framework (CSF 2.0)?
The NIST CSF 2.0 is the latest edition of the voluntary, sector - neutral framework released on 26 Feb 2024. It does not prescribe specific technical controls; instead it defines outcomes and links each outcome to external standards such as NIST SP 800 - 53 or ISO 27001. Organizations adopt it to understand, assess, prioritize, and communicate cybersecurity risk.
How is the CSF 2.0 structured?
The Core of CSF 2.0 is a three - level taxonomy:
- 6 Functions - Govern, Identify, Protect, Detect, Respond, Recover (Govern is new in 2.0).
- 22 Categories - high - level groupings under each Function (down from 23 in CSF 1.1).
- 106 Sub - categories - specific outcomes that can be measured (down from 108). Each Sub - category points to informative references so you can pick concrete controls that satisfy the outcome.
What are the Implementation Tiers and why do they matter?
Implementation Tiers describe the rigor of an organization’s risk - governance and management practices. The four tiers are:
- Tier 1 - Partial - ad - hoc processes, limited risk awareness.
- Tier 2 - Risk - Informed - risk decisions are based on documented processes.
- Tier 3 - Repeatable - consistent, formalized processes across the organization.
- Tier 4 - Adaptive - continuous improvement and proactive adaptation to emerging threats. Tiers are applied to each Function, allowing you to see where you are strong and where you need to mature.
How do I build a Current and Target Profile?
- Select the Functions, Categories, and Sub - categories that are relevant to your business context.
- Assess each Sub - category against your existing practices and mark it as Not Implemented, Partially Implemented, or Fully Implemented - this is your Current Profile.
- Define a Desired State for each Sub - category based on risk appetite, regulatory requirements, and resource constraints - this becomes your Target Profile.
- Gap Analysis - compare the two profiles to prioritize remediation efforts. Focus first on high - impact gaps that affect the Govern function, as leadership buy - in drives all other improvements.
Where do I find concrete controls for each Sub - category?
Every Sub - category includes a list of informative references. For example, the sub - category PR.DS - 1: Data-at-rest is protected links to NIST SP 800 - 53 SC - 28 and ISO 27001 A.10.1. Use those references to select controls that match your technology stack and compliance obligations.
How does CSF 2.0 address supply - chain and privacy?
CSF 2.0 expands supply - chain risk management with new categories such as GV.SC - 04 (supply - chain risk governance) and GV.SC - 06 (supplier - related privacy). Privacy considerations are woven throughout all Functions, ensuring that data - handling practices are evaluated alongside traditional security controls.
Practical steps to adopt CSF 2.0 in 2025
| Step | Action | Output |
|---|---|---|
| 1 | Download the official CSF 2.0 PDF (CSWP 29) | Full reference document |
| 2 | Review the Small - Business Quick - Start Guide (if applicable) | High - level overview |
| 3 | Conduct a workshop with leadership to define risk appetite and governance goals (Govern function) | Governance charter |
| 4 | Map relevant Sub - categories to existing controls using informative references | Control mapping spreadsheet |
| 5 | Populate a Current Profile in a simple matrix (Function → Category → Sub - category) | Current profile matrix |
| 6 | Define a Target Profile aligned with business objectives and regulatory drivers | Target profile matrix |
| 7 | Perform gap analysis and prioritize remediation based on impact and effort | Prioritized remediation list |
| 8 | Implement selected controls, then reassess to update the Current Profile | Updated profile and evidence of control implementation |
| 9 | Review and upgrade your Implementation Tier as processes become repeatable or adaptive | New tier designation |
How can I measure progress over time?
- Quarterly profile updates - refresh the Current Profile to capture new assets or changes.
- Tier reassessment - move from Partial to Adaptive as processes mature.
- Metric dashboards - track the number of fully implemented Sub - categories, the proportion of high - impact gaps closed, and the time to remediate.
Frequently asked questions
Does CSF 2.0 replace existing regulations? No. It is a voluntary framework that can be layered on top of regulations such as GDPR, HIPAA, or industry - specific mandates.
Do I need to implement every Sub - category? No. You select the Sub - categories that align with your risk profile and compliance needs. The framework’s flexibility lets you focus on what matters most.
Is the Govern function only for large enterprises? No. Governance is essential for any organization; the Quick - Start Guide shows how small businesses can adopt basic governance practices.
How does CSF 2.0 relate to other frameworks like ISO 27001? CSF 2.0’s informative references map directly to ISO 27001 controls, making it easy to use CSF as a high - level risk view while relying on ISO 27001 for detailed implementation.
For deeper guidance, see NIST’s official CSF 2.0 publication and the Small - Business Quick - Start Guide.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.