home / frameworks / nist-csf

// U.S. frameworks that reach Canada

NIST Cybersecurity Framework (CSF) 2.0

The NIST Cybersecurity Framework 2.0 is a voluntary, outcome-based framework that organizes cybersecurity into 6 functions, 22 categories, and 106 subcategories. Organizations use it to describe their current and target posture and plan improvements.

United States (used internationally)CSF 2.0 (NIST CSWP 29, February 2024)

Overview

NIST published the Cybersecurity Framework 2.0 on February 26, 2024, replacing version 1.1. It describes outcomes, not controls. The CSF Core groups those outcomes into 6 functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern is new in 2.0, and it covers the strategy, roles, policy, and oversight that shape every other function, along with cybersecurity supply chain risk management.

The Core is broken down into 22 categories and 106 subcategories. Each subcategory is a specific outcome, such as keeping an inventory of hardware or testing incident response plans. NIST also publishes implementation examples for each subcategory, informative references that map the CSF to other standards, and quick start guides for small businesses, enterprise risk managers, and others. Two tools sit alongside the Core. Organizational profiles describe current and target outcomes, and tiers describe how rigorous an organization's risk governance and management practices are.

There's no CSF certificate, and no one audits against it in a formal sense. Use is free. Organizations self-assess, or ask a consultant or internal audit team to measure maturity against the subcategories. In Canada it shows up in vendor questionnaires from U.S. customers, in board reporting, and as a common language for mapping between standards such as ISO/IEC 27001 and Canadian Centre for Cyber Security guidance. Version 2.0 remains current as of October 2026, and NIST continues to add supporting material, including a draft CSF 2.0 AI quick start guide open for comment until October 15, 2026.

Who it applies to in Canada

Any organization of any size or sector that wants a common way to describe, assess, and improve how it manages cybersecurity risk. It was first written for U.S. infrastructure owners and operators, and version 2.0 widened it to all organizations.

Canadian organizations meet the CSF through U.S. customers and partners who ask for it in security questionnaires, and through Canadian bodies that build on it. The Canadian Centre for Cyber Security maps its Cross-Sector Cyber Security Readiness Goals to CSF 2.0, and the Ontario Energy Board's cyber security framework for electricity utilities is based on the NIST CSF.

Controls at a glance

The CSF Core is organized into 6 functions and 22 categories, with 106 subcategories describing specific outcomes.

Govern (GV): 6 categories

  • Organizational context: mission, stakeholders, legal and contractual requirements
  • Risk management strategy, risk appetite, and tolerance
  • Roles, responsibilities, and authorities for cybersecurity
  • Cybersecurity policy set, communicated, and enforced
  • Oversight of risk management results by leadership
  • Cybersecurity supply chain risk management

Identify (ID): 3 categories

  • Asset management for data, hardware, software, and services
  • Risk assessment of threats, vulnerabilities, and impacts
  • Improvement based on assessments, tests, and lessons learned

Protect (PR): 5 categories

  • Identity management, authentication, and access control
  • Awareness and training for staff
  • Data security at rest, in transit, and in use
  • Platform security for hardware, software, and services
  • Technology infrastructure resilience and architecture

Detect (DE): 2 categories

  • Continuous monitoring of networks, people, and services
  • Adverse event analysis to find possible attacks
  • Escalation of events that meet incident criteria

Respond (RS): 4 categories

  • Incident management under the response plan
  • Incident analysis, including root cause and scope
  • Incident response reporting and communication
  • Incident mitigation to contain and eradicate

Recover (RC): 2 categories

  • Incident recovery plan execution and restoration
  • Recovery communication with internal and external parties
  • Verification of restored assets before return to normal

Certification and assessment

Organizations build a current profile, set a target profile, and measure the gap against the 106 subcategories. Many also rate themselves against the 4 tiers. Results are reported to leadership, customers, or regulators that ask for them.

Dates to know

2024-02-26
CSF 2.0 published, adding the Govern function and widening scope to all organizations
2026-10-15
Comment period closes on the draft CSF 2.0 AI Quick-Start Guide (NIST SP 1353)

In this hub

Resources

Official texts and free tools for NIST CSF. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29), NIST
  2. NIST Cybersecurity Framework home page, NIST
  3. Cross-Sector Cyber Security Readiness Goals Toolkit, Canadian Centre for Cyber Security
  4. Ontario Cyber Security Framework (December 2017), Ontario Energy Board