Skip to main content

NIST CSF NIST Cybersecurity Framework.

NIST CSF is the cybersecurity framework published by the US National Institute of Standards and Technology. The 2.0 revision (2024) added "Govern" to the existing five functions (Identify, Protect, Detect, Respond, Recover). Not certifiable; used as a maturity reference. Common companion to ISO 27001 in transatlantic organisations.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyInformation securityAll entries

The Cyber Academy take

NIST CSF is the cybersecurity framework published by the US National Institute of Standards and Technology. The 2.0 revision (2024) added "Govern" to the existing five functions (Identify, Protect, Detect, Respond, Recover). Not certifiable; used as a maturity reference. Common companion to ISO 27001 in transatlantic organisations.

What the NIST CSF is, and what it is not

The NIST Cybersecurity Framework is a structured way to organise a cybersecurity programme around outcomes rather than products. It does not tell you which firewall to buy or which control to deploy. Instead it describes what good looks like, grouping cybersecurity activity into a small set of functions and breaking each function into categories and subcategories that read as plain-language outcomes: assets are inventoried, access is managed, anomalies are detected, response plans are executed. That outcome orientation is why it travels so well across sectors and sizes. A hospital, a manufacturer, and a software vendor can all use the same vocabulary to describe where they stand and where they want to be.

The most important thing to understand is what the framework is not. It is not a certifiable standard. There is no NIST CSF certificate, no accredited body that issues a pass, and no audit that ends in a registered mark on your website. It is a voluntary reference you use to assess maturity, set targets, and communicate posture, both internally to a board and externally to partners. Treat a vendor claim of being "NIST CSF certified" as a red flag, because no such certification exists.

The functions: from five to six

The framework is built around functions that together cover the full lifecycle of managing cyber risk. The original five were Identify, Protect, Detect, Respond, and Recover. The 2.0 revision published in 2024 added Govern, raising the total to six and placing governance at the centre of the model rather than treating it as an afterthought. Govern covers the organisational context, risk management strategy, roles and responsibilities, policy, and oversight that should shape how the other five functions are prioritised and resourced. Adding it formalised what mature programmes already did: technical controls only work when someone owns the risk decisions behind them.

The six NIST CSF 2.0 functions
FunctionWhat it covers
GovernStrategy, roles, policy, and oversight of cyber risk
IdentifyUnderstanding assets, suppliers, and risks to them
ProtectSafeguards that limit or contain an incident
DetectFinding events and anomalies as they occur
RespondActing on a detected incident to contain it
RecoverRestoring capabilities and services after an incident

In practice a team scores its current state against each category, defines a target profile that reflects its risk appetite and obligations, and works the gap between the two. The framework deliberately leaves the how to you, which is why it pairs naturally with prescriptive catalogues such as the CIS Controls or NIST 800-53 that supply the concrete safeguards underneath each outcome.

Why it sits next to ISO 27001

NIST CSF and ISO 27001 are not competitors, and many transatlantic organisations run both. ISO 27001 certifies that you operate an information security management system, with a risk assessment, a Statement of Applicability, and continual improvement, and it produces an auditable certificate that customers recognise worldwide. The NIST CSF gives you a flexible maturity language and a way to express posture to a US-leaning audience or to map against US federal expectations.

A common pattern is to certify the management system under ISO 27001 for the credential, then use the CSF profile to communicate maturity and to align with frameworks and customers that speak in NIST terms. NIST publishes informative references that map CSF subcategories to ISO 27001 and other standards, so the work rarely needs to be done twice.

Frequently asked questions

01Can you get certified in NIST CSF?

No. The NIST CSF is a voluntary framework, not a certifiable standard, so there is no accredited certificate to earn or display. Organisations that need an auditable credential typically certify against ISO 27001 instead and use the CSF as a maturity reference.

02What changed in NIST CSF 2.0?

The 2.0 revision, published in 2024, added a sixth function, Govern, to the original five of Identify, Protect, Detect, Respond, and Recover. Govern places risk strategy, roles, policy, and oversight at the centre of the framework. The 2.0 scope was also broadened beyond critical infrastructure to organisations of any size and sector.

03What are the six functions of the NIST CSF?

Govern, Identify, Protect, Detect, Respond, and Recover. Govern is the addition in version 2.0; the other five were the original functions and cover the lifecycle of preparing for, detecting, responding to, and recovering from incidents.

04How is NIST CSF different from ISO 27001?

ISO 27001 certifies an information security management system and produces an internationally recognised certificate after an audit. The NIST CSF is a voluntary maturity reference with no certification. They are complementary, and many organisations use ISO 27001 for the credential and the CSF to express posture and align with US-oriented expectations.

05Does the NIST CSF tell you which controls to implement?

Not directly. It describes outcomes rather than specific safeguards, which is why it is usually paired with prescriptive catalogues such as the CIS Controls or NIST 800-53 that supply the concrete controls behind each outcome.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.