Cybereen / Resources / NIST CSF
NIST CSF

NIST CSF 2.0: the six functions, explained

By Cybereen · 11 July 2026

The NIST Cybersecurity Framework is a way of organising everything a security programme has to do into a small number of plain-language functions. Version 2.0, released in early 2024, made one headline change: it added a sixth function, Govern, and wrapped it around the other five. This guide explains what each function covers, how Tiers and Profiles fit in, and how to turn the framework into something you can actually measure.

The six functions

NIST CSF 2.0 groups all cybersecurity outcomes under six functions. They aren’t sequential steps — they run continuously and overlap.

  • Govern (GV) — the new one in 2.0, and the centre of gravity. It’s how you set and oversee your cyber risk strategy: organisational context, roles and responsibilities, policy, risk appetite, and oversight of the supply chain. Govern is the function that tells the board what the other five are supposed to achieve.
  • Identify (ID) — knowing what you have and what could go wrong. Asset inventories, the risk assessment, and understanding your business context and dependencies.
  • Protect (PR) — the safeguards that reduce the chance and impact of an incident: access control, awareness and training, data security, and resilient infrastructure.
  • Detect (DE) — finding attacks and anomalies. Continuous monitoring and the analysis that turns raw events into “this is an incident”.
  • Respond (RS) — what you do once something is confirmed: incident management, analysis, containment, and reporting to the people and regulators who need to know.
  • Recover (RC) — restoring services and data after an incident, and communicating clearly while you do it.

A useful way to hold them: Govern sets direction; Identify and Protect are before an incident; Detect, Respond and Recover are during and after.

Functions, categories, subcategories

Each function breaks down into categories (like “Asset Management” under Identify) and then subcategories — the specific, testable outcomes you actually evidence. It’s the same nesting idea as ISO 27001’s Annex A: the function is the headline, the subcategory is where the work lands.

You don’t implement “Protect” as a single thing. You implement its subcategories, one control and one piece of evidence at a time.

Tiers and Profiles: how you measure it

Two concepts turn the framework from a checklist into a management tool.

  • Tiers (1–4) describe how rigorous and consistent your risk management is: Tier 1 Partial, Tier 2 Risk Informed, Tier 3 Repeatable, Tier 4 Adaptive. Tiers aren’t a maturity score to max out — they’re a deliberate choice about how much rigour your risk actually warrants.
  • Profiles are the heart of it. Your Current Profile is where you are today against the subcategories; your Target Profile is where you’ve decided you need to be. The gap between the two is your roadmap.

That Current-versus-Target framing is why NIST CSF works well as a live scorecard rather than a once-a-year assessment — which is exactly how Cybereen tracks NIST CSF: a current and target profile across all six functions, with the gap surfaced per outcome.

Where teams get stuck

The framework is deliberately outcome-based — it tells you what to achieve, not how. That flexibility is its strength and its trap: with no prescribed control set, teams stall on translating subcategories into concrete evidence, and on keeping the Current Profile current between reviews.

Done in spreadsheets, a profile is accurate for about a week after the workshop. Kept in software built around the profile model, it stays live — and the maturity assessment shows the next prioritised step instead of a static gap list.

NIST CSF alongside your other frameworks

Most organisations don’t run NIST CSF in isolation. In Australia that usually means the Essential Eight and often APRA CPS 234 or ISO 27001 as well. The good news is the evidence overlaps heavily — MFA, logging and access reviews each satisfy a NIST CSF subcategory and controls in the other frameworks at once. Mapping those so one piece of evidence counts everywhere is the point of multi-standard mapping: do the work once, report it against each framework.

NIST CSF 2.0 rewards clarity over box-ticking: decide your Target Profile, measure honestly against it, and keep the score live. Govern makes sure the board knows why — the other five make sure it happens.

Want to see your profile? Explore Cybereen’s NIST CSF support or book a walkthrough.

See your frameworks — and their overlap — on one platform.

Book a walkthrough →