NIST Cybersecurity Framework 2.0

The NIST CSF 2.0 Software That Drives the Framework's Six Functions

Structure Govern, Identify, Protect, Detect, Respond and Recover, and map them onto the frameworks you already run.

Discover the platform

What NIST CSF 2.0 brings

The NIST Cybersecurity Framework 2.0, published in February 2024, is a voluntary framework for organising cybersecurity, not a certifiable standard. Version 2.0 introduces a sixth function, Govern, alongside Identify, Protect, Detect, Respond and Recover, and it explicitly widens the scope beyond critical infrastructure to organisations of any size. The framework is organised into functions, categories and subcategories, and is completed by profiles describing the current and the target state. That structure is what makes it a shared language between technical teams and the board.

What a NIST CSF tool has to allow

Because the CSF carries no certification, its practical value lies in measurement: where you stand on each subcategory, where you want to be, and what gap that represents. A useful tool therefore holds the current profile, the target profile, the gap and the plan connecting them. It also has to map CSF subcategories onto the controls you already run, ISO 27001 and NIST SP 800-53 in particular, or you end up maintaining two parallel frameworks describing the same measures.

Why Vailor to run the NIST CSF

Vailor automatically maps CSF 2.0 subcategories onto the ISO 27001 controls and risk assessments you have already produced, so measurement lands on the real gap rather than on re-entry. Agentic AI documents the gaps and prepares the steering deliverables, with every output explainable and traceable. For a European organisation using the CSF as an organising frame while answering to NIS2 or DORA, the point is to hold all three readings on one data layer.

What Vailor's NIST CSF software covers

The framework's six functions

Govern, Identify, Protect, Detect, Respond and Recover, structured into categories and subcategories.

Current and target profiles

Measure where you stand, define where you are going, and track the gap between the two.

Cross-framework mapping

CSF subcategories mapped onto your ISO 27001 controls and your EBIOS RM assessments.

Hosted in France and the EU

Your posture data stays sovereign, hosted in France and the European Union.

What a dedicated NIST CSF tool gives you

Drive all six CSF 2.0 functions, Govern included
Measure the gap between your current and your target profile
Map the CSF onto your ISO 27001 controls without double entry
Give the board a legible reading of your posture
Reuse the same foundation for NIS2 and DORA
Keep your posture data in France and the EU

Frequently asked questions about NIST CSF 2.0

Do you have to start over when moving from CSF 1.1 to 2.0?

No. The five original functions stay in place, so most of the work already done on Identify, Protect, Detect, Respond and Recover carries over. The changes to handle are specific: the new Govern function, which takes in the governance and supplier risk outcomes previously attached to Identify, and the renumbering of some categories and subcategories. The sensible route is to map your existing assessment onto the 2.0 subcategories, then reassess only the ones that genuinely moved.

What is the difference between the NIST CSF and ISO 27001?

ISO/IEC 27001 is a certifiable standard: it requires an information security management system, with a defined scope, a policy, management review and an audit by an accredited certification body. The NIST CSF describes expected security outcomes, organised into functions and subcategories, without imposing a management system and without granting any certificate. The two combine well: the CSF gives you a reading and communication grid, ISO 27001 gives you the proof a customer or an insurer will accept.

What does the Govern function actually cover?

Govern deals with what frames security rather than what implements it: organisational context, risk management strategy, roles and responsibilities, policy, oversight of results, and cybersecurity supply chain risk management. It is the function that ties security to business priorities and names who decides, who arbitrates and who answers for the outcome. It is also the hardest one to hold in a spreadsheet, because its outputs are decisions and trade-offs rather than ticked boxes.

What are the NIST CSF Tiers for?

The Tiers, from Partial to Adaptive, describe how rigorously an organisation governs and manages its cyber risk: how formalised the practices are, how third-party risk is taken into account, how far security is integrated into wider decisions. They are neither a per-control maturity score nor a target to push to the maximum: the Tier you aim for follows your context, your obligations and your means. Read them alongside profiles, not instead of them: the profile says where you stand subcategory by subcategory, the Tier says how you steer the whole.

Is the NIST CSF enough to comply with NIS2 or DORA?

No. NIS2 and DORA set their own legal obligations: risk management measures, incident reporting, oversight of third-party providers, accountability for management bodies. The CSF is not a compliance framework recognised by those texts, and no profile creates a presumption of conformity. It still works as a backbone: structuring your measures across the six functions, then mapping each subcategory onto the applicable requirements, lets you handle the shared ground once and isolate what belongs to each text.

Can you run the NIST CSF in a spreadsheet?

To get started, yes. The limit arrives quickly: every subcategory carries a current state, a target state, a rationale, evidence, an owner and a due date, and you need the history to show a trajectory. Add the mapping onto ISO 27001 or SP 800-53 and you are maintaining a matrix by hand every time a control changes. A spreadsheet does not record who changed what, does not tie a subcategory to dated evidence, and cannot replay the gap after a reorganisation.

How do you prove your CSF posture without certification?

Through documentation rather than a certificate: a dated current profile backed by evidence attached to each subcategory, an owned target profile, and a tracked action plan. An independent third-party assessment remains possible, but it does not commit NIST and produces no official label. If the person asking wants proof they can rely on contractually, an ISO 27001 certificate or an audit report is what you hand over, with the CSF profile used to explain the trajectory.

See Vailor's NIST CSF software in action

Book a demo and watch your current profile build itself from your own data.