> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# NIST CSF v2.0

> Manage and reduce cybersecurity risk with the NIST Cybersecurity Framework version 2.0.

> Manage and reduce cybersecurity risk with the NIST Cybersecurity Framework version 2.0.

The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary framework developed by the U.S. National Institute of Standards and Technology. Released in 2024, version 2.0 expands the original five functions to six by adding **Govern**, making it suitable for organizations of all sizes and sectors — not just critical infrastructure.

<Note>
  NIST CSF 2.0 is widely adopted across industries as a flexible, outcome-based approach to managing cybersecurity risk. It is not a certification — it is a framework for organizing and improving your security program.
</Note>

## Who needs NIST CSF v2.0?

<CardGroup cols={2}>
  <Card title="Organizations of any size" icon="building">
    CSF 2.0 was redesigned to be useful for small businesses through large enterprises across every sector.
  </Card>

  <Card title="Government contractors" icon="landmark">
    Often used as a baseline to demonstrate cybersecurity maturity to federal and state agencies.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="Govern" icon="gavel">
    **New in 2.0.** Establishes and monitors the organization's cybersecurity risk management strategy, expectations, and policy.
  </Card>

  <Card title="Identify" icon="magnifying-glass">
    Understand assets, data, capabilities, and risks to systems, people, and operations.
  </Card>

  <Card title="Protect" icon="shield">
    Implement safeguards — access control, awareness training, data security, and maintenance.
  </Card>

  <Card title="Detect" icon="radar">
    Identify cybersecurity events through continuous monitoring and detection processes.
  </Card>

  <Card title="Respond" icon="bolt">
    Take action on detected incidents — response planning, communications, analysis, mitigation.
  </Card>

  <Card title="Recover" icon="arrows-rotate">
    Restore capabilities and services impaired by incidents and improve resilience.
  </Card>
</CardGroup>

## How DSALTA helps with NIST CSF v2.0

<Steps>
  <Step title="Activate NIST CSF 2.0">
    Select NIST CSF 2.0 from the Frameworks page. DSALTA maps all six functions and their categories to pre-built controls.
  </Step>

  <Step title="Review mapped controls">
    DSALTA maps controls across Govern, Identify, Protect, Detect, Respond, and Recover. Review each and assign owners.
  </Step>

  <Step title="Collect evidence automatically">
    Connect integrations so DSALTA runs automated tests and gathers evidence continuously.
  </Step>

  <Step title="Approve policies">
    Review and approve AI-generated policies pre-mapped to CSF outcomes.
  </Step>

  <Step title="Track maturity">
    Monitor your implementation tier and readiness across all six functions.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="What is new in CSF 2.0 versus 1.1?" icon="circle-question">
    The biggest change is the addition of the **Govern** function, which elevates cybersecurity governance and risk management to a core pillar. CSF 2.0 also broadened its scope beyond critical infrastructure to all organizations.
  </Accordion>

  <Accordion title="Is NIST CSF a certification?" icon="certificate">
    No. NIST CSF is a voluntary framework, not a certifiable standard. There is no official NIST CSF certificate, though you can demonstrate alignment to customers and regulators.
  </Accordion>

  <Accordion title="How does CSF relate to ISO 27001?" icon="arrows-left-right">
    They are complementary. ISO 27001 is a certifiable management system standard, while NIST CSF is an outcome-based framework. Many organizations map between the two.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
