NIST CSF 2.0, including the part everyone skips.
All six functions and 106 subcategories — with Govern, the function 2.0 added and most teams have not operationalised.
2.0 made governance a function
The Cybersecurity Framework has always been the most approachable way to structure a security program: not a certification, not an audit, just a common language for what you do and how well you do it.
Version 2.0 added a sixth function, Govern, and it is the largest one — 31 of the 106 subcategories. It covers organisational context, risk management strategy, roles, policy, oversight and supply chain. It is also the function most teams have not genuinely implemented, because it is the least technical.
OpenGRC includes NIST CSF 2.0 and the 1.1 legacy bundle on every plan.
A framework you can actually show progress against.
Maturity, not just presence
CSF is about how well you do something, not whether a control exists. Implementations carry maturity and test procedures, and control effectiveness is derived from your most recent completed audit rather than asserted.
Govern, operationalised
The 31 Govern subcategories map to things OpenGRC already holds: policies with approval workflows, risk strategy, roles and ownership, and vendor risk for the supply chain subcategories.
A dashboard that means something
Role-aware dashboards and custom widgets let you show function-level progress to a board without rebuilding a slide deck every quarter.
The six functions
| Function | Subcategories |
|---|---|
| GV Govern — context, strategy, roles, policy, oversight, supply chain | 31 |
| ID Identify — assets, risk assessment, improvement | 21 |
| PR Protect — identity, access, awareness, data, platform, resilience | 22 |
| DE Detect — continuous monitoring, adverse event analysis | 11 |
| RS Respond — incident management, analysis, reporting, mitigation | 13 |
| RC Recover — recovery execution and communication | 8 |
NIST CSF questions
Is NIST CSF a certification?
No. There is no CSF certificate. It is a voluntary framework for organising and communicating a security program, which is part of why it works so well as a starting point or as the backbone you map other frameworks onto.
™