Sentrix

Framework · NIST CSF 2.0

NIST CSF 2.0: the risk framework your board understands

The NIST Cybersecurity Framework, version 2.0 of 2024: six outcome-based functions, including the new Govern function, that layer on top of your standards.

The NIST Cybersecurity Framework is widely adopted, not because regulators require it, but because it describes what good cybersecurity looks like rather than prescribing specific controls. Version 2.0, released in 2024 by the US National Institute of Standards and Technology, added a Govern function and expanded scope beyond critical infrastructure. It is used across sectors and regions as an overlay framework on top of the specific standards you are already required to follow.

Key facts

  • 6 functions: Govern (new), Identify, Protect, Detect, Respond, Recover.
  • 2024: version 2.0 release.
  • GV.SC: supply chain risk governance, one of the most significant additions in version 2.0.
  • Profiles: the framework is implemented through a current profile and a target profile, whose gap becomes the roadmap.

What NIST CSF 2.0 covers

NIST CSF is outcomes-based. The new Govern function addresses cybersecurity strategy, risk management oversight, and supply chain risk governance at the executive level.

  1. GV, Govern: cybersecurity strategy, policy, roles, and supply chain risk governance
  2. ID, Identify: asset management, risk assessment, improvement
  3. PR, Protect: access control, awareness, data security, resilience
  4. DE, Detect: continuous monitoring, anomaly detection
  5. RS, Respond: incident management, communications, analysis
  6. RC, Recover: recovery planning and improvements

What Sentrix provides for NIST CSF

Current and target profile

Sentrix tracks both your current CSF profile and your target profile, showing the gap as a prioritized roadmap. Board and executive teams see progress toward the target profile over time.

Board-ready reporting

CSF is designed to communicate cybersecurity risk to executives. Sentrix generates risk posture summaries by function, with no technical jargon and no spreadsheets.

Supply chain risk (GV.SC)

Sentrix maps your third-party risk program to the GV.SC subcategories of the Govern function.

Continuous monitoring (DE)

The Detect function requires continuous monitoring. Sentrix connects to your SIEM, cloud security tools, and endpoint platforms to collect evidence automatically.

Incident response (RS)

Respond function evidence collected from your ticketing and incident management tools: response times tracked, lessons learned documented, and post-incident reviews recorded as audit evidence.

Crosswalks

  • ISO 27001: Annex A controls are mapped to the six functions.
  • SOC 2: the Trust Services Criteria are mapped to the CSF.
  • NIST SP 800-53: catalog controls are mapped to CSF subcategories.
  • CAN/DGSI 104: the 18 baseline controls map to the Protect and Detect functions.
  • OSFI B-13: the guideline is aligned to the CSF structure.
  • NIS2: regional measures mapped to the CSF functions.

Further reading

Compliance automation.

See your NIST CSF 2.0 profile against your real stack.

Contact us

Frequently asked questions

Is the NIST CSF mandatory?
No. The NIST Cybersecurity Framework is voluntary and widely adopted because it describes what good cybersecurity looks like rather than prescribing specific controls. That makes it an ideal overlay framework that maps to whatever standards you are already required to follow, such as ISO 27001, SOC 2 or NIST SP 800-53, and a common language with executives and the board.
What is the Govern function added in version 2.0?
The Govern (GV) function, new in version 2.0 released in 2024, addresses cybersecurity strategy, policy, roles, risk management oversight and supply chain risk governance (GV.SC) at the executive level. It joins the five existing functions: Identify, Protect, Detect, Respond and Recover.
What are the current profile and the target profile?
The current profile describes the cybersecurity outcomes your organization achieves today, function by function; the target profile describes the ones it aims for. The gap between the two becomes a prioritized roadmap. Sentrix tracks both profiles and shows the board and executive teams progress toward the target profile over time.

Let's talk about your compliance program.

Last updated: 2026-09-17