NIST CSF 2.0 vs 1.1: what actually changed
NIST released CSF 2.0 in February 2024 — the first major revision since 2014's v1.0. If your program is still mapped to v1.1, here's what moved.
The headline change: Govern
CSF 2.0 adds a sixth Function, Govern (GV), alongside Identify, Protect, Detect, Respond, and Recover. Governance — risk strategy, roles, policy, supply-chain oversight — was scattered through v1.1; now it has its own home and its own outcomes. In practice this means your risk management strategy, board reporting, and vendor-risk program map to GV, not to a footnote under Identify.
Structure, by the numbers
- 6 Functions (was 5): Govern, Identify, Protect, Detect, Respond, Recover.
- 22 Categories and 106 Subcategories — the outcome statements you actually assess against.
- Implementation Examples added under most subcategories — concrete "what good looks like" guidance v1.1 lacked.
- Informative References updated to map subcategories to SP 800-53, ISO 27001, and other sources.
It's no longer just for critical infrastructure
CSF 1.x was built for critical infrastructure under a 2013 executive order. CSF 2.0 is explicitly written for all organizations regardless of size or sector, with tailored quick-start guides for small business, enterprise, and organizations with higher-risk profiles.
What to do about it
Don't re-paper your whole program on day one. Map your existing v1.1 profile to 2.0, identify where Govern outcomes are currently homeless, and close those gaps first — that's where auditors and customers will now look. Our readiness check is built on the 2.0 functions.
Get quotes from verified firms
One brief, matched firms, competing quotes — free.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.