Version 2.0, published in 2024 as NIST CSWP 29, extended the framework beyond its original critical-infrastructure focus to organizations of any size and sector. The framework describes desired outcomes rather than prescriptive controls, so organizations can map it to their own obligations, architecture, and maturity.
The framework is used in three main ways: as a common language between technical teams and leadership, as a structure for assessing current posture against a target profile, and as a bridge to detailed control catalogs such as NIST SP 800-53 or ISO/IEC 27001 through published mappings.
Key points
Functions and categoriesGovern establishes the risk-management strategy and accountability; Identify covers assets and risks; Protect, Detect, Respond, and Recover cover safeguards, detection, response, and restoration outcomes respectively.
Profiles and tiersAn organizational profile compares current and target outcomes, while the four tiers describe increasing rigor in risk-management practices; tiers indicate process maturity, not a score of security.
ApplicationScope the systems and services covered, document current outcomes, set a target profile, prioritize gaps by risk, and track progress with owners and evidence.
Important limitationCSF alignment is a management outcome, not certification or proof of security. Self-assessed profiles can overstate capability, and the framework’s flexibility means two organizations claiming conformance may operate very different controls.