NIST CSF
NIST Cybersecurity Framework 2.0
A flexible framework for managing and reducing cybersecurity risk.
Maintained by
NIST
Region
Global (US-origin)
Latest version
2.0 (2024)
Type
Voluntary framework
Overview
What is NIST CSF?
The NIST Cybersecurity Framework is a voluntary, widely adopted framework for managing cyber risk, maintained by the US National Institute of Standards and Technology. Version 2.0, released in 2024, broadened its scope to organizations of all sizes and sectors.
It is organized around six core Functions that give leadership a common language for cybersecurity — and it maps cleanly onto other frameworks, making it a strong backbone for a broader compliance program.
Who needs it: Any organization that wants a structured, risk-based way to assess and improve its cybersecurity posture — often used as the foundation other frameworks build on.
Inside the framework
The six core Functions
Govern (new in 2.0)
Establish and monitor the organization's cybersecurity risk-management strategy and governance.
Identify
Understand assets, risks, and the business context that shapes them.
Protect
Put safeguards in place to limit or contain the impact of potential events.
Detect
Find and analyze cybersecurity events as they happen.
Respond
Take action on a detected incident to contain it.
Recover
Restore capabilities and services impaired by an incident.
With RegShield
Get NIST CSF-ready in a fraction of the time
AI evidence mapping
Upload a policy, screenshot, or config and RegShield maps it to the right NIST CSF controls in seconds — with confidence scores you can defend in front of an auditor.
Reuse across frameworks
Evidence you collect for NIST CSF is automatically reused across every other framework you've activated — so the work compounds instead of repeating.
Gaps & audit-ready reports
See your NIST CSF readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.
FAQ
Common questions
Is NIST CSF a certification?
No — it's a voluntary framework for self-assessment and improvement. There's no certificate, but it's an excellent baseline RegShield can score you against.
What changed in 2.0?
The headline addition is the Govern function, elevating governance alongside the original five, plus broader applicability beyond critical infrastructure.
How does it relate to ISO 27001?
They overlap heavily. NIST CSF gives you the risk-management structure; ISO 27001 gives you a certifiable management system. RegShield reuses evidence across both.