Home/ Frameworks/ NIST CSF
Framework · NIST CSF 2.0

NIST CSF 2.0: the risk-based security framework your board understands.

The NIST Cybersecurity Framework is the most widely adopted security framework globally—not because regulators require it, but because it works. Version 2.0, released in 2024, added a new Govern function and expanded scope beyond critical infrastructure. Sentrix maps your controls across all six CSF functions continuously and generates board-ready risk posture reports in one click.

6
CSF 2.0 functions: Govern (new), Identify, Protect, Detect, Respond, Recover—all tracked in Sentrix
2024
Version 2.0 release—Sentrix crosswalks are updated to the new Govern function and expanded scope
1-click
Board-ready CSF risk posture report with function-level coverage percentages and gap summary
Multi
CSF controls mapped simultaneously to ISO 27001, SOC 2, and NIST SP 800-53—one evidence set
What NIST CSF 2.0 covers

Six functions. Outcomes-based. Designed to layer on top of anything.

NIST CSF is outcomes-based—it describes what good cybersecurity looks like rather than prescribing specific controls. This makes it ideal as an overlay framework that maps to whatever specific standards you are already required to follow. The new Govern function in version 2.0 addresses cybersecurity strategy, risk management oversight, and supply chain risk governance at the executive level.

  • GV — Govern: cybersecurity strategy, policy, roles, and supply chain risk governance (new in 2.0)
  • ID — Identify: asset management, risk assessment, improvement
  • PR — Protect: access control, awareness, data security, resilience
  • DE — Detect: continuous monitoring, anomaly detection
  • RS — Respond: incident management, communications, analysis
  • RC — Recover: recovery planning and improvements

NIST CSF 2.0 · Function coverage

CURRENT PROFILE
GV — Govern78%
ID — Identify94%
PR — Protect96%
DE — Detect91%
RS — Respond88%
RC — Recover82%
Full NIST CSF capabilities

CSF as your security program backbone—mapped to everything else you need.

Current & target profile

Sentrix tracks both your current CSF profile and your target profile, showing the gap as a prioritized roadmap. Board and executive teams see progress toward the target profile over time.

Board-ready reporting

CSF is designed to communicate cybersecurity risk to executives. Sentrix generates board-ready risk posture summaries by CSF function—no technical jargon, no spreadsheets, one click.

Supply chain risk (GV.SC)

The new Govern function includes supply chain risk governance. Sentrix maps your third-party risk program to GV.SC subcategories, satisfying one of the most significant new additions to CSF 2.0.

Cross-framework mapping

CSF 2.0 controls mapped to ISO 27001, SOC 2, NIST SP 800-53, and Canadian frameworks simultaneously. Use CSF as your primary program and satisfy all specific requirements from one evidence set.

Continuous monitoring (DE)

The Detect function requires continuous monitoring. Sentrix connects to your SIEM, cloud security tools, and endpoint platforms to collect DE evidence automatically without manual screenshots.

Incident response (RS)

Respond function evidence collected from your ticketing and incident management tools. Response time SLAs tracked, lessons learned documented, and post-incident reviews recorded as audit evidence.

See your NIST CSF 2.0 profile against your real stack.

We generate your current and target profile live in the demo using your actual infrastructure.