The NIST Cybersecurity Framework (CSF) is a voluntary framework from the U.S. National Institute of Standards and Technology that organizes cybersecurity work into six functions. It isn't a certification and doesn't produce a pass/fail audit — it's a shared vocabulary and structure that a huge number of organizations use to organize their security program, regardless of size or industry.
The six functions (CSF 2.0)
Govern
Aligns cybersecurity with business strategy and establishes accountability. New in version 2.0, and a deliberate signal that security is a business-wide responsibility, not just IT's.
Identify
Maps assets, risks, and dependencies so the organization actually knows what it has and what could go wrong.
Protect
Secures critical assets and reduces the likelihood of initial access — access control, training, data security.
Detect
Finds and analyzes attacks early, minimizing how long a threat sits undetected.
Respond
Contains an active threat and prevents it from spreading further once it's found.
Recover
Restores normal operations and feeds lessons learned back into the program.
What changed in CSF 2.0
The biggest addition is Govern itself — the original five-function version treated cybersecurity as a mostly technical discipline. Version 2.0 also widened its intended audience: rather than focusing mainly on critical infrastructure operators, it's now written for organizations of any size or sector, which is a big part of why it's become such a common reference point in GRC conversations.
Voluntary, but everywhere
NIST CSF carries no certification and, for most private companies, no legal requirement to adopt it. Its influence comes from being a genuinely useful shared structure — it shows up constantly in job postings, security questionnaires, and other frameworks that reference it, even though almost nobody is legally forced to use it.
How this connects to GRC work
A GRC team often uses NIST CSF's six functions as the skeleton for organizing a broader risk and control program, then layers frameworks like ISO 27001 or SOC 2 on top for the parts that need external certification or attestation.