
Key takeaways
- The framework describes results, leaving the choice of controls open. Informative References point toward candidates, and settling on a set that satisfies each outcome is your call.
- Twelve of the twenty-three CSF 1.1 Categories came out in the rewrite. Two transferred with minor definition changes and ten were incorporated with significant ones.
- Accountability under Govern runs upward. Leadership carries responsibility for cyber risk, approves the risk register, and answers for whether roles and budget exist.
- Tiers describe the rigor of governance and management, and NIST scopes their selection to leadership at Function or Category level. A subcategory-level score answers a different question.
- Conformity assessment for CSF has no NIST program behind it. Certificates bearing the framework name originate with whoever issued them.
Teams often meet NIST CSF 2.0 as a spreadsheet someone else built. Each row carries a subcategory ID. GV.SC-04, PR.AA-05. Owners get assigned, and a quarter later the question of whether a row is finished has no clean answer.
All 106 subcategories describe results. NIST also left a marker in its own numbering that tells you when a mapping document has gone stale.
NIST CSF 2.0 controls are outcomes you still have to build
GV.SC-04 asks that suppliers be known and prioritized by criticality, and stops there. Nothing in the Core sets a threshold for criticality. GV.RM-06 separately asks you to establish a standardized method for prioritizing cybersecurity risks, and the CSF does not supply one.

The abstract of CSWP 29 declines to prescribe how outcomes should be achieved and points to online resources covering practices and controls. Section 2 of the same document states that the outcomes are not a checklist of actions to perform.
NIST does hand you candidate controls through Informative References. Section 4 explains that one control from SP 800-53 may be one of many references needed to achieve the outcome in a single subcategory. Your spreadsheet row is a result, and the set of controls that produces it is yours to assemble and defend.
Subcategory numbers are intentionally nonsequential, and NIST states the gaps mark CSF 1.1 subcategories that were relocated. PR.DS runs 01, 02, then jumps to 10 and 11. DE.CM runs 01, 02, 03, 06, 09. CSF 2.0 also numbers every subcategory with two digits, so a document citing DE.CM-4 or PR.DS-3 is working from CSF 1.1.
Map NIST CSF outcomes to CIS IG1 and 800-171 controls
CIS Controls v8.1 does the prescriptive work CSF leaves open. The Center for Internet Security labels IG1 essential cyber hygiene and calls it a foundational set of 56 safeguards. CIS frames those safeguards as what every enterprise should apply against the most common attacks, and it treats IG1 as an emerging minimum standard.
CIS scopes IG1 narrowly. It targets smaller enterprises with lower-sensitivity data facing untargeted attacks. Anyone handling CUI should read the scoping language before adopting IG1.
CSF gives you the outcome to govern and report against. IG1 gives you the specific safeguard to implement.
Teams already running NIST SP 800-171 controls have material to reuse. Those controls are written and evidenced, and much of that work supports CSF outcomes you have not formally claimed.
NIST CSF 2.0 dropped 12 of 23 CSF 1.1 categories
NIST published a companion document listing every withdrawn CSF 1.1 element, and just over half the category structure carries the Withdrawn label.
Read the withdrawal wording before you remap anything. NIST marks some items moved to, meaning a single destination with minor changes to the definition. Others are marked incorporated into, meaning significant changes, sometimes spread across several destinations at once.
Some outcomes left their function altogether. PR.IP-11 moved to GV.RR-04, carrying a Protect item into Govern. DE.CM-08 was incorporated into ID.RA-01. RS.AN-05 moved to ID.RA-08.
Where one CSF 1.1 subcategory now answers to five
NIST incorporated ID.SC-01 into five separate CSF 2.0 subcategories, and ID.SC-02 into five more. One row in your old assessment now owes evidence to all the outcomes.

PR.DS-09 never shipped. NIST flags it as the only subcategory added in the CSF 2.0 public comment draft and withdrawn before the final release. Any mapping built during that window still lists it.
Who signs off on risk under the NIST CSF 2.0 govern function
NIST's workforce and ERM quick-start guide, finalized in March 2026, puts authority on named levels. It convenes stakeholders who hold the authority to execute risk responses, draws accountable leads from board level and executive leadership, and lists executive sponsorship among its sample activities. Its last step has the leadership team finalize and sign off on the updated risk register.
The evaluation stage asks you to confirm authority has not fragmented across the enterprise.
Where GV.RR puts enforcement and resourcing in writing
GV.RR runs four subcategories deep. GV.RR-01 makes organizational leadership responsible and accountable for cybersecurity risk. GV.RR-02 asks that roles, responsibilities, and authorities be established, communicated, understood, and enforced. GV.RR-03 calls for adequate resources allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies. GV.RR-04 places cybersecurity inside human resources practices.
The guide pairs ownership with competence. Its sample activities include designating risk owners who remain accountable to internal and external authorities, and it suggests a gap analysis between the assigned owner and the risk work role to check whether that person holds the competencies. Its sample risk register gives risk owner and risk action owner separate columns, and records a risk response type alongside its cost.
Why the NIST CSF maturity score is not a tier
The usual artifact is a spreadsheet with a 1-to-5 column and an average at the bottom. The Tiers quick-start guide that NIST finalized in October 2024 describes a Tier differently on two counts. Organization leadership generally selects the Tier. And choosing Tiers overall or at the Function or Category level gives a better sense of current practice than choosing them at the lower Subcategory level.
What Tiers capture is rigor. They run Partial, Risk Informed, Repeatable, and Adaptive, a progression from informal ad hoc responses toward approaches that are agile, risk-informed, and continuously improving. Each Tier carries two descriptions, one keyed to Govern and one to the other five Functions.
Where NIST CSF Tiers allow your own descriptions
An organization can reuse the notional Tier descriptions from Appendix B of the framework, customize them, write new ones, or use a set it already has in place. A maturity scale you already maintain fits that last option, and the guide assumes a methodology of your own already exists, since Tiers inform it without replacing it.
Tiers then feed the Profile. Leadership picks a Tier for a Function. The Current Profile records how well that Tier's characteristics are currently achieved across the Categories inside it, and the Target Profile records the improvements needed to reach the description in full.
The NIST CSF guide your buyer builds questionnaires from
NIST's C-SCRM quick-start guide, finalized in October 2024, tells acquirers how to build the questionnaire you receive.
Buyers weigh how important your product is to their business, how sensitive the data you handle is, and how much access you hold to their systems. Those factors decide which criticality level you land in. Suppliers in higher levels receive longer questionnaires.
A buyer can select CSF Categories and Subcategories directly, or build a Target Profile for each criticality level and share it as their set of C-SCRM requirements.
NIST publishes examples of the subcategories that carry supplier requirements. They span all six Functions and include GV.OC-03, GV.RR-02, ID.RA-09, ID.RA-10, PR.AA-01, PR.AT-02, DE.CM-03, RS.CO-02, and RC.RP-03. You can work that list before a buyer sends you anything.
The evidence NIST tells buyers to ask for
NIST's checklist has buyers contractually requiring four things from suppliers. Disclose cybersecurity features, functions, and vulnerabilities for the life of the product or term of service. Maintain a current component inventory for critical products. Vet employees against insider threats. Provide evidence of acceptable security practices.
NIST names four acceptable forms of evidence, which are self-attestation, conformance to known standards, certifications, and inspections. A questionnaire is a self-attestation, and its weight comes from the controls and evidence standing behind each answer.
Security requirements also go into service level agreements for monitoring suppliers across the relationship lifecycle.
Koop pulls those answers from evidence you already hold. It automates the common questionnaire formats, including SIG, VSA, and CAIQ. It reports up to 95% of compliance tasks automated through Housekeeper, its AI agent.
Running NIST CSF 2.0 with one person and no CISO
NIST's small business quick-start guide, published February 2024, addresses organizations with modest or no cybersecurity plans in place.
Among its governance questions is whether you need to upskill existing staff, hire talent, or engage an external partner to establish and manage the plan. Under Detect, it goes further, telling you to prioritize engaging a service provider to monitor computers and networks if you lack the resources internally.
Every Function in the guide runs on four verbs: Understand, Assess, Prioritize, and Communicate.
What NIST CSF tells small businesses to prioritize first
Multi-factor authentication leads. NIST asks for it on every account that offers one under PR.AA-03, with password managers suggested alongside. It calls MFA one of the fastest and cheapest ways to protect your data, and says to begin with the accounts that reach the most sensitive information.
A starter checklist follows, running banking, accounting and tax, merchant, platform, email, password manager, and website accounts. NIST notes your own list will run longer.
Access limits come next. PR.AA-05 covers restricting sensitive information to employees who need it for their jobs, and NIST asks whether you remove that access once the need ends. Changing default manufacturer passwords earns its own line under PR.AA-01.
Three more items carry the Prioritize label under Protect. Patching software and operating systems with automatic updates enabled, backing up data and testing the backups, and enabling full-disk encryption on laptops and tablets.
There is no NIST CSF certification, only assessments
A customer asks whether you are NIST CSF certified. NIST published the answer to that exact question.
Its CSF FAQ states that NIST does not offer certifications or endorsements of CSF-related products, implementations, or services, and that there are no plans to develop a conformity assessment program.
Third parties can still sell you a certificate. One issued by an assessment body is that body's certificate, and carrying the framework's name in the title does not make NIST the issuer.
Three claims hold up. You can self-attest to the outcomes you achieve, which is what a completed questionnaire already amounts to. You can point to certifications in standards that do issue them, ISO 27001 among them. And you can commission a third-party assessment that produces a report on your alignment.
Sequencing your NIST CSF 2.0 work with Koop
Teams carrying CSF 1.1 mappings should remap first, using the withdrawn-elements document to separate what NIST moved from what it incorporated. Teams with nothing to inherit start on the small business Prioritize list, at multi-factor authentication on every account that offers it.
GV.SC-04 asks you to rank your own suppliers the same way your customers rank you.
Requirements arriving from different teams land in one place in Koop's third-party risk management, and each vendor's compliance, security, and insurance posture stays visible. When a posture stops meeting your requirements, you get notified. Reviewing red flags and closing non-compliance gaps run in the same workflow.
Its regulatory intelligence database tracks existing and upcoming regulations, so a change like the CMMC Phase II suspension reaches you when it happens.
Frequently asked questions
- Is NIST CSF 2.0 mandatory?
No, not on its own. NIST describes the CSF as a resource that may be adopted voluntarily and through governmental policies and mandates. Whether it binds your organization depends on your contracts and your regulator.
- How many functions and controls are in NIST CSF 2.0?
CSF 2.0 contains six Functions, 22 Categories, and 106 Subcategories. That structure replaced the 23 Categories in CSF 1.1, twelve of which NIST withdrew.
- Does NIST CSF 2.0 replace NIST SP 800-171 or CMMC?
No. They are separate regimes. CSF 2.0 is voluntary, and 800-171 arrives through contract clauses. On July 13, 2026, the Department of War suspended CMMC Phase II with immediate effect, along with pending and future implementation milestones. Phase II had been scheduled for November 10, 2026. Phase I self-assessment requirements remain firmly in place, the Department continues enforcing NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments, and DFARS clause 252.204-7012 obligations are unchanged. The CMMC Reform Task Force delivers its final report to the DoW CIO within 60 days of that announcement, placing it around mid-September 2026.



