Auditen
Home / Frameworks / NIST CSF 2.0 / What changed from CSF 1.1 to 2.0

What changed from CSF 1.1 to 2.0

NIST CSF 2.0 expands the framework's scope from "critical infrastructure" to all organizations regardless of size or sector. The primary requirement for those transitioning is the integration of a new "Govern" (GV) function, which shifts cybersecurity from a purely technical exercise to a strategic business governance requirement.

What it means

The transition from 1.1 to 2.0 signifies that cybersecurity risk must be managed at the enterprise level rather than solely within IT or security silos. The addition of the Govern function ensures that an organization's cybersecurity strategy is aligned with its broader mission and legal obligations, emphasizing leadership oversight and resource allocation.

In practice, this means you cannot simply implement technical controls (Protect/Detect) without first establishing a governance layer that defines why those controls exist and who is accountable for them. The scope now explicitly includes more robust supply chain risk management and an expectation that cybersecurity goals are integrated into the organization's overall risk management strategy.

How to meet it

Evidence an auditor asks for

  • Updated Framework Profiles documenting the transition from CSF 1.1 targets to CSF 2.0 targets.
  • Executive or Board meeting minutes demonstrating active oversight of cybersecurity risks and approval of security budgets/resources.
  • A formal Governance Policy or Charter defining roles, responsibilities, and accountability (e.g., a RACI matrix).
  • Documentation of supply chain risk management processes, including third-party risk assessments and contractual security requirements.

Common pitfalls

  • Treating the "Govern" function as a documentation exercise rather than implementing actual leadership engagement and oversight.
  • Assuming that compliance with CSF 1.1 automatically satisfies CSF 2.0 without reviewing new subcategories and updated terminology.
  • Failing to update third-party risk management processes to reflect the increased emphasis on supply chain security in version 2.0.