a NIST blog
Celebrate this milestone with us!
Email us at csf [at] nist.gov or tag @NISTcyber on X telling us what your favorite CSF 2.0 resource is (or how your organization has benefitted from implementing the CSF 2.0).
Today marks two years since the publication of the Cybersecurity Framework (CSF) 2.0!
Published in 2024, the CSF 2.0 included the addition of a Govern Function, increased emphasis on cybersecurity supply chain risk management, updated categories and subcategories to address current threat and technology shifts, and expansion into a suite of resources designed to make the CSF 2.0 easier to consume and put into practice—enabling organizations to better manage and reduce their cybersecurity risk.
The CSF 2.0 has been widely embraced by millions of organizations of all sizes and sectors around the globe and continues to be the most downloaded NIST technical publication (with over 3 million views and downloads, to date). The team has been hard at work the last two years engaging with thousands of stakeholders and continuing to produce practical, actionable resources. Last year, we published a blog highlighting accomplishments from the CSF 2.0’s first year. Below are some highlights from this past year.
Elevating Cybersecurity as a Strategic Business Decision
We expanded the focus on cybersecurity governance to highlight the importance of ensuring cybersecurity capabilities support the broader mission through Enterprise Risk Management (ERM). The NIST IR 8286 series, which was updated in 2025 to align more closely with the CSF 2.0 and other updated NIST guidance, helps practitioners better understand the close relationship between cybersecurity and ERM.
Streamlining Working with Multiple Frameworks and Guidelines
Informative References highlight connections between the CSF and other frameworks, standards, and guidelines. There were seven new CSF 2.0 informative references published in the last calendar year:
Get involved: The NIST Online Informative Reference (OLIR) Program encourages subject matter experts to review and contribute to the OLIR portfolio. If you would like to participate, please consult NISTIR 8278A Rev. 1 National Online Informative References (OLIR) Program: Submission Guidance for OLIR Developers.
Using the CSF 2.0 to Address Community Cybersecurity Risk Management
A Community Profile is a baseline of CSF outcomes that is created and published to address shared interests and goals among several organizations. Several draft community profiles were added to the CSF 2.0 Resource Center this past year for public comment:
|
|
Get Involved: The NIST National Cybersecurity Center of Excellence (NCCoE) plays a significant role in helping communities implement NIST Frameworks. The NCCoE’s Resources for Applying NIST Frameworks page serves as a repository of information and tools for creating Community Profiles. We also welcome your feedback on Community Profiles when they are out for public comment.
Getting Started with CSF 2.0
If you haven’t migrated your cybersecurity risk management strategy to the CSF 2.0, there’s no time like the present. Where can you start?