Map your CSF 2.0 profile — including the new Govern function.
CSF 2.0 is the version that finally says the quiet part out loud. The 2024 revision added Govern to the five functions everyone already knew — Identify, Protect, Detect, Respond, Recover — and put it first, because the other five fail for governance reasons far more often than technical ones. The framework is voluntary and there is nothing to pass; what it gives you is a vocabulary the rest of your obligations can be expressed in.
That vocabulary is the reason CSF is worth operating rather than reading. Subcategories are where your controls actually live, and the same control that satisfies a CSF subcategory is the one an ISO auditor samples and a NIS2 supervisor asks about. Mapped once, it answers in every dialect. Mapped per framework, it drifts.
Who it applies to
Anyone who wants it. CSF 2.0 dropped the critical-infrastructure framing that scoped version 1.1 and is written for organizations of any size and sector. In practice it rarely arrives as a decision — it arrives inside a customer security questionnaire, an insurer's renewal form, or a parent company's reporting template, phrased as though everyone already has a profile.
Profiles and Tiers, not a pass mark
CSF has no certificate and no score. It has Profiles — a Current Profile describing what you actually do, a Target Profile describing what you intend to do, and the distance between them as your plan. Tiers sit alongside, describing how rigorous and repeatable your risk governance is rather than how many controls you hold. The honest version of this is uncomfortable to assemble by hand, because a Current Profile written from memory is aspirational by default. Derived from live control state, it is simply a readout.
What it asks, in operating terms
Read as an operating requirement rather than a reference document, the six functions reduce to six standing questions — each answerable from the same control library the other frameworks read.
| What the function asks | Where it is answered |
|---|---|
| Govern — strategy, roles and policy, actually overseen | Governance workspace · policy, named owners, review dates |
| Identify — know the assets, suppliers and risks you hold | Asset and supplier register · one record every regime reads |
| Protect — safeguards in place and evidenced | Control library · continuously monitored, evidence attached |
| Detect — find the events that matter | Monitoring · findings routed to a named owner |
| Respond — act, with the clock running | Incident workflow · clocked, sealed record |
| Recover — restore, and learn from it | Continuity and post-incident review · actions tracked to closure |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a profile is made of:
- Functions covered
- 6/6 · Govern included
- Subcategories mapped
- to shared controls · not a separate set
- Current vs Target
- gap shown per function
- Evidence freshness
- continuous · provenance tracked
- Export
- sealed · sha256:6c1b...84af
Where teams usually start
With a demo walked through by TruSecure — your Current Profile derived from controls you already operate, the Govern function opened to a single subcategory, the gap to a Target Profile you choose. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIST CSF 2.0 organizes cybersecurity activity into six functions — Govern, Identify, Protect, Detect, Respond, and Recover — with Govern newly added to emphasize organizational oversight. TruSecure maps CSF functions directly to the same control library used for every other framework.