NIST CSF

NIST CSF six functions and version 2.0 changes explained

NIST CSF is the framework nobody audits you against and everybody borrows from. Version 2.0 added a governance function and dropped the critical infrastructure framing, which is why it started appearing in questionnaires aimed at startups.

  • Glossary
  • Compliance

The short answer

NIST CSF is the Cybersecurity Framework published by the US National Institute of Standards and Technology. It organises security work into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is voluntary and there is no certificate. Its value is as a common vocabulary for describing a security programme and measuring where it currently sits against where you want it to be.

That absence of an audit is the point people miss. NIST CSF is a way of thinking about coverage, not a bar to clear.

The six NIST CSF functions

GOVERN sets the strategy, roles and risk appetite the other five operate under Identify Know what you have Protect Reduce the chance Detect See it happening Respond Contain and act Recover Return to service Govern is not a sixth step in a sequence. It wraps the other five. Adding it in version 2.0 is what made the framework readable to a board rather than only to a security team.
FunctionWhat it covers
GovernStrategy, roles, policy, risk appetite and supply chain oversight, which is largely the territory of GRC
IdentifyAsset inventory, risk assessment and understanding what you actually run
ProtectAccess control, data security, endpoint protection, awareness training and platform hardening
DetectMonitoring, logging and correlation across the estate
RespondIncident response, analysis, containment and communication
RecoverRestoration, recovery planning and the improvements that follow an incident

What changed in version 2.0

Version 2.0 was published in February 2024 and made two changes that matter to anyone outside the United States government supply chain.

The first is Govern. Version 1.1 had five functions, all operational. Adding governance moved accountability, roles and risk appetite into the framework itself, which is what lets a security programme be described to a board rather than only to engineers.

The second is scope. Version 1.1 was framed around critical infrastructure. Version 2.0 dropped that framing and is written for organisations of any size or sector, which is a large part of why NIST CSF now shows up in vendor questionnaires sent to small companies that have nothing to do with power grids.

Tiers and profiles

The functions describe what to cover. Tiers and profiles are how you say where you are and where you are going.

ConceptWhat it means
Tier 1, PartialAd hoc, reactive, little organisational awareness of risk
Tier 2, Risk InformedRisk is understood but practice is inconsistent and rarely documented
Tier 3, RepeatableFormal policy, consistently applied and updated as things change
Tier 4, AdaptivePractice adjusts continuously from lessons learned and threat intelligence
Current ProfileAn honest description of what you do today, function by function
Target ProfileWhere you intend to be, given your risk and your budget

Tier 4 is not the goal

Tiers are not maturity grades to climb. NIST is explicit that the appropriate tier depends on your risk, your resources and your obligations, and that a small company operating well at Tier 2 or 3 may be exactly where it should be. Treating Tier 4 as a target is how teams end up buying tooling they cannot staff.

NIST CSF and ISO 27001

NIST CSFISO 27001
TypeVoluntary frameworkCertifiable standard
OutcomeA profile and a gap pictureA certificate from an accredited body
StructureSix functions with outcome statementsAn ISMS plus Annex A controls
Best used forOrganising and communicating a programmeProving one to a buyer or regulator
Cost to reachTime onlyAudit fees and an ongoing surveillance cycle

They are complements rather than alternatives. A common pattern is to use NIST CSF to structure the programme and decide sequencing, then certify against ISO 27001 or report under SOC 2 when a buyer needs evidence they can file.

Where NIST CSF gets asked for

ContextWhat is expected
US enterprise vendor reviewA self-assessment against the functions, often inside a larger security questionnaire
Cyber insuranceUnderwriters use the functions as a structure for assessing controls, particularly Detect and Respond
Board and investor reportingA profile is easier to present than a control list, which is what Govern was added for
Indian regulatory frameworksSEBI CSCRF uses the same functional vocabulary of identify, protect, detect, respond and recover
Internal planningThe most common honest use: deciding what to fix next when everything looks urgent

How Osto maps to NIST CSF

The six functions correspond closely to how the platform is built. Identify covers asset and API discovery plus cloud posture. Protect covers access, endpoint, web and data controls. Detect is SIEM and correlation across those modules. Respond and Recover attach to incident response. Govern is where the GRC layer sits.

Because the controls run in one stack, a current profile is something you can read rather than assemble. That matters most when NIST CSF is being used the way it was designed to be used, as a coverage picture, since a gap in Detect is usually a gap in what you can see rather than a missing document. The same control set maps to SOC 2, ISO 27001, GDPR and over 200 other frameworks at the same time.

Platform walkthrough

A profile you can read, not assemble

Identify, protect, detect, respond and recover running as live controls in one stack, mapped to SOC 2, ISO 27001 and 200+ frameworks from the same evidence base. One owner, one dashboard.

Book a demo

Coverage across all six functions · 200+ frameworks mapped · One platform, everything

Frequently asked questions

What is NIST CSF?

The Cybersecurity Framework from the US National Institute of Standards and Technology. It organises security into six functions, Govern, Identify, Protect, Detect, Respond and Recover, and provides tiers and profiles for describing current and target state. It is voluntary.

Can you get certified against NIST CSF?

No. There is no certification scheme and no accredited body issuing NIST CSF certificates. Organisations self-assess, or engage an assessor for an independent view. When a buyer wants a certificate, ISO 27001 or SOC 2 is the answer.

What changed in NIST CSF 2.0?

Published in February 2024, it added Govern as a sixth function covering strategy, roles, risk appetite and supply chain, and removed the critical infrastructure framing so the framework applies to organisations of any size or sector.

Should we use NIST CSF or ISO 27001?

Usually both, for different jobs. NIST CSF structures the programme and shows where the gaps are. ISO 27001 produces a certificate a buyer or regulator can accept. Using the framework to plan and the standard to prove is the common sequence.

Is NIST CSF relevant outside the United States?

Yes. Version 2.0 is written for any organisation, and the functional vocabulary appears in insurance assessments, enterprise questionnaires and regulatory frameworks including SEBI CSCRF in India.