NIST CSF 2.0: the risk-based security framework your board understands.
The NIST Cybersecurity Framework is the most widely adopted security framework globally—not because regulators require it, but because it works. Version 2.0, released in 2024, added a new Govern function and expanded scope beyond critical infrastructure. Sentrix maps your controls across all six CSF functions continuously and generates board-ready risk posture reports in one click.
Six functions. Outcomes-based. Designed to layer on top of anything.
NIST CSF is outcomes-based—it describes what good cybersecurity looks like rather than prescribing specific controls. This makes it ideal as an overlay framework that maps to whatever specific standards you are already required to follow. The new Govern function in version 2.0 addresses cybersecurity strategy, risk management oversight, and supply chain risk governance at the executive level.
- GV — Govern: cybersecurity strategy, policy, roles, and supply chain risk governance (new in 2.0)
- ID — Identify: asset management, risk assessment, improvement
- PR — Protect: access control, awareness, data security, resilience
- DE — Detect: continuous monitoring, anomaly detection
- RS — Respond: incident management, communications, analysis
- RC — Recover: recovery planning and improvements
NIST CSF 2.0 · Function coverage
CURRENT PROFILECSF as your security program backbone—mapped to everything else you need.
Current & target profile
Sentrix tracks both your current CSF profile and your target profile, showing the gap as a prioritized roadmap. Board and executive teams see progress toward the target profile over time.
Board-ready reporting
CSF is designed to communicate cybersecurity risk to executives. Sentrix generates board-ready risk posture summaries by CSF function—no technical jargon, no spreadsheets, one click.
Supply chain risk (GV.SC)
The new Govern function includes supply chain risk governance. Sentrix maps your third-party risk program to GV.SC subcategories, satisfying one of the most significant new additions to CSF 2.0.
Cross-framework mapping
CSF 2.0 controls mapped to ISO 27001, SOC 2, NIST SP 800-53, and Canadian frameworks simultaneously. Use CSF as your primary program and satisfy all specific requirements from one evidence set.
Continuous monitoring (DE)
The Detect function requires continuous monitoring. Sentrix connects to your SIEM, cloud security tools, and endpoint platforms to collect DE evidence automatically without manual screenshots.
Incident response (RS)
Respond function evidence collected from your ticketing and incident management tools. Response time SLAs tracked, lessons learned documented, and post-incident reviews recorded as audit evidence.
See your NIST CSF 2.0 profile against your real stack.
We generate your current and target profile live in the demo using your actual infrastructure.