Skip to main content
FRAMEWORK

Map your CSF 2.0 profile — including the new Govern function.

CSF 2.0 is the version that finally says the quiet part out loud. The 2024 revision added Govern to the five functions everyone already knew — Identify, Protect, Detect, Respond, Recover — and put it first, because the other five fail for governance reasons far more often than technical ones. The framework is voluntary and there is nothing to pass; what it gives you is a vocabulary the rest of your obligations can be expressed in.

That vocabulary is the reason CSF is worth operating rather than reading. Subcategories are where your controls actually live, and the same control that satisfies a CSF subcategory is the one an ISO auditor samples and a NIS2 supervisor asks about. Mapped once, it answers in every dialect. Mapped per framework, it drifts.

Who it applies to

Anyone who wants it. CSF 2.0 dropped the critical-infrastructure framing that scoped version 1.1 and is written for organizations of any size and sector. In practice it rarely arrives as a decision — it arrives inside a customer security questionnaire, an insurer's renewal form, or a parent company's reporting template, phrased as though everyone already has a profile.

Profiles and Tiers, not a pass mark

CSF has no certificate and no score. It has Profiles — a Current Profile describing what you actually do, a Target Profile describing what you intend to do, and the distance between them as your plan. Tiers sit alongside, describing how rigorous and repeatable your risk governance is rather than how many controls you hold. The honest version of this is uncomfortable to assemble by hand, because a Current Profile written from memory is aspirational by default. Derived from live control state, it is simply a readout.

What it asks, in operating terms

Read as an operating requirement rather than a reference document, the six functions reduce to six standing questions — each answerable from the same control library the other frameworks read.

CSF 2.0 functions · how TruSecure answers them
What the function asksWhere it is answered
Govern — strategy, roles and policy, actually overseenGovernance workspace · policy, named owners, review dates
Identify — know the assets, suppliers and risks you holdAsset and supplier register · one record every regime reads
Protect — safeguards in place and evidencedControl library · continuously monitored, evidence attached
Detect — find the events that matterMonitoring · findings routed to a named owner
Respond — act, with the clock runningIncident workflow · clocked, sealed record
Recover — restore, and learn from itContinuity and post-incident review · actions tracked to closure

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a profile is made of:

CSF 2.0 profile · excerptSample data
Functions covered
6/6 · Govern included
Subcategories mapped
to shared controls · not a separate set
Current vs Target
gap shown per function
Evidence freshness
continuous · provenance tracked
Export
sealed · sha256:6c1b...84af

Where teams usually start

With a demo walked through by TruSecure — your Current Profile derived from controls you already operate, the Govern function opened to a single subcategory, the gap to a Target Profile you choose. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIST CSF 2.0 organizes cybersecurity activity into six functions — Govern, Identify, Protect, Detect, Respond, and Recover — with Govern newly added to emphasize organizational oversight. TruSecure maps CSF functions directly to the same control library used for every other framework.