
What the document says
On 26 February 2024, NIST released version 2.0 of the Cybersecurity Framework. The framework document itself, NIST CSWP 29, records that the publication previously titled the Framework for Improving Critical Infrastructure Cybersecurity no longer carries that name, reflecting a scope that now explicitly covers organizations of any size, sector or maturity rather than critical infrastructure operators specifically. The Core's six Functions are now Govern, Identify, Protect, Detect, Respond and Recover. Govern is new in this version and covers how an organization establishes, communicates and monitors its cybersecurity risk strategy, including supply chain risk management and the assignment of roles and authorities that inform the other five Functions.
The document also defines Organizational Profiles, which describe an organization's current or target outcomes against the Core, and Tiers, which characterize the rigor of an organization's risk governance on a four-step scale from Partial through Risk Informed and Repeatable to Adaptive. The document states directly that the CSF does not prescribe how outcomes should be achieved; it links instead to online Informative References and Implementation Examples maintained separately from the document.
Confidence and limits
This description rests on the framework document and NIST's own announcement, both primary sources with no ambiguity about what was published or when. The remaining uncertainty is about use, not content: because the CSF is voluntary guidance rather than a certification scheme, an organization's claim to follow it cannot be verified from the document alone, and NIST's own Cybersecurity Framework website, current as retrieved 16 September 2026, does not define what would count as sufficient adoption for any particular regulatory or contractual purpose.
Why it mattered
Adding Govern as a named Function makes explicit something many mature security programs already treated as implicit: that risk decisions, accountability and resourcing sit upstream of technical controls. Dropping the critical-infrastructure framing acknowledged that the CSF's actual user base, spanning small businesses to large enterprises across every sector, had already outgrown its original title. Because the CSF is widely referenced in contracts, insurance questionnaires and other frameworks' cross-references, a structural change to its Core ripples into how many organizations describe their own programs, even when no regulation requires them to use it.
Defensive takeaway
Map your existing security documentation to the CSF's six Functions and identify which Function, most often Govern, has the thinnest evidence behind it, rather than assuming a general sense of alignment is sufficient.
- Do we have a written Target Profile, or only informal awareness of the CSF's existence?
- Which of the six Functions has the least documented ownership and authority behind it in our organization?
- If a partner or regulator asked how we use the CSF, could we point to a specific Tier assessment rather than a general claim of familiarity?
CSF 2.0 is a vocabulary and structure for describing cybersecurity risk management, not a scorecard; its value depends entirely on whether an organization uses the Profiles and Tiers to make and document real decisions rather than treating the framework as a name to cite.
Before citing the CSF as evidence of your security posture, confirm your organization has an actual Current and Target Profile against the Core, not just a general claim of alignment.
The framework document and NIST's own release describe the changes directly; the CSF explicitly disclaims prescribing specific controls, so any claim that an organization is CSF compliant or certified goes beyond what the document itself supports.
Sources & reading trail
Announces the 26 February 2024 release of CSF 2.0 and its expanded Govern function and broadened scope.
government-primary · Source published: 26 February 2024 · Retrieved: 16 September 2026
Defines the six Core Functions including Govern, defines Tiers as Partial/Risk Informed/Repeatable/Adaptive, and states the CSF does not prescribe how outcomes should be achieved.
standards-body · Source published: 26 February 2024 · Retrieved: 16 September 2026
The framework's living reference page, hosting CSF 2.0 as the current version along with supplemental implementation resources, as retrieved 16 September 2026.
standards-body · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.