🛡️ NIST CSF 2.0 · UPDATED JULY 2026

NIST Cybersecurity Framework 2.0:
A Practical Govern → Recover Guide for SMBs

NIST CSF is the most widely adopted free cybersecurity framework in the world — and the February 2024 release (CSF 2.0) added a brand-new Govern function. Here's what the 6 Functions actually look like in practice for a 10–250 person business, how to map them onto the tools you already have, and how to score your current maturity in 5 minutes.

📅 July 24, 2026 📊 NIST CSF 2.0 (Feb 2024) · 22 Categories · 108 Subcategories 👥 SMBs 5–500 employees

Get Your Free NIST CSF Readiness Score →

See where you stand on all 6 NIST CSF functions in 5 minutes. Free, no signup. The assessment benchmarks you against the 22 CSF Categories and shows the highest-impact gaps first.

Why NIST CSF 2.0 Is the Right Starting Point for SMBs

6
Functions: Govern, Identify, Protect, Detect, Respond, Recover
NIST CSF 2.0
22
Categories across the 6 Functions (CSF 2.0 structure)
NIST.gov
108
Subcategories — the implementation-level outcomes
NIST.gov
0$
Compliance cost — free framework download from NIST
NIST.gov

NIST CSF 2.0 (February 2024) added the Govern function — bringing enterprise-wide risk governance, supply chain risk management, and explicit roles/responsibilities into the framework for the first time. The previous 5-function model (Identify, Protect, Detect, Respond, Recover) is now wrapped in this new governance layer. CSF 2.0 also explicitly extended applicability beyond critical infrastructure — meaning SMBs in any sector can adopt the same framework that large enterprises use.

What NIST CSF 2.0 Actually Means

The NIST Cybersecurity Framework is the most widely adopted free security framework in the world — used by more than 50% of U.S. organizations according to Gartner's 2024 adoption surveys, and referenced by federal regulators (CISA), cyber insurers, and SOC 2 / ISO 27001 auditors. CSF 2.0 gives you a common language for managing cybersecurity risk that translates across boards, IT providers, insurers, and auditors.

Ad-Hoc SMB Security (Pre-CSF) NIST CSF 2.0 Approach
Security decisions made reactively, after an incident or audit ask Structured 6-Function framework (Govern → Recover) covering strategy, prevention, detection, response, and recovery upfront
No common vocabulary — IT provider, insurer, and board all talk past each other Shared taxonomy (22 Categories, 108 Subcategories) every stakeholder recognizes
Random tooling: whatever the IT guy read about last week Controls mapped to Functions/Categories so you can justify every tool purchase
After-incident scramble: no playbook, no owners, no communications plan Documented Respond (RS) and Recover (RC) playbooks with tabletop-tested RTO/RPO
Cyber insurance application: "we have MFA, sometimes" Maturity score across all 6 Functions — underwriters see you've thought about each
Vendor / supply-chain risk: discovered when the SaaS provider gets breached Govern (GV.SC) Subcategories force supply-chain assessment before, not after

The core idea is simple: every security decision rolls up to one of the 6 Functions. When someone asks "do we need MFA?" the answer is yes — it lives under Protect > Identity, Authentication, and Access Control (PR.AA). When the auditor asks "how do you handle incidents?" the answer is the Respond playbook, which lives under RS.RP. CSF gives every participant in your security program a stable address system for what you're doing.

The 6 NIST CSF 2.0 Functions

CSF 2.0 reorganized the framework around 6 Functions. The brand-new Govern (GV) function wraps the original 5 (Identify, Protect, Detect, Respond, Recover) with enterprise-wide risk oversight. You don't need to implement all 6 simultaneously — Identify and Protect deliver the most immediate risk reduction, but you won't pass any audit or insurance application without at least basic coverage of Govern and Respond.

GV
Govern NEW
Risk governance strategy, roles & responsibilities, supply chain risk management, and oversight policies. Added in CSF 2.0 (Feb 2024) — the management wrapper that ties the other 5 Functions to leadership.
ID
Identify
Asset inventory (hardware, software, data, people), risk assessment, business context documentation, and governance of identifying emerging risks. The "what do I have to protect?" function.
PR
Protect
Identity & access control (MFA, conditional access), awareness training, data security (encryption, DLP), platform security (patching, secure configs), and resilience (backups, change management).
DE
Detect
Continuous monitoring of networks, endpoints, cloud workloads, and identity systems; anomaly & event detection; analysis of detected events; and alerting with clear escalation paths. The "is something happening?" function.
RS
Respond
Incident response plan (RS.RP), communications (legal, exec, customers, regulators), analysis, mitigation, and post-incident reporting. The function that turns detection into recovery instead of panic.
RC
Recover
Recovery planning (RC.RP), execution of recovery playbooks to restore operations, and post-incident improvements that feed back into Govern and Protect. The function that lets you come back after a breach.

SMB-Relevant Mappings: CSF Categories → Concrete Controls

The 108 CSF Subcategories are written as outcomes — they're intentionally tool-agnostic. Here's how the most important ones map to concrete SMB controls you can actually deploy this quarter.

GV GV.OC / GV.RM — Organizational Context & Risk Management Strategy

SMB control: A written cybersecurity strategy doc (1–2 pages) that names your risk tolerance, defines security goals for the next 12 months, and assigns an owner — typically the COO or a fractional CISO. CSF 2.0 explicitly requires this; insurance applications, SOC 2 readiness, and vendor questionnaires all ask for it. Without GV.OC documented, you've got no row to stand on when the auditor asks "who owns security here?"

ID ID.AM — Asset Inventory (Hardware, Software, Data, People)

SMB control: A maintained asset inventory — every laptop, server, SaaS subscription, and data store. For <50 employees this can be a spreadsheet refreshed quarterly; for larger SMBs, Intune/Google endpoint management plus a SaaS inventory (Zylo, Productiv, or Torii). The downstream benefit is enormous: zero-trust controls (segmentation, EDR, conditional access) all depend on knowing what assets you have.

PR PR.AA — Identity, Authentication, and Access Control

SMB control: Multi-factor authentication (MFA) on every account — Microsoft 365, Google Workspace, VPN, cloud admin consoles, financial systems, source control. Add conditional access: block legacy auth, require MFA from untrusted locations, block impossible-travel sign-ins. This single Category drives more insurance discounts and audit-pass marks than any other.

PR PR.DS — Data Security (at Rest, in Transit, in Use)

SMB control: Encryption at rest for laptops (BitLocker / FileVault), encryption in transit for all internet-facing services (TLS 1.2+), a data classification policy distinguishing public/internal/confidential, and DLP rules in Microsoft 365 or Google Workspace to block confidential data leaving the org. PR.DS pairs with PR.AA — together they address the majority of breach root causes.

DE DE.CM — Continuous Monitoring

SMB control: Endpoint Detection & Response (EDR) on every workstation and server — Microsoft Defender for Endpoint (included in M365 Business Premium), CrowdStrike Falcon, SentinelOne, or similar. Centralized log retention for at least 90 days (Windows Event Logs, M365 audit logs, firewall logs, EDR telemetry). The minimum viable DE.CM stack: an EDR product + a SIEM-lite like Microsoft Sentinel or a managed detection & response (MDR) provider.

RS RS.MA / RS.RP — Incident Management & Response Planning

SMB control: A written Incident Response Plan (IRP) that names the incident commander, lists the 8–10 incident categories you care about (ransomware, phishing, data breach, account takeover, etc.), defines communications templates (legal, board, customers, regulators), and is tabletop-tested at least once per year. Cyber insurers increasingly require a written IRP before they'll issue a policy; insurance denial rates jump for SMBs without one.

RC RC.RP — Recovery Plan Execution

SMB control: Tested, immutable backups for critical data with documented Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). Backups must be stored separately from production so ransomware can't reach them — immutable cloud backup (Wasabi, Backblaze B2 with object lock, AWS S3 Glacier with WORM) plus offline copies. RC.RP requires quarterly restore tests, not just backup checks — most SMBs discover their backups don't work the day they need them.

NIST CSF 2.0 Implementation Roadmap for SMBs

You don't need a 12-month enterprise-wide project to start. These 6 steps are ordered by impact, speed of implementation, and how directly they map to PR.AA (MFA), the single highest-impact Category.

1 Run the free readiness self-assessment

Start by scoring where you stand against all 22 CSF 2.0 Categories. The free NIST CSF readiness assessment gives you a maturity score (0–100) and a prioritized gap list — what to fix first to maximize insurance eligibility, audit pass rate, and actual risk reduction. This becomes your single source of truth for the next 12 months. You can also use NIST's own CSF 2.0 Reference Tool, but the CyberStackHub version maps to your SMB context.

2 Write a Govern charter and assign ownership

The brand-new Govern function (GV) requires that you document organizational context, risk strategy, and roles. For an SMB, this is a 1–2 page charter that states: your risk tolerance, your security objectives for the next 12 months, who owns security (COO, fractional CISO, MSP lead), and how often you'll review. Without GV.OC documented, the other 5 Functions have no leadership anchor.

3 Inventory assets and build a risk register

The Identify (ID) Function is the bedrock. Build a maintained asset inventory — hardware, software/SaaS, data, people — and capture the top 10–20 risks in a simple risk register (probability × impact). You can't prioritize what you haven't enumerated, and you can't defend what you don't know you have. ID.AM is the Category every auditor asks about first.

4 Layer Protect controls: MFA, EDR, backups, training

Protect (PR) is where the highest-impact technical controls live. MFA everywhere (PR.AA), EDR on every endpoint (PR.PS), immutable tested backups (PR.IP), security awareness training with phishing simulation (PR.AT), and a data classification policy (PR.DS). For most SMBs, this Category is fully addressable using tools already in M365 Business Premium or Google Workspace.

5 Stand up Detect: monitoring, alerts, EDR telemetry

Detection (DE) is what lets you catch ransomware, credential theft, and anomalous behavior in time to respond. The minimum viable DE stack: EDR with cloud telemetry (Microsoft Defender, CrowdStrike), centralized log retention (M365 unified audit log, Windows event log forwarding), and an alerting destination (email, Slack, or a managed SOC at ~$1,500–$3,000/month). DE.CM-SS is your highest-ROI Category after MFA.

6 Document Respond and Recover playbooks with tabletop testing

Respond (RS) and Recover (RC) are what determine whether a breach becomes a setback or a catastrophe. Document an incident response plan (RS.RP), a recovery plan with RTO/RPO targets (RC.RP), communications playbooks (RS.CO), and—critically—run a tabletop exercise at least once per year. Most SMBs that "have a plan on paper" discover it's unusable the day an incident happens because nobody has ever rehearsed it.

NIST CSF 2.0 vs Related Frameworks

You don't need to pick one framework — CSF 2.0 is the umbrella that most others crosswalk to. Here's how the major frameworks relate.

NIST CSF 2.0 vs. NIST 800-171. CSF 2.0 is a high-level risk management framework for any organization — it tells you what to think about. NIST SP 800-171 is a prescriptive set of 110 security requirements specifically for protecting Controlled Unclassified Information (CUI) in non-federal systems — it tells you what to implement. Most 800-171 controls map directly to CSF Subcategories. The DoD's CMMC 2.0 builds on 800-171.

NIST CSF 2.0 vs. SOC 2. SOC 2 (AICPA Trust Services Criteria) is a 5-category framework focused on securely operating customer data for service organizations — Security, Availability, Processing Integrity, Confidentiality, Privacy. SOC 2 is an audit: you hire a CPA firm to issue a SOC 2 report. CSF is the program you run to make SOC 2 (or ISO 27001) feasible. If you operate any SaaS product serving enterprise customers, you need both — CSF to build the program, SOC 2 to prove it.

NIST CSF 2.0 vs. ISO 27001. ISO 27001 is the international certifiable Information Security Management System (ISMS) standard. It comes with audit, certification, and ongoing surveillance costs (~$30K–$50K+ for SMBs). CSF 2.0 covers most of what ISO 27001 Annex A controls require — and ISO publishes an official CSF-to-27002 crosswalk. For SMBs without contractual pressure for ISO certification, CSF 2.0 alone is sufficient. For SMBs trying to win EU enterprise contracts, ISO 27001 is often required.

NIST CSF 2.0 vs. CIS Critical Security Controls v8. CIS Controls v8 is a tightly prioritized list of 18 Safeguards across three Implementation Groups (IG1 = SMB baseline of 56 controls, IG2 = mid-size, IG3 = enterprise). CIS is the do these things first checklist; CSF is the management framework that wraps a program around it. NIST publishes an official CSF-to-CIS mapping. The practical SMB path: adopt CIS IG1 as the technical floor, run CSF 2.0 as the program wrapping — together they cover ~85% of insurance/RFP questionnaire items.

Benchmark Your NIST CSF 2.0 Maturity

The free readiness assessment scores you against all 22 CSF 2.0 Categories — showing the prioritized gap list, the controls that move your score the most, and how you stack up against typical SMBs in your industry. Use it as the launch point for a 12-month CSF rollout, or as evidence for an insurance application or compliance questionnaire.

Know Where You Stand Across All 6 NIST CSF Functions

CSF 2.0 isn't a project you finish — it's a program you maintain. Start with your current score; the assessment gives you the roadmap. From there, the CyberStackHub tool library turns each Function into a concrete action.

Need SMB CSF implementation case studies? Read CSF implementation examples on the blog →  |  Browse all CSF-aligned tools →

Sources & Citations

1. NIST Cybersecurity Framework 2.0. National Institute of Standards and Technology. February 26, 2024. nist.gov/cyberframework
2. NIST IR 8286 — Integrating Cybersecurity and Enterprise Risk Management (ERM). National Institute of Standards and Technology. October 2020 (updated 2024). How the Govern function ties CSF to enterprise risk. csrc.nist.gov/publications/detail/nist.ir.8286/final
3. NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems. 110 security requirements mapped to the CMMC 2.0 maturity levels. csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
4. Verizon 2025 Data Breach Investigations Report (DBIR). 22,052 incidents, 12,195 confirmed breaches, 139 countries; SMB-specific breach patterns and credential theft prevalence. verizon.com/business/resources/reports/dbir/
5. IBM Cost of a Data Breach Report 2025. Ponemon Institute. SMB breach cost benchmarks and impact of tested incident response on containment time. ibm.com/reports/data-breach
6. CIS Critical Security Controls v8. Center for Internet Security. 18 controls across Implementation Groups IG1/IG2/IG3 — the technical floor that pairs with CSF 2.0's program-level framing. cisecurity.org/controls/v8
7. CyberStackHub Demand Signals. NIST CSF ranked as the #1 missing keyword cluster — competitor gap analysis (Sprinto, Defendify) confirmed zero CSH presence on "NIST CSF" queries despite high SMB search volume. Driving this landing.