.ai

NIST CSF 2.0 PLANNING PREVIEW

Preview

Explore how NIST CSF outcomes could map to the security work you already operate.

Review preliminary Function and Subcategory mappings, shared controls, likely evidence, and open questions. Active NIST CSF programs are not yet available.

What this Preview includes

  • Preview Function, Category, and Subcategory catalog
  • Preliminary shared-control mappings
  • Likely evidence examples
  • Current and Target Profile planning concepts
  • Open questions for product feedback

What this Preview does not provide

  • No active maturity or readiness score
  • No complete NIST CSF implementation claim
  • No certification or attestation conclusion
  • No production framework activation
  • No independent assessment
  • No guarantee that preliminary mappings are complete

Shared work

Explore where existing work may support NIST CSF outcomes.

Preview mappings show possible relationships to controls already supporting SOC 2 or ISO 27001. A relationship is a planning aid, not proof that a NIST CSF outcome has been achieved.

Govern

Governance policies may support outcomes for organizational context, strategy, roles, oversight, and supply chain risk.

Identify

Asset inventories and risk records may support outcomes for understanding systems, threats, vulnerabilities, and improvement priorities.

Protect

Identity, awareness, data-security, and resilience controls may support outcomes intended to reduce cybersecurity risk.

Detect

Monitoring observations may support outcomes for continuous monitoring and adverse-event analysis.

Respond

Incident procedures may support outcomes for management, analysis, reporting, communication, and mitigation.

Recover

Recovery plans and test records may support outcomes for restoration and recovery communication.

NIST-specific planning

Move from business context to an improvement roadmap.

Current and Target Profiles organize cybersecurity outcomes around the organization's risk context. The Preview helps structure that planning without making an implementation or assessment claim.

  1. Define business context

    Document mission, stakeholders, requirements, risk appetite, and the systems that matter to the business.

  2. Review applicable CSF outcomes

    Identify the Functions, Categories, and Subcategories that fit the organization and its risk context.

  3. Describe the Current Profile

    Record which applicable outcomes appear to be in place, incomplete, or still unverified.

  4. Define the Target Profile

    Choose the outcome state the organization wants to reach and the priorities that shape it.

  5. Identify and prioritize gaps

    Compare Current and Target Profiles using risk, business impact, and dependencies.

  6. Build the improvement roadmap

    Connect priority gaps to an owner, related control, improvement action, and expected review.

What is NIST CSF 2.0?

The NIST Cybersecurity Framework is a risk-based framework for describing and improving cybersecurity outcomes. Version 2.0 organizes those outcomes into six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. It can be used by organizations of any size or sector without prescribing one technology stack.

The Core contains Categories and Subcategories that describe outcomes a security program should achieve. Organizations can use Profiles to describe their current and target posture, then prioritize work based on business context and risk. The framework supports communication and improvement, but it is not an audit report or certification.

Implementation Tiers characterize the rigor of cybersecurity risk governance and management practices. Informative References connect CSF outcomes to other standards and guidance. Neither concept is a certification level or a substitute for an organization-specific Profile.

The catalog has 106 active Subcategories represented in preliminary Preview mappings. Shared-control relationships can help teams reuse work from SOC 2 and ISO 27001 while preserving the distinct language and risk-based purpose of NIST CSF.

Six Functions across one security program

106 active Subcategories are represented in preliminary Preview mappings across the six Functions.

GV

Govern

Context, strategy, policy, oversight, roles, and supply chain risk

ID

Identify

Assets, risk assessment, and improvement

PR

Protect

Access, awareness, data security, resilience, and platform security

DE

Detect

Continuous monitoring and adverse-event analysis

RS

Respond

Incident management, analysis, reporting, and mitigation

RC

Recover

Recovery execution, restoration, and communication

Questions the production workspace must answer

  • Which outcomes fit the business context?
  • What belongs in the Current Profile?
  • What should the Target Profile prioritize?
  • Which gaps need accountable improvement work?

Frequently asked questions

Quick answers about the product, frameworks, and getting started.

NIST CSF basics

Is NIST CSF a certification?

No. NIST CSF is a voluntary risk-based cybersecurity framework. Organizations use it to understand, communicate, and improve cybersecurity outcomes. vCISO.ai does not issue a NIST certification or independent assessment.

What changed in NIST CSF 2.0?

Version 2.0 adds Govern as a top-level Function and broadens the framework's language for organizations of every size and sector. The Core is organized across Govern, Identify, Protect, Detect, Respond, and Recover.

Can we reuse SOC 2 or ISO 27001 work?

Often, yes. Many implemented controls and reviewed evidence records can support outcomes in more than one framework. The mappings are planning aids, and each framework's requirements and review purpose remain distinct.

Is NIST CSF available in vCISO.ai today?

The requirement view and mappings are currently Preview. Active readiness programs, commercial availability, and assurance should not be inferred from the Preview workspace.

Did not find what you were looking for? Talk to us.

Preview access

Help shape the NIST CSF 2.0 workspace.

Tell us what your team needs. Active readiness remains limited to SOC 2 and ISO 27001 today.

Do not include credentials, security findings, regulated data, or other sensitive information.