An official website of the United States government
Here’s how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
https://www.nist.gov/cyberframework
Cybersecurity Framework
Helping organizations to better understand and improve their management of cybersecurity risk
CSF 2.0
For industry, government, and organizations to reduce cybersecurity risks
CSF 2.0 Webinar Series: Implementing CSF 2.0—The Why, What, and How
Latest Updates
Seeking comment through September 11, 2025: The NIST Interagency Report (NIST IR) 8374 Revision 1, Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile reflects changes made to the Cybersecurity Framework (CSF) from CSF 1.1 to CSF 2.0 which identifies security objectives that support managing, detecting, responding to, and recovering from ransomware events that organizations of various sizes and sectors at home and abroad use. The project team is interested in gathering additional comments and feedback prior to publishing the final version. Please send your feedback about this draft publication to ransomware [at] nist.gov (ransomware[at]nist[dot]gov).
On July 25, 2025, NIST launched the CSF 2.0 Resources page to list publicly available resources submitted by the CSF 2.0 user community. Resource topics include educational materials, examples of use, tools, and informative references. Visit the CSF 2.0 Resources page to learn more about evaluation criteria and how you can submit a resource.