Skip navigation

What is the NIST Cybersecurity Framework?

Cybersecurity risk is hard to manage without a common language. The NIST Cybersecurity Framework gives organizations the structure to assess, prioritize, and act on it.

What is the NIST Cybersecurity Framework

Key takeaways

  • The NIST CSF is voluntary and flexible. Organizations adapt it to their specific risk tolerance, industry, and resources. It is not a checklist to pass but a structure for managing cybersecurity risk over time.

  • CSF 2.0 added a sixth function: Govern. The Govern function elevates cybersecurity governance to a top-level concern, requiring leadership accountability and integration with enterprise risk management.

  • The framework applies to any organization. Originally created for critical infrastructure, CSF 2.0 explicitly serves organizations of all sizes and sectors, including small and medium-sized businesses.

  • Implementation is iterative, not one-time. Organizations assess their current state, define a target, close the gaps, and repeat. The framework is designed for continuous improvement, not a fixed endpoint.

Why was the NIST Cybersecurity Framework created?

In February 2013, Executive Order 13636 directed NIST to develop a voluntary framework for reducing cybersecurity risk to critical infrastructure. It aimed to address fragmentation and inconsistency. Organizations varied in their approaches to cybersecurity and struggled to communicate risk between technical teams and executives.

NIST developed the framework through a collaborative process involving government agencies, private industry, and academic institutions. CSF 1.0 was published in February 2014, with an incremental update (CSF 1.1) following in April 2018. By the time CSF 2.0 arrived in February 2024, the framework was the most widely adopted cybersecurity standard in the United States, and used well beyond its original critical infrastructure audience.

The expansion reflects how the threat landscape has shifted. Remote work, cloud adoption, ransomware, and supply chain attacks have made cybersecurity a universal organizational concern rather than a niche infrastructure problem. Identity security and access management became central to the conversation as compromised credentials emerged as a leading breach vector, and CSF 2.0's emphasis on governance and access controls reflects that shift.

What are the key functions and structures in the NIST cyber framework?

The foundation of the framework is called the CSF core. The CSF core is a taxonomy of cybersecurity outcomes building from six functions into 22 categories and 106 subcategories.

The six functions are the top-level organizational pillars. These pillars operate in a continuous cycle, with each function informing and reinforcing the others.

Function

Primary focus

Key activities

Govern (GV)

Strategy and oversight

Cybersecurity policy, risk management strategy, roles and responsibilities, supply chain risk management

Identify (ID)

Asset and risk awareness

Asset inventory, risk assessment, vulnerability identification, understanding business context

Protect (PR)

Safeguards and controls

Access control, data security, identity management, security awareness training

Detect (DE)

Monitoring and discovery

Continuous monitoring, anomaly detection, security event analysis

Respond (RS)

Incident management

Response planning, communications, analysis, mitigation

Recover (RC)

Restoration and improvement

Recovery planning, restoring capabilities, lessons learned

Govern was added to CSF 2.0 and represents the most significant structural change from previous versions. It sits at the center of the framework, underpinning all five other functions. Govern addresses leadership accountability, cybersecurity strategy, policy development, and supply chain risk management. Its addition reflects the growing consensus that cybersecurity is an enterprise governance responsibility, not just a technical function.

Identify focuses on understanding the organization's cybersecurity risk posture. It reviews what assets exist, who has access to them, what vulnerabilities are present, and how the business context shapes risk priorities. This function provides the inventory and risk assessment that all other functions depend on.

Protect implements security controls. Access control, identity management, multi-factor authentication (MFA), data protection, and security awareness training all fall under this function. For identity security, Protect is the most directly relevant function, covering subcategories for credential management, access enforcement, and least privilege.

Detect addresses monitoring activity and identifying cybersecurity events. This includes watching authentication patterns, flagging anomalous access behavior, and analysis that distinguishes routine activity from potential threats.

Respond covers what happens after a cybersecurity event is detected, including incident response plans, stakeholder communication, scoping the incident, and containment. In identity terms, this includes revoking compromised credentials and blocking malicious access.

Recover gives guidance on restoring capabilities that were impaired during an incident. This includes recovery planning, restoring legitimate user access, updating identity policies based on lessons learned, and communicating recovery status to stakeholders.

Categories subdivide each function into more specific outcome areas (22 total across the framework), and subcategories (106 total) define specific, measurable outcomes that organizations can assess themselves against. NIST also provides informative references that map subcategories to other standards like ISO 27001, CIS controls, and NIST SP 800-53.

What are NIST CSF tiers and profiles?

NIST created tools called tiers and profiles to help security teams manage risk in their organizational contexts and assess their progress. Together, they help organizations understand where they are, decide where they want to be, and plan how to get there.

NIST CSF tiers

Tiers range from 1 to 4 and describe the maturity and sophistication of an organization's cybersecurity risk management. They are not "grades" to pass, but are categories that apply based on business needs, the threat environment, and available resources.

  • Tier 1, Partial
    Cybersecurity risk management is ad hoc and reactive. There is limited awareness of organizational cybersecurity risk and no formalized processes.

  • Tier 2, Risk Informed
    Risk management practices are approved by management but not established as organizational policy. Awareness exists but is not consistently applied across the organization.

  • Tier 3, Repeatable
    Cybersecurity risk management practices are formally approved, expressed as policy, and consistently applied. Practices are regularly updated based on changes in business requirements and the threat landscape.

  • Tier 4, Adaptive
    The organization adapts its cybersecurity practices based on lessons learned and predictive indicators. Continuous improvement and proactive response to evolving threats are standard operating procedures.

NIST CSF profiles

A profile aligns the framework's categories and subcategories to an organization's specific requirements, risk tolerance, and resources. There are two types.

A Current Profile represents the organization's existing cybersecurity posture: which subcategories are addressed, partially addressed, or not addressed. A Target Profile represents the desired state: the cybersecurity outcomes the organization wants to achieve based on its business objectives and risk appetite. The gap between the two profiles becomes the basis for a prioritized improvement plan.

NIST also provides Community Profiles, sector-specific or use-case-specific adaptations developed by NIST and external contributors that organizations can adopt as starting points rather than building from scratch.

What changed in the latest version of the NIST CSF?

CSF 2.0 was released in February 2024, the first major update since the original 2014 publication. It maintains backward compatibility with earlier versions while reflecting a decade of community feedback and an evolving threat landscape.

  • New Govern function
    Governance and risk management strategy are now a top-level function rather than a subcategory of Identify. This elevates leadership accountability and integrates cybersecurity into enterprise risk management.

  • Expanded scope
    The framework is now explicitly designed for all organizations, not just critical infrastructure. NIST changed the title from "Framework for Improving Critical Infrastructure Cybersecurity" to "The NIST Cybersecurity Framework (CSF) 2.0" to reflect this broadened audience. Quick Start Guides for small and medium-sized businesses are included.

  • Reorganized subcategories
    The framework consolidated from 108 subcategories (in CSF 1.1) to 106, merging overlapping outcomes and rewriting subcategory language to focus on measurable results.

  • Stronger supply chain emphasis
    Supply chain risk management receives expanded coverage, recognizing the interconnected nature of modern business and the risks from third-party vendors.

  • Enhanced implementation resources
    NIST now provides Quick Start Guides, Community Profiles, Implementation Examples, and the CPRT Reference Tool for searchable, machine-readable access to every subcategory and cross-framework mapping.

  • Better alignment with other NIST resources
    CSF 2.0 integrates more closely with the NIST Privacy Framework, AI Risk Management Framework, and other NIST security publications.

Organizations currently using CSF 1.1 can transition incrementally. NIST provides crosswalk documents mapping 1.1 subcategories to their 2.0 equivalents.

What are the steps to implementing the NIST framework for cybersecurity?

1. Assess your current cybersecurity state

Create a Current Profile by evaluating existing practices against the framework's six functions.

  • Inventory assets and users (Identify)

  • Review existing controls like MFA and access policies (Protect)

  • Assess monitoring capabilities (Detect)

  • Examine incident response plans (Respond)

  • Check recovery processes (Recover)

  • Review governance structures and policies (Govern)

Document which subcategories are addressed, partially addressed, or missing. Involve stakeholders from IT, security, business units, and leadership, since the framework spans technical and organizational concerns.

2. Choose a Target Profile

The Target Profile defines desired cybersecurity outcomes based on business objectives, regulatory requirements, risk appetite, and available resources. Not every subcategory needs full implementation.

Prioritize based on which systems and data are most critical, which threats are most likely, and which regulatory mandates apply (HIPAA, PCI-DSS, CMMC, or others). The Target Profile should be realistic given current resources and will evolve as the business and threat landscape change.

3. Prioritize and plan improvements

Compare the Current Profile to the Target Profile to identify gaps, then prioritize based on risk reduction, business impact, and feasibility.

Focus on high-impact, achievable improvements first. Build a roadmap with milestones, responsibilities, and timelines. Consider dependencies between improvements and look for quick wins that demonstrate progress and build organizational momentum.

4. Implement the action plan

Deploy new controls, processes, and technologies with clear ownership for each improvement. Start with foundational controls: asset inventory, access management, MFA, and basic monitoring are common early priorities because they address multiple framework categories simultaneously.

Phase major changes through pilots before full deployment. Document everything, since the framework's value depends on being able to demonstrate what has been implemented and how it maps to specific subcategories. Minimize user friction to encourage adoption.

5. Monitor and refine regularly

Review the Current Profile periodically (quarterly or annually) to verify it accurately reflects the organization's posture. Update the Target Profile as threats, technologies, and business needs evolve.

Track metrics like time to detect incidents, percentage of users with MFA enabled, and number of unpatched vulnerabilities. Feed lessons learned from incidents back into the framework implementation. Communicate progress to leadership regularly, since the govern function requires ongoing executive visibility into cybersecurity status.

Security professional reviewing a cybersecurity risk management dashboard, representing the structured approach of the NIST Cybersecurity Framework

How can organizations map the NIST Cybersecurity Framework to other standards?

One of the framework's strengths is its compatibility with other cybersecurity standards. NIST provides Informative References, official mappings that show how framework subcategories align with other standards and NIST protocols, so organizations can use a single NIST CSF implementation to demonstrate compliance with multiple requirements simultaneously.

  • ISO 27001/27002
    The international standard for information security management systems has significant overlap with NIST CSF categories, particularly in the Protect function.

  • CIS Controls
    The Center for Internet Security's prioritized actions for cyber defense map directly to many NIST subcategories and provide specific implementation guidance.

  • NIST SP 800-53
    The comprehensive catalog of security and privacy controls for federal systems provides detailed implementation guidance for NIST CSF subcategories. This is where organizations go for prescriptive control-level detail.

  • PCI-DSS
    Payment Card Industry requirements for protecting payment card data align with multiple NIST categories.

  • HIPAA security rule
    Healthcare privacy and security regulations map to NIST categories, and NIST provides specific crosswalk documentation for healthcare organizations.

  • GDPR
    The EU's General Data Protection Regulation maps to several NIST categories, particularly around data protection and incident response.

  • CMMC
    The Cybersecurity Maturity Model Certification for defense contractors is built on NIST SP 800-171, which aligns closely with the CSF.

  • SOC 2
    Trust service criteria for service organizations map to NIST categories, allowing organizations to address both frameworks with a unified control set.

These maps can help companies quickly identify their tier and target profiles. For example, standards like PCI-DSS, HIPAA, and CMMC translate specific regulatory requirements into framework subcategories, identifying risk management practices and outcomes. The NIST framework controls, then provides the structure for prioritizing improvements and closing the gaps between current state and target state.

How do MFA and IAM fit into the NIST security approach?

Identity and access management (IAM) is fundamental to implementing the NIST CSF because it touches every function in the framework.

The Protect function addresses IAM most directly. Subcategory PR.AA-01 covers identity and credential management, PR.AA-03 covers authentication, and PR.AA-05 covers access permissions and authorizations.

Multi-factor authentication, which requires two or more verification factors (something the user knows, has, or is), directly supports these subcategories. Phishing-resistant MFA methods like FIDO2 security keys or passkeys are particularly effective because they resist the credential theft that drives the majority of identity-based attacks.

But IAM extends well beyond Protect.

  • The Govern function relies on IAM policies to define who can access what resources under what conditions.

  • Identify user and device inventory to map all identities with access to organizational resources.

  • Detect depends on continuous monitoring of authentication patterns and access behavior to flag anomalies.

  • Respond includes the ability to revoke compromised credentials and escalate authentication requirements when threats are detected.

  • Recover involves restoring legitimate access after incidents while preventing re-compromise.

Adaptive authentication, which adjusts security requirements based on context like device health, location, and behavioral signals, supports risk-based decisions across multiple functions simultaneously. This is why IAM platforms are often among the first investments organizations make when implementing the NIST framework: a single platform can address subcategories across Govern, Protect, Detect, and Respond.

How can identity security strengthen a NIST cyber framework implementation?

The NIST framework describes what organizations should achieve. Identity security platforms provide the tools to achieve it across multiple functions with a single integrated approach.

Phishing-resistant MFA directly supports Protect by preventing unauthorized access to the authentication layer. It also supports Detect by surfacing suspicious authentication attempts that indicate compromised credentials or targeted attacks.

Device trust verifies that devices meet security standards before granting access, supporting both Protect (endpoint security) and Identify (device inventory and health visibility).

Adaptive access policies enable risk-based decisions that adjust authentication requirements based on context, supporting Protect and Respond by tightening access when risk signals are elevated.

Single sign-on (SSO) centralizes authentication and access control across applications, supporting Protect (consistent access enforcement) and Govern (unified policy management).

Continuous monitoring provides visibility into authentication patterns, anomalous behavior, and permission drift, supporting Detect and enabling the metrics and reporting that the Govern function requires for executive oversight.

Implementation friction is one of the most common barriers to framework adoption. Organizations that quickly deploy strong, user-friendly identity controls begin addressing multiple NIST categories from day one rather than spending months on infrastructure changes.

See for yourself how Duo's IAM platform with phishing-resistant MFA can strengthen your organization's security with a free 30-day trial.

Frequently asked questions about the NIST Cybersecurity Framework

Common questions about the NIST Cybersecurity Framework, from mandatory requirements to cloud security coverage.

  • Is the NIST Cybersecurity Framework mandatory for all organizations?

    The framework is voluntary for most organizations. Some federal agencies and government contractors face mandatory requirements through FISMA or CMMC, but most organizations adopt the NIST CSF voluntarily because it provides valuable structure for managing cybersecurity risk and helps satisfy multiple compliance obligations simultaneously.

  • How long does it typically take to implement the NIST CSF?
  • Can small and medium-sized businesses use the NIST Cybersecurity Framework effectively?
  • What resources are available to help map existing security controls to NIST categories?
  • Does implementing the NIST framework guarantee protection from cyber attacks?
  • How does the NIST Cybersecurity Framework address cloud security?

Want to learn more about access and identity security?

Discover more 'what-is' content and learning resources, including ebooks, guides and webinars, crafted to help you enhance your organization’s access security strategy.