NIST RMF is a process and a lifecycle. It tells you the steps to run, the artifacts you have to produce at each gate, and the moment at which an Authorizing Official signs off and lets the system go live. The language of RMF is SP 800-53 controls, ATOs, and POA&Ms.
NIST CSF 2.0 is a taxonomy and a common vocabulary. It does not prescribe a process or ask for an ATO; it gives every team a shared list of cyber outcomes — the six functions — so the security group, the auditor, and the regulator can talk about the same thing. The language of CSF 2.0 is Govern, Identify, Protect, Detect, Respond, Recover.
They overlap cleanly in three places. RMF Categorize maps to CSF Identify — both demand an evidence-backed asset and risk inventory before anything else. RMF Implement and Assess map to CSF Protect and Detect — the controls you ship and the signals that prove they work. RMF Monitor touches all six CSF functions, because continuous monitoring is what keeps a once-signed ATO honest over time. In short: RMF is the engine, CSF 2.0 is the dashboard.