Standards & Frameworks·28 August 2026

NIST CSF 2.0 Guide: The Six Functions and What They Ask You to Evidence

A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile, and where physical controls contribute evidence.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
7 min read
Share
NIST CSF 2.0 Guide: The Six Functions and What They Ask You to Evidence
Standards & Frameworks

Why it matters

What this means for organisations holding critical data

A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile, and where physical controls contribute evidence.

Written by Mark Fermor. This guide explains what the NIST Cybersecurity Framework 2.0 actually requires, how to use it without turning it into a paperwork exercise, and what good evidence looks like for the outcomes it describes.

What the CSF is, and what it is not

The NIST Cybersecurity Framework is voluntary guidance published by the US National Institute of Standards and Technology. Version 2.0 was published in February 2024. It is not a certification. There is no such thing as being "CSF certified", and no auditor issues a CSF certificate. What the framework provides is a common vocabulary of cyber security outcomes, organised so that a board, a security team and a supplier can discuss the same risk without talking past each other.

Three things changed materially in 2.0. The scope widened beyond critical infrastructure to organisations of any size or sector. A sixth Function, Govern, was added. And the framework was published alongside implementation examples and Quick Start Guides, which makes it considerably more usable than the 2014 original.

The six Functions

CSF 2.0 organises outcomes into six Functions. Five of them describe what you do about risk. The sixth describes how you decide.

  • Govern (GV). The cyber security risk management strategy, expectations and policy are established, communicated and monitored. This covers organisational context, risk appetite, roles and responsibilities, policy, oversight and the cyber security supply chain. Govern is not a phase. It sits across the other five.
  • Identify (ID). The current cyber security risk to the organisation is understood. Asset inventories, risk assessment, and improvement informed by lessons learned.
  • Protect (PR). Safeguards to manage risk are used. Identity and access management, awareness and training, data security, platform security, and technology resilience.
  • Detect (DE). Possible attacks and compromises are found and analysed. Continuous monitoring and adverse event analysis.
  • Respond (RS). Action regarding a detected incident is taken. Incident management, analysis, reporting, communication and mitigation.
  • Recover (RC). Assets and operations affected by an incident are restored. Recovery plan execution and recovery communication.

Each Function contains Categories, and each Category contains Subcategories, which are the outcome statements you actually evidence. Subcategories are written as outcomes rather than controls on purpose, so that the framework does not dictate a particular product or architecture.

Tiers and Profiles: the part most organisations skip

The Functions describe what to achieve. Tiers and Profiles describe how you manage the journey, and they are where most of the practical value sits.

  • Tiers 1 to 4 characterise the rigour of your cyber risk governance and management practices, from Partial through Risk Informed and Repeatable to Adaptive. A Tier is not a score to maximise. A small organisation may be entirely rational in operating at Tier 2.
  • A Current Profile records the Subcategory outcomes you are achieving today, and how.
  • A Target Profile records the outcomes you intend to achieve, given your mission, threat environment, regulatory obligations and resources.

The gap between the two Profiles is your action plan, and it is the artefact that most usefully translates into a board paper: here is what we achieve, here is what we intend to achieve, here is what stands between the two, and here is what it costs.

A workable sequence for adopting CSF 2.0

  1. Scope it. Decide whether the Profile covers the whole organisation, a business unit, or a specific system such as an OT estate. Mixed scopes produce meaningless Profiles.
  2. Start with Govern. Establish risk appetite, ownership and reporting lines before assessing controls. Without this, the assessment has no benchmark to judge sufficiency against.
  3. Build the Current Profile from evidence. Not from opinion, and not from a policy library. If a Subcategory outcome cannot be demonstrated, it is not achieved.
  4. Set the Target Profile against threat and obligation. Regulatory duties, insurance requirements, customer contracts and the incidents you would not survive.
  5. Prioritise the gaps by consequence. Weight the gaps that sit between an incident and your ability to operate through it.
  6. Re-assess on a defined cycle and after material change or a significant incident.

The Functions people over-invest in, and the ones they under-evidence

In practice, Identify, Protect and Detect attract most of the budget because they map neatly onto products. Respond and Recover attract most of the pain during an incident, and they are consistently the weakest part of a Current Profile.

Three questions expose the gap quickly:

  • Under RC.RP, can you demonstrate that recovery has been executed from your recovery assets, at realistic scale, within your stated recovery time objective?
  • Under PR.DS, can you demonstrate that recovery data cannot be altered or deleted by an actor who holds valid administrative credentials in production?
  • Under RS.CO, can you communicate during an incident if your primary identity, email and telephony platforms are unavailable or untrusted?

An organisation that answers all three with documented evidence is in a materially better position than one with a higher Tier and no rehearsal.

CSF, and the other things people compare it to

  • ISO/IEC 27001 is a certifiable management system standard. CSF is not. They coexist comfortably: an ISMS provides the management system, CSF provides the outcome vocabulary and the Profile mechanism.
  • NIST SP 800-53 is a control catalogue. CSF references it as an Informative Reference. Use CSF to decide what outcome you need and 800-53 to select the control.
  • NCSC Cyber Assessment Framework serves a comparable purpose in the UK, with an assessment model built around principles and indicators of good practice, and a regulatory context for essential services.
  • MITRE ATT&CK is a knowledge base of adversary behaviour, not a framework of outcomes. It informs Detect and Respond rather than replacing them.

Evidence that stands up

The recurring failure in CSF adoption is documentary evidence that describes intent rather than fact. A policy asserting that backups are protected is not evidence that they are. Useful evidence is contemporaneous, generated by the control itself, and independent of the person presenting it: a restore test report with timings, an access log showing who authorised a boundary crossing and when, a retention record that a production administrator could not have altered.

This distinction matters more under 2.0 than it did under 1.1, because Govern explicitly asks whether outcomes are monitored, not merely defined.

Where physical controls contribute

Several CSF outcomes are difficult to evidence with logical controls alone, because the logical control and the asset it protects share the same administrative domain. If an attacker holds valid credentials in that domain, the evidence and the asset fall together.

Firevault works on two of those outcomes. Offline Secure Storage® holds selected recovery, configuration and evidential material on storage that is physically disconnected when it is not in use, which speaks directly to data security under PR.DS and recovery execution under RC.RP. Control by Firevault is a suite of nine purpose-built tools and techniques that give an organisation physical control over the paths into and across its estate, applied through Blueprints that treat a specific risk. That is relevant to platform and technology resilience under PR.PS and PR.IR, and to containment under RS.MI.

Neither replaces the framework, the control catalogue, or your existing security programme. The contribution is narrower and more specific: for the small number of assets and paths where a logical control is not sufficient assurance, a physical state change produces evidence that a compromised credential cannot rewrite.

Frequently asked questions

Does CSF 2.0 still have five Functions?

No. Version 2.0 has six. Govern was added and sits across Identify, Protect, Detect, Respond and Recover.

Can we be certified against NIST CSF?

No. It is voluntary guidance. You can be assessed against it, and you can align an ISO/IEC 27001 certified management system to it, but there is no CSF certificate.

Do we have to address every Subcategory?

No. The Target Profile is chosen on the basis of mission, risk and resources. Deliberately excluding an outcome, with a recorded reason, is a legitimate CSF position.

How does CSF relate to cyber insurance?

Insurers rarely require CSF itself, but the questions on a proposal form map closely to Protect, Respond and Recover outcomes. A defensible Current Profile shortens underwriting conversations considerably.

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

HardwareYour copy sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
RecoveryA known-clean copy to rebuild from, on your timetable
LocationHeld in a secure Firevault Bunker
Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up