Skip to content
← Services

NIST CSF

NIST Cybersecurity Framework 2.0

Industry StandardGlobalIn force: February 26, 2024

What it is

NIST CSF 2.0 expanded the original five-function framework (Identify, Protect, Detect, Respond, Recover) with a sixth function — Govern — reflecting the elevation of cybersecurity to board-level accountability. Widely adopted globally as a flexible framework adaptable to any organisation regardless of sector.

What it requires

Voluntary, organisation-agnostic framework. The six functions decompose into 22 categories and approximately 100 subcategories. Used as a mapping layer to translate between regulatory regimes — NIS 2, ISO 27001, CRA, sector-specific frameworks — and as a board-reportable maturity instrument.

Key facts

Supervisor
Voluntary framework — no direct supervisor; widely referenced in US federal contracting, insurance underwriting, and board-level governance

DSI services for NIST CSF

DSI Advisory Services helps covered entities translate NIST CSF obligations into evidence a supervisor, auditor, or board can sign off on — gap assessment, control mapping, and documentation that survives review.

See the service →

Related briefings

Security Doesn't Need Another Framework. It Needs an Operating Model.
Practitioner OperationsJune 21, 2026
Security Doesn't Need Another Framework. It Needs an Operating Model.

On 12 January 2024, a Russian state actor read the email of Microsoft's senior leadership. Not through a zero-day — through a forgotten legacy test tenant with no MFA, an over-permissioned OAuth app, and an elevated consent grant nobody owned. The path crossed four domains; not one team owned the route. Every control was green. Storm-0558 was the same shape: a consumer signing key accepted as valid for enterprise mailboxes — a seam between two identity planes. This is the failure the industry refuses to name. A vulnerability is a property of a component; a threat is a property of the system. We have spent two decades building frameworks that make each silo defensible in isolation and almost no time building the thing that lets a defender reason across them the way an attacker already does. The fix is not another framework. It is an operating model — decision rights, intake, prioritisation, governance, delivery engagement — the connective tissue that owns the seams. Run the removal test: if your security function vanished tomorrow, would any business decision change? Part I of two. Part II continues on ARIA.

Free tier8 min read
Before the Warzone: Why the Only Answer to the Internet's Most Dangerous Vulnerability Has to Come First
Internet GovernanceMarch 24, 2026
Before the Warzone: Why the Only Answer to the Internet's Most Dangerous Vulnerability Has to Come First

The concluding piece in a series that began with a cable ship declaring force majeure and ended with a question nobody in power has answered. The answer has to exist before the warzone, not inside it.

Free tier11 min read

Read more on this

Other industry standard frameworks in the DSI registry: