Overview
NIST published the Cybersecurity Framework 2.0 on February 26, 2024, replacing version 1.1. It describes outcomes, not controls. The CSF Core groups those outcomes into 6 functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern is new in 2.0, and it covers the strategy, roles, policy, and oversight that shape every other function, along with cybersecurity supply chain risk management.
The Core is broken down into 22 categories and 106 subcategories. Each subcategory is a specific outcome, such as keeping an inventory of hardware or testing incident response plans. NIST also publishes implementation examples for each subcategory, informative references that map the CSF to other standards, and quick start guides for small businesses, enterprise risk managers, and others. Two tools sit alongside the Core. Organizational profiles describe current and target outcomes, and tiers describe how rigorous an organization's risk governance and management practices are.
There's no CSF certificate, and no one audits against it in a formal sense. Use is free. Organizations self-assess, or ask a consultant or internal audit team to measure maturity against the subcategories. In Canada it shows up in vendor questionnaires from U.S. customers, in board reporting, and as a common language for mapping between standards such as ISO/IEC 27001 and Canadian Centre for Cyber Security guidance. Version 2.0 remains current as of October 2026, and NIST continues to add supporting material, including a draft CSF 2.0 AI quick start guide open for comment until October 15, 2026.
Who it applies to in Canada
Any organization of any size or sector that wants a common way to describe, assess, and improve how it manages cybersecurity risk. It was first written for U.S. infrastructure owners and operators, and version 2.0 widened it to all organizations.
Canadian organizations meet the CSF through U.S. customers and partners who ask for it in security questionnaires, and through Canadian bodies that build on it. The Canadian Centre for Cyber Security maps its Cross-Sector Cyber Security Readiness Goals to CSF 2.0, and the Ontario Energy Board's cyber security framework for electricity utilities is based on the NIST CSF.
Controls at a glance
The CSF Core is organized into 6 functions and 22 categories, with 106 subcategories describing specific outcomes.
Govern (GV): 6 categories
- Organizational context: mission, stakeholders, legal and contractual requirements
- Risk management strategy, risk appetite, and tolerance
- Roles, responsibilities, and authorities for cybersecurity
- Cybersecurity policy set, communicated, and enforced
- Oversight of risk management results by leadership
- Cybersecurity supply chain risk management
Identify (ID): 3 categories
- Asset management for data, hardware, software, and services
- Risk assessment of threats, vulnerabilities, and impacts
- Improvement based on assessments, tests, and lessons learned
Protect (PR): 5 categories
- Identity management, authentication, and access control
- Awareness and training for staff
- Data security at rest, in transit, and in use
- Platform security for hardware, software, and services
- Technology infrastructure resilience and architecture
Detect (DE): 2 categories
- Continuous monitoring of networks, people, and services
- Adverse event analysis to find possible attacks
- Escalation of events that meet incident criteria
Respond (RS): 4 categories
- Incident management under the response plan
- Incident analysis, including root cause and scope
- Incident response reporting and communication
- Incident mitigation to contain and eradicate
Recover (RC): 2 categories
- Incident recovery plan execution and restoration
- Recovery communication with internal and external parties
- Verification of restored assets before return to normal
Certification and assessment
Organizations build a current profile, set a target profile, and measure the gap against the 106 subcategories. Many also rate themselves against the 4 tiers. Results are reported to leadership, customers, or regulators that ask for them.
Dates to know
- 2024-02-26
- CSF 2.0 published, adding the Govern function and widening scope to all organizations
- 2026-10-15
- Comment period closes on the draft CSF 2.0 AI Quick-Start Guide (NIST SP 1353)
In this hub
NIST CSF 2.0 functions and categories explained
How the 6 functions, 22 categories, and 106 subcategories of the CSF 2.0 Core fit together.
NIST CSF profiles and tiers
How organizational profiles, community profiles, and the 4 tiers turn the CSF Core into a working plan.
Using the NIST CSF in Canada
How Canadian regulators, critical infrastructure programs, and organizations reference the NIST CSF, and how it maps to Canadian Centre for Cyber Security guidance.
NIST CSF vs ISO 27001
How the NIST CSF and ISO/IEC 27001 differ in purpose, structure, and assurance, and how organizations use both.
Resources
Official texts and free tools for NIST CSF. Links open the publisher’s site.
- NIST Cybersecurity Framework home page, NIST
- The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29), NIST
- CSF 2.0 Reference Tool, NISTtool
- CSF 2.0 Quick Start Guides, NISTguidance
- CSF 2.0 Profiles and templates, NISTtemplate
- Cross-Sector Cyber Security Readiness Goals Toolkit, Canadian Centre for Cyber Securityguidance
Need help? Browse the directory or read the guides.
References
- The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29), NIST
- NIST Cybersecurity Framework home page, NIST
- Cross-Sector Cyber Security Readiness Goals Toolkit, Canadian Centre for Cyber Security
- Ontario Cyber Security Framework (December 2017), Ontario Energy Board
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.