Framework · Last verified
The NIST Cybersecurity Framework (CSF) 2.0
The NIST Cybersecurity Framework 2.0 is guidance a business aligns with, not a certification — published by NIST as CSWP 29 on 26 February 2024. Its Core organises cybersecurity outcomes around six Functions — Govern, Identify, Protect, Detect, Respond and Recover — and NIST states it can be used by organizations of any size, sector or maturity.
- Class
- Framework
- Owner
- National Institute of Standards and Technology (NIST), U.S. Department of Commerce
- Last verified
What it is
The NIST Cybersecurity Framework 2.0 is guidance, not a certification. Its abstract states that it "provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity …" (the sentence continues in the source). The Core is organised around six Functions: "The CSF Core Functions — GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER — organize cybersecurity outcomes at their highest level."
Before version 2.0, NIST notes, "the Cybersecurity Framework was called the 'Framework for Improving Critical Infrastructure Cybersecurity.' This title is not used for CSF 2.0."
Who owns it
The framework is published by the National Institute of Standards and Technology (NIST), an agency of the U.S. Department of Commerce, as NIST CSWP 29 (26 February 2024).
Who asks for it
Voluntary. NIST frames adoption as voluntary AND through governmental policy or mandate — not purely optional. Which specific policies mandate it was not verified in the sources reviewed as of 28 August 2026.
Adoption is not framed as purely optional by NIST itself: "The CSF is a foundational resource that may be adopted voluntarily and through governmental policies and mandates." Which specific U.S. federal policies reference the CSF was not verified in the sources reviewed as of 28 August 2026 — confirm against the referencing policy instrument.
Sources
- NIST CSWP 29 — The NIST Cybersecurity Framework (CSF) 2.0 ↗ — accessed
- NIST CSRC — CSWP 29 publication record (published 26 February 2024) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.