home / guides / nist-cybersecurity-framework-2

Frameworks and controls · NIST

NIST Cybersecurity Framework 2.0

A widely used outcome-based framework for organizing a security program and explaining it to executives.

Who this applies to

Organizations of any size that want a common language for risk, program maturity, and board reporting.

What to know

  • Version 2.0 organizes outcomes into six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
  • Govern was added in 2.0 and puts strategy, roles, policy, and oversight at the center of the model.
  • It is voluntary and describes outcomes, not specific products or settings.
  • Many Canadian organizations use it as a map, and it pairs well with a control catalog such as the CIS Controls.

What to do

  • Build a current profile of what you do today in each function.
  • Choose a target profile based on your risk and your obligations.
  • Turn the gap between the two into a prioritized, funded plan.

Sources

Reviewed October 2026.