What is NIST CSF 2.0?
The US National Institute of Standards and Technology's Cybersecurity Framework. Version 2.0 is a voluntary, outcome-based framework organised as six functions, widely used outside the US as a common structure for describing a security programme.
Nobody by law outside specific US federal contexts. It matters here because it is the structure other frameworks are built from — the CyFun 2025 requirement ids are literally CSF 2.0 subcategory ids.
Govern, Identify, Protect, Detect, Respond, Recover.
The function that did not exist in 1.1, covering strategy, roles, policy and oversight.
The outcome statements assessments are made against.
Dates that matter
- 26 February 2024Version 2.0 published as NIST CSWP 29.
- 2014 / 2018Versions 1.0 and 1.1 — still widely referenced, and not interchangeable with 2.0.
What people get wrong
GOVERN is the 2.0 change that matters
Version 1.1 had five functions. Version 2.0 adds GOVERN and places it at the centre: organisational context, risk management strategy, roles and responsibilities, policy, oversight, and supply chain risk management. A programme built on 1.1 has this as a genuine gap rather than a renaming.
Subcategory ids changed between versions
1.1 ids do not map cleanly onto 2.0. DE.CM-08, for instance, exists in 1.1 and not in 2.0. If a document cites a subcategory that will not resolve, check which version it was written against before assuming it is a typo.
It is the spine under CyFun
The CyFun 2025 edition is defined as a selection of CSF 2.0 subcategories, so a requirement id in CyFun IS a subcategory id. That is why coverage against one informs the other.
What Vivid Risk does with NIST CSF 2.0
Subcategory citations on every scored control, read against NIST CSWP 29 and its own outcome text.
Questions
Is NIST CSF relevant to a European organisation?
As a structure, yes — it is the vocabulary many frameworks and vendors share, and CyFun is built from it directly. As a legal obligation, no.
Which version do you cite?
2.0 only, read against NIST CSWP 29 and its own outcome text. Sixteen citations in this product were corrected during that read, including one that pointed at a 1.1 subcategory which does not exist in 2.0.
One assessment, every framework
The same answers produce your citations across every framework we cover at once, rather than one questionnaire per regulation.