NIST Cybersecurity Framework 2.0: What It Means for Your Organization
The NIST Cybersecurity Framework (CSF) 2.0 is free, voluntary guidance from the National Institute of Standards and Technology for managing cybersecurity risk. It organizes security outcomes into six Functions: Govern, Identify, Protect, Detect, Respond and Recover. It does not tell you which tools to buy or which steps to take. Instead, it gives you a common language for where you are, where you want to be and what to do next. NIST designed it for organizations of every size, and it publishes quick start guides for small businesses. In Texas, the NIST framework is one of the frameworks the SB 2610 cybersecurity safe harbor names. ALCON DTS can help you build a profile, close the gaps and run the controls.
This page answers:
At a glance
- Framework: The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, published February 26, 2024
- Published by: the National Institute of Standards and Technology (NIST), U.S. Department of Commerce
- Structure: 6 Functions (Govern, Identify, Protect, Detect, Respond, Recover), 22 Categories and 106 Subcategories in the CSF Core, plus Organizational Profiles (Current and Target), four Tiers, and supporting online resources such as Community Profiles
- Who it is for: “organizations of all sizes and sectors,” including industry, government, academia and nonprofits
- Required? Voluntary for most organizations. NIST says it “is not a regulatory agency, and most organizations use the CSF on a voluntary basis.”
- Certification: none. NIST “does not offer certifications or endorsements of CSF-related products, implementations, or services.”
- Texas connection: the NIST framework is listed in the SB 2610 safe harbor (Texas Business and Commerce Code Sec. 542.004(b)(1)(A))
- Official text: NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0
- Last reviewed: September 30, 2026
What is the NIST Cybersecurity Framework 2.0?
NIST describes CSF 2.0 as guidance “to manage cybersecurity risks” that offers “a taxonomy of high-level cybersecurity outcomes that can be used by any organization,” whatever its size, sector or maturity. The key point is in the next sentence: “The CSF does not prescribe how outcomes should be achieved.” It tells you what good looks like and leaves the how to you.
Before version 2.0, the framework had a different name. In NIST’s words: “Before version 2.0, the Cybersecurity Framework was called the ‘Framework for Improving Critical Infrastructure Cybersecurity.’ This title is not used for CSF 2.0.”
The CSF has three main parts:
- The CSF Core, “a taxonomy of high-level cybersecurity outcomes,” organized as Functions, Categories and Subcategories.
- Organizational Profiles, which describe “an organization’s current and/or target cybersecurity posture in terms of the CSF Core’s outcomes.”
- Tiers, which “characterize the rigor of an organization’s cybersecurity risk governance and management practices.”
NIST adds online resources around the framework: Informative References that map outcomes to other standards, Implementation Examples, Quick Start Guides and Community Profiles.
The six Functions
| Function | NIST’s definition | What it covers (from CSF 2.0) |
|---|---|---|
| Govern (GV) | “The organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.” | Organizational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management |
| Identify (ID) | “The organization’s current cybersecurity risks are understood.” | Asset management, risk assessment and improvement |
| Protect (PR) | “Safeguards to manage the organization’s cybersecurity risks are used.” | Identity management, authentication and access control; awareness and training; data security; platform security; technology infrastructure resilience |
| Detect (DE) | “Possible cybersecurity attacks and compromises are found and analyzed.” | Continuous monitoring and adverse event analysis |
| Respond (RS) | “Actions regarding a detected cybersecurity incident are taken.” | Incident management, analysis, reporting and communication, and mitigation |
| Recover (RC) | “Assets and operations affected by a cybersecurity incident are restored.” | Incident recovery plan execution and recovery communication |
Govern is new in 2.0. NIST places Govern “in the center of the wheel because it informs how an organization will implement the other five Functions.” It covers who is responsible, what your policy says, how cybersecurity fits with your other business risks and how you manage suppliers. NIST also says the Functions “should be addressed concurrently,” not one after another.
What does the CSF cover, and what doesn’t it?
It covers: cybersecurity risk across all the technology you use. NIST says the Core applies to “all ICT used by an organization,” including IT, the Internet of Things and operational technology, and to cloud, mobile and artificial intelligence systems.
It is not:
- A checklist. NIST says the CSF “does not specify actions” for meeting its outcomes. Implementation Examples are “not a comprehensive list of all actions” and do not represent “a baseline of required actions.”
- A certification. NIST does not certify organizations against the CSF, and there are “no plans to develop a conformity assessment program.”
- A law. NIST is not a regulator. Some customers and contracts do require the CSF, and Executive Order 13800 made it mandatory for U.S. federal agencies.
- One size fits all. In NIST’s words, “the CSF does not embrace a one-size-fits-all approach.”
Does the NIST Cybersecurity Framework apply to you?
For most private organizations, using the CSF is a choice. NIST says “most organizations use the CSF on a voluntary basis,” and it notes that “some companies require the CSF for their customers or within their supply chain.” The CSF is a good fit in these situations:
- You want the Texas SB 2610 safe harbor. The NIST framework is one of the industry-recognized frameworks a qualifying program can conform to (Sec. 542.004(b)(1)(A)). For businesses with at least 100 but fewer than 250 employees, the statute calls for “compliance with the requirements of Subsection (b),” the framework list (Sec. 542.004(a)(4)(C)).
- You need to explain security to leadership, a board or customers. The CSF is designed to provide “a common language for communicating inside and outside the organization about cybersecurity risks.”
- You answer to several rules at once. The CSF’s outcomes are mapped to other standards and regulations, which helps you organize one program for several needs.
Quick check: does this apply to you?
- You want a recognized way to describe your security program to leadership, customers, insurers or your attorney.
- Or you are a Texas business entity with fewer than 250 employees that owns or licenses computerized data that includes sensitive personal information (Sec. 542.002) and you are building a program for the SB 2610 safe harbor.
If either is true, the CSF is very likely a good fit for you. Whether your program qualifies for the SB 2610 safe harbor is a legal question decided on the facts. Confirm with your attorney.
What do you need to have in place?
The CSF does not require a fixed set of controls. NIST describes working through an Organizational Profile as one way to improve. The table below follows the five steps NIST describes in CSWP 29, Section 3.1.
| Step (CSF 2.0) | What NIST describes | Smaller organization | Larger or more complex organization |
|---|---|---|---|
| 1. Scope the Profile | Document the facts and assumptions the Profile is based on. A Profile can cover the whole organization or one part of it | One Profile for the whole business | Several Profiles, for example one per business unit or for a specific threat such as ransomware |
| 2. Gather information | Policies, risk priorities, requirements you follow, practices and tools, and work roles | A short list of systems, vendors and legal and contract requirements | Business impact analyses, risk registers and departmental inputs |
| 3. Create the Profile | Document the Current Profile (what you achieve today) and the Target Profile (what you want to achieve) | Use the Small Business Quick Start Guide actions as a first target | Consider a Community Profile as the basis for the Target Profile |
| 4. Analyze gaps and plan | Compare Current and Target Profiles and create a prioritized action plan, such as a risk register or plan of action and milestones | A short, ranked list of fixes | A tracked plan with owners and target dates |
| 5. Implement and update | Follow the action plan and update the Profile | Review on a regular cycle and after any major change | Build reviews into planning for new systems and operations |
What are the CSF Tiers?
Tiers describe how rigorous your cybersecurity risk governance and management are. NIST names four:
| Tier | Name | Short description (from CSF 2.0, Appendix B, Table 2, “Notional Illustration of the CSF Tiers”) |
|---|---|---|
| 1 | Partial | Strategy is managed “in an ad hoc manner,” and there is “limited awareness of cybersecurity risks at the organizational level” |
| 2 | Risk Informed | Practices are “approved by management but may not be established as organization-wide policy” |
| 3 | Repeatable | Practices are “formally approved and expressed as policy,” and there is “an organization-wide approach to managing cybersecurity risks” |
| 4 | Adaptive | The organization “adapts its cybersecurity practices based on previous and current cybersecurity activities, including lessons learned and predictive indicators” |
You do not have to aim for Tier 4. NIST says “Progression to higher Tiers is encouraged when risks or mandates are greater or when a cost-benefit analysis indicates a feasible and cost-effective reduction of negative cybersecurity risks.” Tiers “should complement an organization’s cybersecurity risk management methodology rather than replace it.”
Where should a small business start?
NIST publishes a Small Business Quick-Start Guide (NIST SP 1300, February 2024) for “small-to-medium sized businesses (SMB), specifically those who have modest or no cybersecurity plans in place.” It lists actions for each Function. Examples include:
- Govern: understand your legal, regulatory and contractual cybersecurity requirements, and assess the risks posed by suppliers before entering into formal relationships.
- Identify: create and maintain an inventory of hardware, software, systems and services.
- Protect: require multifactor authentication on all accounts that offer it, change default manufacturer passwords, update and patch software, back up data and test backups, and enable full-disk encryption on laptops and tablets.
- Detect: understand the common indicators of an incident, and engage a service provider to monitor computers and networks if you do not have the resources to do it internally.
- Respond: understand your incident response plan and who has authority to carry it out.
- Recover: understand who has recovery responsibilities, and check the integrity of backed up data before you restore from it.
The guide also says that if there are activities “that you do not understand or do not feel comfortable addressing yourself, this guide can serve as a discussion prompt with whomever you have chosen to help you reduce your cybersecurity risks.” NIST offers other quick start guides as well, including guides on Organizational Profiles, Community Profiles, Tiers, supply chain risk and enterprise risk management.
How can ALCON DTS help you?
You keep the compliance decisions. We run the controls. You set your risk appetite and choose your Target Profile. ALCON DTS can help you build your Current Profile, turn the gaps into a work plan, run the safeguards on the systems we manage and keep the evidence in one place.
| CSF Function | What ALCON DTS provides |
|---|---|
| Govern | Compliance tracking against your chosen framework, with documented policies, procedures and an organized evidence file; regular, documented program reviews against the current framework version |
| Identify | Device management and automated documentation of systems and configurations; a review of identity and access, email, devices, backups and vendor access |
| Protect | Identity and access with multifactor authentication and tight administrator rights; email security and domain authentication; devices kept updated, protected and encrypted; security awareness training with completion records; managed firewalls, switching and secure wireless networks |
| Detect | Centralized logging and security monitoring, with alerts routed to a named owner who can act |
| Respond | When an alert fires, ALCON DTS opens a ticket, contacts your named owner and works the issue with you until it is back under control. |
| Recover | Tested backup and recovery, so you know what is backed up and who can restore |
The exact controls in your environment depend on your ALCON DTS plan and any project work, and we will show you which are in place today and which would close a gap. Using the CSF does not make your organization certified, and ALCON DTS does not certify organizations against it.
Want to see your Current Profile? We will map what you have today to the six CSF Functions and show you the gaps that matter most.
How does the NIST Cybersecurity Framework fit with other rules?
- Texas Cybersecurity Safe Harbor (SB 2610, Bus. and Com. Code Ch. 542). The statute lists “the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST)” among the frameworks a program can conform to, using “a current version” of it (Sec. 542.004(b)(1)(A)). That is the framework’s name before version 2.0. NIST published CSF 2.0 on February 26, 2024. When a listed framework is updated, a program keeps qualifying if it is updated by the later of the implementation date in the updated standard or one year after the update is published (Sec. 542.004(c)). CSF 2.0 does not state a separate implementation date, and one year after its publication was February 26, 2025, so a program still built on CSF 1.1 may not be conforming to a current version. Ask your attorney how this applies to your program. See Texas SB 2610 Cybersecurity Safe Harbor.
- HIPAA Security Rule. If you are a HIPAA covered entity or business associate, HIPAA’s requirements still apply, including the security risk analysis in 45 CFR 164.308(a)(1)(ii)(A). NIST SP 800-66 Rev. 2 (February 2024) is NIST’s resource guide for the Security Rule. It maps the Security Rule’s standards and implementation specifications to Cybersecurity Framework Subcategories and SP 800-53 Rev. 5 controls, with the mapping kept in NIST’s Cybersecurity and Privacy Reference Tool. That published mapping uses CSF version 1.1 Subcategories. NIST said it would update the mapping for CSF 2.0. The CSF can help you organize the program. It does not replace HIPAA. SB 2610 also expects your program to conform to HIPAA if you are subject to it (Sec. 542.004(b)(2)(A)).
- CIS Critical Security Controls. CIS Controls v8.1 realigned its mappings to NIST CSF 2.0, including the Govern function. The CIS Controls can supply specific actions for many CSF outcomes. For Texas businesses with at least 20 but fewer than 100 employees, SB 2610 names CIS Controls Implementation Group 1 (Sec. 542.004(a)(4)(B)).
- Texas duty to protect sensitive personal information (Bus. and Com. Code Sec. 521.052). A CSF-based program is one practical way to show the “reasonable procedures” Texas requires. It does not change your breach notification duties under Sec. 521.053.
- NIST Privacy Framework. NIST notes that the Privacy Framework and the CSF can be used together to address cybersecurity and privacy risks.
Frequently asked questions
What is the current version of the NIST Cybersecurity Framework?
What are the six Functions?
Is the NIST CSF mandatory?
Can you get NIST CSF certified?
Is the CSF too big for a small business?
Do you need to reach Tier 4?
Does the NIST CSF count for Texas SB 2610?
Does the NIST CSF replace HIPAA compliance?
Sources
- NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0, February 26, 2024 (NIST)
- Cybersecurity Framework (NIST)
- CSF 2.0 Quick-Start Guides (NIST)
- NIST SP 1300, NIST Cybersecurity Framework 2.0: Small Business Quick-Start Guide, February 2024 (NIST)
- Cybersecurity Framework Frequently Asked Questions (NIST)
- NIST SP 800-66 Rev. 2, Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide, February 2024 (NIST)
- CIS Critical Security Controls Version 8.1 (Center for Internet Security)
- Texas Business and Commerce Code, Chapter 542, Cybersecurity Program (Texas Constitution and Statutes)
- Texas Business and Commerce Code, Chapter 521, Unauthorized Use of Identifying Information (Texas Constitution and Statutes)
Last reviewed: September 30, 2026
This page is general information about the NIST Cybersecurity Framework and related rules, not legal advice for your situation.
Talk with ALCON DTS about the NIST Cybersecurity Framework
Not sure where you stand across the six Functions, or what your Target Profile should be? We will walk through your environment, show you what is in place and give you a clear plan for the rest.
Email: info@alcondts.com ยท Phone: 512-892-6900

