Framework
Beginner

NIST CSF 2.0 Quick-Start

A beginner-friendly walk of NIST CSF 2.0 — the six functions, the four-tier maturity model, three real analyst briefs to anchor each function to a working scenario, and where to go next once you have read it.

Last updated:

Pair this primer with the full course: Full /courses/nist-csf-2 walk →

The six functions

  • A voluntary framework with the six functions Govern, Identify, Protect, Detect, Respond, Recover — language that maps to almost any other standard.
  • Govern — owns the rules, risk appetite, roles, and supplier oversight. The newest function in CSF 2.0 and the one most teams under-invest in.
  • Identify — owns the inventory: assets, data, systems, people, and the risks against them. You cannot protect what you have not named.
  • Protect — owns the controls that keep the bad day from happening: access management, training, encryption, secure configuration.
  • Detect — owns the signal: logging, monitoring, and the anomalies that say the bad day is already happening.
  • Respond — owns the playbook you run once the signal fires: containment, communication, eradication.
  • Recover — owns the return to normal: restoration, lessons learned, and the controls you add so the next bad day is smaller.

Tiers 1–4

  • Tier 1 — Partial: ad hoc, reactive, dependent on heroics. Risk is unmanaged.
  • Tier 2 — Risk-Informed: approved by leadership but not standardized across the org. Risk decisions are made; processes are not repeatable.
  • Tier 3 — Repeatable: formally policy-driven, regularly updated, and tested across the org.
  • Tier 4 — Adaptive: continuous, informed by threat intel and prior incidents; the org actively improves its posture based on what the world is doing.

Three beginner briefs, one function each

  • WovenCart (D2C apparel on Shopify Plus, PCI scope on the marketing tooling that touches cardholder data). Open the "Identify" function first: you need an inventory of which systems actually see cardholder data before you can defend the SAQ-A evidence the QSA will ask for.
  • Lumora Learning (EU K-12 tutoring platform, processing minors' educational records and shipping an AI-recommendation feature). Open the "Govern" function first: parental-consent flows, DPIA gating, and AI-profiling policy are the gating controls on launch.
  • Atlas Health Partners (regional integrated delivery network, HIPAA exposure and a half-finished HITRUST journey post-merger). Open the "Protect" function first: encryption at rest on endpoints, BAA-backed vendor contracts, and workforce-training evidence are the three pieces an OCR inquiry letter asks about before anything else.

Next steps

Once you can name which function a brief opens first, you are no longer reading CSF 2.0 as a checklist; you are using it as a triage tool. The next concrete move is to score a real environment against it. The Gap Analysis lab below runs a 0–3 maturity walk across the framework's twelve control areas so you can hand a print-ready Gap Report to whoever signs the controls budget.

When you are ready to read the matching course, the full /courses/nist-csf-2 walk covers the function-to-control mapping in detail. Until then, the laminate for CSF 2.0 is: name the function, name the brief, name the next concrete artifact.

If the next system in your queue is a federal or fed-adjacent one, the /guides/nist-rmf primer is the matching lifecycle primer: SP 800-53, ATO, POA&M.

Next
Next: try the Gap Analysis lab

Score a real environment against the 12 CSF 2.0 control areas on a 0–3 maturity scale and print a Gap Report (per-area current vs target, average maturity, and a remediation list sorted lowest first).

Open the Gap Analysis lab →