NIST Cybersecurity Framework 2.0
A voluntary framework for organising a security programme around outcomes, widely used as a common language between technical teams and boards.
NUEXUS delivers readiness, gap assessment, implementation support and evidence preparation. NUEXUS is not an accredited certification body and not an auditor, and cannot certify you, issue an attestation, or sign off on a result.
How it is organised
Six functions, and the newest one is the important one
CSF 2.0 organises outcomes under Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in version 2.0 and is the change that matters: it puts roles, policy, risk appetite and supply chain oversight at the centre rather than treating governance as paperwork around the technical work.
It describes outcomes, not implementations
The framework says what should be true, not which product to buy. That is why it maps cleanly onto other standards and why it survives technology changes, and also why it is not by itself an audit standard.
Profiles are how it becomes useful
The practical use is a current profile and a target profile: where you are, where you intend to be, and therefore what the gap and the roadmap are. A CSF assessment that produces only a score has skipped the part that creates value.
What an assessor will ask to see
- A current profile grounded in evidence rather than in self-assessment optimism
- A target profile agreed with the business, not set by the security team alone
- A prioritised gap list with owners and dates
- Traceability from CSF outcomes to the controls you actually operate
Where it usually goes wrong
- Scoring the organisation against the framework without evidence behind the scores
- Treating Govern as documentation rather than as decision rights
- A target profile set at maximum everywhere, which is neither affordable nor honest
- No re-assessment, so the profile describes the organisation as it was
