Framework · NIST CSF 2.0
NIST CSF 2.0: the risk framework your board understands
The NIST Cybersecurity Framework, version 2.0 of 2024: six outcome-based functions, including the new Govern function, that layer on top of your standards.
The NIST Cybersecurity Framework is widely adopted, not because regulators require it, but because it describes what good cybersecurity looks like rather than prescribing specific controls. Version 2.0, released in 2024 by the US National Institute of Standards and Technology, added a Govern function and expanded scope beyond critical infrastructure. It is used across sectors and regions as an overlay framework on top of the specific standards you are already required to follow.
Key facts
- 6 functions: Govern (new), Identify, Protect, Detect, Respond, Recover.
- 2024: version 2.0 release.
- GV.SC: supply chain risk governance, one of the most significant additions in version 2.0.
- Profiles: the framework is implemented through a current profile and a target profile, whose gap becomes the roadmap.
What NIST CSF 2.0 covers
NIST CSF is outcomes-based. The new Govern function addresses cybersecurity strategy, risk management oversight, and supply chain risk governance at the executive level.
- GV, Govern: cybersecurity strategy, policy, roles, and supply chain risk governance
- ID, Identify: asset management, risk assessment, improvement
- PR, Protect: access control, awareness, data security, resilience
- DE, Detect: continuous monitoring, anomaly detection
- RS, Respond: incident management, communications, analysis
- RC, Recover: recovery planning and improvements
What Sentrix provides for NIST CSF
Current and target profile
Sentrix tracks both your current CSF profile and your target profile, showing the gap as a prioritized roadmap. Board and executive teams see progress toward the target profile over time.
Board-ready reporting
CSF is designed to communicate cybersecurity risk to executives. Sentrix generates risk posture summaries by function, with no technical jargon and no spreadsheets.
Supply chain risk (GV.SC)
Sentrix maps your third-party risk program to the GV.SC subcategories of the Govern function.
Continuous monitoring (DE)
The Detect function requires continuous monitoring. Sentrix connects to your SIEM, cloud security tools, and endpoint platforms to collect evidence automatically.
Incident response (RS)
Respond function evidence collected from your ticketing and incident management tools: response times tracked, lessons learned documented, and post-incident reviews recorded as audit evidence.
Crosswalks
- ISO 27001: Annex A controls are mapped to the six functions.
- SOC 2: the Trust Services Criteria are mapped to the CSF.
- NIST SP 800-53: catalog controls are mapped to CSF subcategories.
- CAN/DGSI 104: the 18 baseline controls map to the Protect and Detect functions.
- OSFI B-13: the guideline is aligned to the CSF structure.
- NIS2: regional measures mapped to the CSF functions.
Further reading
See your NIST CSF 2.0 profile against your real stack.
Frequently asked questions
- Is the NIST CSF mandatory?
- No. The NIST Cybersecurity Framework is voluntary and widely adopted because it describes what good cybersecurity looks like rather than prescribing specific controls. That makes it an ideal overlay framework that maps to whatever standards you are already required to follow, such as ISO 27001, SOC 2 or NIST SP 800-53, and a common language with executives and the board.
- What is the Govern function added in version 2.0?
- The Govern (GV) function, new in version 2.0 released in 2024, addresses cybersecurity strategy, policy, roles, risk management oversight and supply chain risk governance (GV.SC) at the executive level. It joins the five existing functions: Identify, Protect, Detect, Respond and Recover.
- What are the current profile and the target profile?
- The current profile describes the cybersecurity outcomes your organization achieves today, function by function; the target profile describes the ones it aims for. The gap between the two becomes a prioritized roadmap. Sentrix tracks both profiles and shows the board and executive teams progress toward the target profile over time.
Related pages
Framework · ISO 27001:2022
ISO 27001:2022: from ISMS to certification in one program
The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.
Framework · SOC 2
SOC 2 is a continuous program, not a one-time audit
AICPA attestation framework across five Trust Services Criteria categories, reported as Type I or Type II. Continuous evidence, drift alerts, auditor access.
Framework · NIST SP 800-53
NIST SP 800-53: the control catalog behind FedRAMP and CMMC
NIST catalog of security and privacy controls for US federal information systems: 20 control families, three baselines, Revision 5, behind FedRAMP and CMMC.
Framework · CAN/DGSI 104
CAN/DGSI 104: the cybersecurity baseline for Canadian SMEs
Canada's baseline cyber security controls standard for SMEs: 18 main controls, 55 sub-controls, two levels, and the CyberSecure Canada certification program.
Framework · OSFI B-10 / B-13
OSFI B-10 and B-13: outsourcing, technology and cyber risk
OSFI guidelines on outsourcing (B-10) and technology and cyber risk management (B-13) for Canada's federally regulated financial institutions, in one program.
Let's talk about your compliance program.
Last updated: 2026-09-17
