Quick answer

NIST CSF 2.0 is the US National Institute of Standards and Technology's Cybersecurity Framework: a voluntary structure for understanding, governing, and reducing cybersecurity risk, organized into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Nobody certifies you against it; organizations adopt it because it's the most widely understood way to structure and communicate a security program, and version 2.0's new Govern function made board-level accountability explicit.

Why adopt something voluntary

  • A common language. "We're strengthening our Detect capability" means the same thing to your board, your insurer, your customers, and your regulator. The CSF is the closest thing security has to a lingua franca.
  • Maturity without an audit. The framework's tiers let you honestly assess where you are and target where you need to be, useful for roadmaps and budget conversations that certifications don't serve well.
  • A superstructure over your other frameworks. Many organizations use CSF as the top-level map and let ISO 27001, CIS Controls, or regulatory frameworks fill in the implementation detail. The mappings are well established.
  • Insurers and partners ask about it. Cyber insurance applications and US partner due-diligence commonly frame questions in CSF terms.

What 2.0 changed

The headline addition is Govern: cybersecurity risk management strategy, roles, policy, and oversight as a first-class function rather than an assumption. That mirrors where regulation is heading (NIS 2's management accountability, board reporting expectations), so a CSF 2.0 profile positions you well for the mandatory frameworks too. The scope also broadened beyond critical infrastructure to all organizations, with supply chain risk woven throughout.

How adoption actually works

You build a profile: which outcomes matter for your risk picture, current state versus target state, and a plan to close the gap. That's a gap analysis with a prioritized backlog, which is precisely the shape a compliance platform works in; see running CSF 2.0 on OptiTech.

See OptiTech in action

Get a personalized walkthrough of automated compliance for your team. No commitment required.