Skip to main content
—
Framework library
Framework module · nist-csf-2-0

NIST Cybersecurity Framework

The outcome-based vocabulary boards use to talk about cyber risk. Not certifiable — it organizes a program rather than testing one.

2.0 · NIST Cybersecurity Framework · published 2024-02-26

Standing today
Acquisition required

00Answer

from the registry record
What is NIST Cybersecurity Framework?
The outcome-based vocabulary boards use to talk about cyber risk. Not certifiable — it organizes a program rather than testing one.
Who does NIST Cybersecurity Framework apply to?
NIST Cybersecurity Framework applies to all sectors, US, global, per NIST Cybersecurity Framework.
What is the current version of NIST Cybersecurity Framework?
The current edition is 2.0, issued by NIST Cybersecurity Framework and published 2024-02-26. Source: https://www.nist.gov/cyberframework.
What does an assessment under NIST Cybersecurity Framework require?
No control catalog has been ingested for NIST Cybersecurity Framework yet — the registry tracks it as roadmap (Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Acquisition required

Named, with the authority's acquisition path recorded; onboarding is refused until a control set is registered.

NIST Cybersecurity Framework cannot be onboarded yet: Freely published; not ingested as a control catalog. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.

NIST Cybersecurity Framework cannot be onboarded yet: Freely published; not ingested as a control catalog. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.

02Registry record

checked 2026-08-26
Registry status
Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Govern · Identify · Protect · Detect · Respond · Recover
Applies to
all sectors · US · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-26

03Version ledger

2 editions
1.1Superseded2018-04-16
2.0Current edition · supersedes 1.12024-02-26

04Authority intelligence

reviewed 2026-08-30

Curated primary-source signals connected to this registry record. An authority change creates review work; it does not silently change tenant posture, evidence credit, or prior decisions.

  1. Draft guidance

    NIST publishes draft guidance for using AI in CSF analysis.

    The initial public draft of SP 1353 illustrates AI-assisted CSF analysis, planning, implementation, and monitoring while calling for precautions and continuous evaluation and improvement.

    Operating move

    Version the prompt, approved source set, generated profile or report, evaluation result, and named reviewer disposition as one governed work record.

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to all sectors · NIST's voluntary framework for managing privacy risk through enterprise risk management. It is guidance, not a regulation or certification.

  2. NIST SP 800-53Rev. 5, Release 5.2.0

    Same framework family · NIST's federal security and privacy control catalog, used directly or tailored by programs such as FedRAMP and CMS ARC-AMPE. CMMC Level 2 instead uses NIST SP 800-171 requirements.

  3. ASD Essential EightMaturity Model (November 2023)

    Also applies to all sectors · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.

  4. Also applies to all sectors · A prioritized, prescriptive set of defensive actions organized into three implementation groups — the practical starting list when a team has no framework yet.

NIST Cybersecurity Framework | ControlFrame