---
title: "NIST CSF 2.0 Guide: The Six Functions and What… | Firevault"
description: "A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile,…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/nist-csf-2-0-guide#webpage",
      "url": "https://fire-vault.com/learn/guides/nist-csf-2-0-guide",
      "name": "NIST CSF 2.0 Guide: The Six Functions and What…",
      "description": "A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile,…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/nist-csf-2-0-guide.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/nist-csf-2-0-guide#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/nist-csf-2-0-guide#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "NIST CSF 2.0 Guide: The Six Functions and What They Ask You to Evidence",
          "item": "https://fire-vault.com/learn/guides/nist-csf-2-0-guide"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "NIST CSF 2.0 Guide: The Six Functions and What They Ask You to Evidence",
      "description": "A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile, and where physical controls contribute evidence.",
      "url": "https://fire-vault.com/learn/guides/nist-csf-2-0-guide",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/nist-csf-2-0-guide.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-08-28T07:19:31.793533+00:00",
      "dateModified": "2026-08-28T10:12:43.171224+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/nist-csf-2-0-guide"
      },
      "inLanguage": "en-GB",
      "articleSection": "Standards & Frameworks",
      "wordCount": 1344,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What the CSF is, and what it is notThe six FunctionsTiers and Profiles: the part mos…A workable sequence for adopting…The Functions people over-invest…CSF, and the other things people…Evidence that stands upWhere physical controls contributeFrequently asked questionsMore

[Guides](/learn/knowledge?filter=guides)/ Standards & Frameworks 

Standards & Frameworks · 28 August 2026 

# NIST CSF 2.0 Guide: The Six Functions and What They Ask You to Evidence

A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile, and where physical controls contribute evidence.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

7 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fnist-csf-2-0-guide)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fnist-csf-2-0-guide&text=NIST%20CSF%202.0%20Guide%3A%20The%20Six%20Functions%20and%20What%20They%20Ask%20You%20to%20Evidence%0A%0AA%20practical%20guide%20to%20the%20NIST%20Cybersecurity%20Framework%202.0%3A%20the%20six%20Functions%20including%20Govern%2C%20Tiers%20and%20Profiles%2C%20how%20to%20build%20a%20Current%20and%20Target%20Profile%2C%20and%20where%20physical%20controls%20contribute%20evidence.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fnist-csf-2-0-guide)[](mailto:?subject=NIST%20CSF%202.0%20Guide%3A%20The%20Six%20Functions%20and%20What%20They%20Ask%20You%20to%20Evidence&body=A%20practical%20guide%20to%20the%20NIST%20Cybersecurity%20Framework%202.0%3A%20the%20six%20Functions%20including%20Govern%2C%20Tiers%20and%20Profiles%2C%20how%20to%20build%20a%20Current%20and%20Target%20Profile%2C%20and%20where%20physical%20controls%20contribute%20evidence.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fnist-csf-2-0-guide)

![NIST CSF 2.0 Guide: The Six Functions and What They Ask You to Evidence](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/nist-csf-2-0-guide.jpg)

Standards & Frameworks 

Why it matters

## What this means for organisations holding critical data

A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile, and where physical controls contribute evidence.

**On this page**[What the CSF is, and what it is not](#section-0)[The six Functions](#section-1)[Tiers and Profiles: the part mos…](#section-2)[A workable sequence for adopting…](#section-3)[The Functions people over-invest…](#section-4)[CSF, and the other things people…](#section-5)[Evidence that stands up](#section-6)[Where physical controls contribute](#section-7)[Frequently asked questions](#section-8)

On this page

1.  [What the CSF is, and what it is not](#section-0)
2.  [The six Functions](#section-1)
3.  [Tiers and Profiles: the part most organisations skip](#section-2)
4.  [A workable sequence for adopting CSF 2.0](#section-3)
5.  [The Functions people over-invest in, and the ones they under-evidence](#section-4)
6.  [CSF, and the other things people compare it to](#section-5)
7.  [Evidence that stands up](#section-6)
8.  [Where physical controls contribute](#section-7)
9.  [Frequently asked questions](#section-8)

**Written by Mark Fermor.** This guide explains what the NIST Cybersecurity Framework 2.0 actually requires, how to use it without turning it into a paperwork exercise, and what good evidence looks like for the outcomes it describes.

## What the CSF is, and what it is not

The NIST Cybersecurity Framework is voluntary guidance published by the US National Institute of Standards and Technology. Version 2.0 was published in February 2024. It is not a certification. There is no such thing as being "CSF certified", and no auditor issues a CSF certificate. What the framework provides is a common vocabulary of cyber security outcomes, organised so that a board, a security team and a supplier can discuss the same risk without talking past each other.

Three things changed materially in 2.0. The scope widened beyond [critical infrastructure](/control-for-critical-infrastructure) to organisations of any size or sector. A sixth Function, Govern, was added. And the framework was published alongside implementation examples and Quick Start Guides, which makes it considerably more usable than the 2014 original.

## The six Functions

CSF 2.0 organises outcomes into six Functions. Five of them describe what you do about risk. The sixth describes how you decide.

-   **Govern (GV).** The cyber security risk management strategy, expectations and policy are established, communicated and monitored. This covers organisational context, risk appetite, roles and responsibilities, policy, oversight and the cyber security supply chain. Govern is not a phase. It sits across the other five.
-   **Identify (ID).** The current cyber security risk to the organisation is understood. Asset inventories, risk assessment, and improvement informed by lessons learned.
-   **Protect (PR).** Safeguards to manage risk are used. Identity and access management, awareness and training, data security, platform security, and technology resilience.
-   **Detect (DE).** Possible attacks and compromises are found and analysed. Continuous monitoring and adverse event analysis.
-   **Respond (RS).** Action regarding a detected incident is taken. Incident management, analysis, reporting, communication and mitigation.
-   **Recover (RC).** Assets and operations affected by an incident are restored. Recovery plan execution and recovery communication.

Each Function contains Categories, and each Category contains Subcategories, which are the outcome statements you actually evidence. Subcategories are written as outcomes rather than controls on purpose, so that the framework does not dictate a particular product or architecture.

## Tiers and Profiles: the part most organisations skip

The Functions describe what to achieve. Tiers and Profiles describe how you manage the journey, and they are where most of the practical value sits.

-   **Tiers 1 to 4** characterise the rigour of your cyber risk governance and management practices, from Partial through Risk Informed and Repeatable to Adaptive. A Tier is not a score to maximise. A small organisation may be entirely rational in operating at Tier 2.
-   **A Current Profile** records the Subcategory outcomes you are achieving today, and how.
-   **A Target Profile** records the outcomes you intend to achieve, given your mission, threat environment, regulatory obligations and resources.

The gap between the two Profiles is your action plan, and it is the artefact that most usefully translates into a board paper: here is what we achieve, here is what we intend to achieve, here is what stands between the two, and here is what it costs.

## A workable sequence for adopting CSF 2.0

1.  **Scope it.** Decide whether the Profile covers the whole organisation, a business unit, or a specific system such as an OT estate. Mixed scopes produce meaningless Profiles.
2.  **Start with Govern.** Establish risk appetite, ownership and reporting lines before assessing controls. Without this, the assessment has no benchmark to judge sufficiency against.
3.  **Build the Current Profile from evidence.** Not from opinion, and not from a policy library. If a Subcategory outcome cannot be demonstrated, it is not achieved.
4.  **Set the Target Profile against threat and obligation.** Regulatory duties, insurance requirements, customer contracts and the incidents you would not survive.
5.  **Prioritise the gaps by consequence.** Weight the gaps that sit between an incident and your ability to operate through it.
6.  **Re-assess on a defined cycle** and after material change or a significant incident.

## The Functions people over-invest in, and the ones they under-evidence

In practice, Identify, Protect and Detect attract most of the budget because they map neatly onto products. Respond and Recover attract most of the pain during an incident, and they are consistently the weakest part of a Current Profile.

Three questions expose the gap quickly:

-   Under RC.RP, can you demonstrate that recovery has been executed from your recovery assets, at realistic scale, within your stated recovery time objective?
-   Under PR.DS, can you demonstrate that recovery data cannot be altered or deleted by an actor who holds valid administrative credentials in production?
-   Under RS.CO, can you communicate during an incident if your primary identity, email and telephony platforms are unavailable or untrusted?

An organisation that answers all three with documented evidence is in a materially better position than one with a higher Tier and no rehearsal.

## CSF, and the other things people compare it to

-   **ISO/IEC 27001** is a certifiable management system standard. CSF is not. They coexist comfortably: an ISMS provides the management system, CSF provides the outcome vocabulary and the Profile mechanism.
-   **NIST SP 800-53** is a control catalogue. CSF references it as an Informative Reference. Use CSF to decide what outcome you need and 800-53 to select the control.
-   **NCSC Cyber Assessment Framework** serves a comparable purpose in the UK, with an assessment model built around principles and indicators of good practice, and a regulatory context for essential services.
-   **MITRE ATT&CK** is a knowledge base of adversary behaviour, not a framework of outcomes. It informs Detect and Respond rather than replacing them.

## Evidence that stands up

The recurring failure in CSF adoption is documentary evidence that describes intent rather than fact. A policy asserting that backups are protected is not evidence that they are. Useful evidence is contemporaneous, generated by the control itself, and independent of the person presenting it: a restore test report with timings, an access log showing who authorised a boundary crossing and when, a retention record that a production administrator could not have altered.

This distinction matters more under 2.0 than it did under 1.1, because Govern explicitly asks whether outcomes are monitored, not merely defined.

## Where physical controls contribute

Several CSF outcomes are difficult to evidence with logical controls alone, because the logical control and the asset it protects share the same administrative domain. If an attacker holds valid credentials in that domain, the evidence and the asset fall together.

Firevault works on two of those outcomes. **[Offline Secure Storage](/offline-secure-storage)®** holds selected recovery, configuration and evidential material on storage that is physically disconnected when it is not in use, which speaks directly to data security under PR.DS and recovery execution under RC.RP. **Control by Firevault** is a suite of nine purpose-built tools and techniques that give an organisation physical control over the paths into and across its estate, applied through Blueprints that treat a specific risk. That is relevant to platform and technology resilience under PR.PS and PR.IR, and to containment under RS.MI.

Neither replaces the framework, the control catalogue, or your existing security programme. The contribution is narrower and more specific: for the small number of assets and paths where a logical control is not sufficient assurance, a physical state change produces evidence that a compromised credential cannot rewrite.

## Frequently asked questions

### Does CSF 2.0 still have five Functions?

No. Version 2.0 has six. Govern was added and sits across Identify, Protect, Detect, Respond and Recover.

### Can we be certified against NIST CSF?

No. It is voluntary guidance. You can be assessed against it, and you can align an ISO/IEC 27001 certified management system to it, but there is no CSF certificate.

### Do we have to address every Subcategory?

No. The Target Profile is chosen on the basis of mission, risk and resources. Deliberately excluding an outcome, with a recorded reason, is a legitimate CSF position.

### How does CSF relate to cyber insurance?

Insurers rarely require CSF itself, but the questions on a proposal form map closely to Protect, Respond and Recover outcomes. A defensible Current Profile shortens underwriting conversations considerably.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

## Continue learning

-   [
    
    ### MITRE ATT&CK Guide: Mapping Controls to Real Adversary Behaviour
    
    How to use MITRE ATT&CK properly: tactics, techniques and sub-techniques, the Enterprise and ICS matrices, coverage mapping without self-deception, and why version changes matter.
    
    Read guide ](/learn/guides/mitre-attack-mapping-guide)
-   [
    
    ### ISA/IEC 62443 Guide: Zones, Conduits and Security Levels in Practice
    
    A practical guide to ISA/IEC 62443 for asset owners: how the series is structured, how zones and conduits are defined, what Security Levels mean, and how the standard relates to the Purdue Model.
    
    Read guide ](/learn/guides/iec-62443-guide)
-   [
    
    ### NCSC Cyber Assessment Framework Guide: Objectives, Principles and Evidence
    
    A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what evidence satisfies an assessor.
    
    Read guide ](/learn/guides/ncsc-caf-guide)
-   [
    
    ### Crown Jewels Audit: What Deserves Disconnection
    
    Not everything needs to go offline. The Crown Jewels Audit is a structured framework for identifying exactly which assets deserve the protection that only physical disconnection can provide.
    
    Read guide ](/learn/guides/crown-jewels-audit)

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up