NIST CSF 2.0, including the part everyone skips.

All six functions and 106 subcategories — with Govern, the function 2.0 added and most teams have not operationalised.

2.0 made governance a function

The Cybersecurity Framework has always been the most approachable way to structure a security program: not a certification, not an audit, just a common language for what you do and how well you do it.

Version 2.0 added a sixth function, Govern, and it is the largest one — 31 of the 106 subcategories. It covers organisational context, risk management strategy, roles, policy, oversight and supply chain. It is also the function most teams have not genuinely implemented, because it is the least technical.

OpenGRC includes NIST CSF 2.0 and the 1.1 legacy bundle on every plan.

Built for maturity

A framework you can actually show progress against.

Maturity, not just presence

Maturity, not just presence

CSF is about how well you do something, not whether a control exists. Implementations carry maturity and test procedures, and control effectiveness is derived from your most recent completed audit rather than asserted.

Govern, operationalised

Govern, operationalised

The 31 Govern subcategories map to things OpenGRC already holds: policies with approval workflows, risk strategy, roles and ownership, and vendor risk for the supply chain subcategories.

A dashboard that means something

A dashboard that means something

Role-aware dashboards and custom widgets let you show function-level progress to a board without rebuilding a slide deck every quarter.

The six functions

FunctionSubcategories
GV Govern — context, strategy, roles, policy, oversight, supply chain31
ID Identify — assets, risk assessment, improvement21
PR Protect — identity, access, awareness, data, platform, resilience22
DE Detect — continuous monitoring, adverse event analysis11
RS Respond — incident management, analysis, reporting, mitigation13
RC Recover — recovery execution and communication8

NIST CSF questions

Is NIST CSF a certification?

No. There is no CSF certificate. It is a voluntary framework for organising and communicating a security program, which is part of why it works so well as a starting point or as the backbone you map other frameworks onto.

2.0 or 1.1?

Can we map CSF to our other frameworks?

How do we show progress?