Guide

NIST CSF 2.0 vs 1.1: what actually changed

NIST released CSF 2.0 in February 2024 — the first major revision since 2014's v1.0. If your program is still mapped to v1.1, here's what moved.

The headline change: Govern

CSF 2.0 adds a sixth Function, Govern (GV), alongside Identify, Protect, Detect, Respond, and Recover. Governance — risk strategy, roles, policy, supply-chain oversight — was scattered through v1.1; now it has its own home and its own outcomes. In practice this means your risk management strategy, board reporting, and vendor-risk program map to GV, not to a footnote under Identify.

Structure, by the numbers

It's no longer just for critical infrastructure

CSF 1.x was built for critical infrastructure under a 2013 executive order. CSF 2.0 is explicitly written for all organizations regardless of size or sector, with tailored quick-start guides for small business, enterprise, and organizations with higher-risk profiles.

What to do about it

Don't re-paper your whole program on day one. Map your existing v1.1 profile to 2.0, identify where Govern outcomes are currently homeless, and close those gaps first — that's where auditors and customers will now look. Our readiness check is built on the 2.0 functions.

Independent directory. CSFCompliance.com is an independent directory and quote-matching service.

Get quotes from verified firms

One brief, matched firms, competing quotes — free.

Get a free quote

← All guides