NIST CSF 2.0: The Six Functions and the New AI Profile

Key takeaways

  • The NIST CSF is voluntary guidance describing cybersecurity outcomes. It is not a regulation, not a certification, and not a control list.
  • CSF 2.0, published in February 2024, has six core functions. Govern was added to the original five, which is why older material still talks about five pillars.
  • Tiers and Profiles turn the NIST CSF from a taxonomy into a roadmap, through the gap between a Current Profile and a Target Profile.
  • In December 2025, NIST released a preliminary draft Cyber AI Profile (NIST IR 8596) that applies the NIST CSF to AI systems across three focus areas.
  • The NIST CSF and the NIST AI RMF are complementary. NIST itself points to the CSF as the tool for the cybersecurity share of AI risk.
NIST CSF hexagonal keystone illustrating the six core functions

What the NIST CSF actually is (and what it is not)

The NIST CSF, short for the National Institute of Standards and Technology Cybersecurity Framework, is a voluntary framework for managing cybersecurity risk. The current version, CSF 2.0, was published on 26 February 2024. The framework’s own abstract is precise about its scope. It “offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization, regardless of its size, sector, or maturity, to better understand, assess, prioritize, and communicate its cybersecurity efforts.” One sentence in that abstract explains most of the confusion around the NIST CSF: “The CSF does not prescribe how outcomes should be achieved.” The framework tells you what good looks like. It deliberately refuses to tell you which product to buy, which configuration to apply, or which control to implement. Those live elsewhere, in catalogues such as SP 800-53, and the CSF links out to them through what NIST calls Informative References. This matters commercially. Organizations frequently ask to be “NIST CSF certified”, and no such thing exists. There is no certificate, no accredited auditor, and no pass mark. You can assess yourself against the NIST CSF, you can be assessed by a third party against it, and you can be contractually required to use it, but the framework itself issues nothing. CSF 2.0 also widened its audience. Version 1.1 was aimed largely at critical infrastructure operators. Version 2.0 explicitly addresses executives, boards of directors, acquisition professionals, risk managers, lawyers, and human resources specialists alongside security teams. That widening is the first signal of where the framework was heading, and it is the reason a cybersecurity artefact now sits inside broader AI governance framework conversations.

The six core functions of CSF 2.0

Before the definitions, the question the search results keep asking: there are no longer five pillars. CSF 1.1 had five functions. CSF 2.0 has six, because Govern was added in February 2024. Material still describing five pillars is describing the previous version. The six functions of the NIST CSF, in the framework’s official wording, are as follows.

GOVERN (GV)

“The organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.” Govern is the function that changed the shape of the framework. It does not sit beside the other five as a sixth activity. It wraps them, setting the risk appetite, roles, policy, and oversight that determine how the remaining five are prioritized and resourced.

IDENTIFY (ID)

“The organization’s current cybersecurity risks are understood.” Identify covers asset management, risk assessment, and improvement. It is the function that fails silently, because you cannot assess risk on assets you have never inventoried.

PROTECT (PR)

“Safeguards to manage the organization’s cybersecurity risks are used.” Protect covers identity and access management, awareness and training, data security, platform security, and the resilience of technology infrastructure.

DETECT (DE)

“Possible cybersecurity attacks and compromises are found and analyzed.” Detect covers continuous monitoring and adverse event analysis: finding the anomalies and indicators of compromise that Protect did not prevent.

RESPOND (RS)

“Actions regarding a detected cybersecurity incident are taken.” Respond covers incident management, analysis, reporting, communication, and mitigation once something has actually happened.

RECOVER (RC)

“Assets and operations affected by a cybersecurity incident are restored.” Recover covers restoration of systems and services, and the communication that accompanies it. Read in sequence, the six functions of the NIST CSF describe a full lifecycle wrapped in governance, which is precisely the structure mature AI governance programmes end up adopting independently.

Tiers and Profiles: how the NIST CSF is actually applied

The functions are the vocabulary. Profiles and Tiers are the grammar, and they are where most NIST CSF implementations either succeed or quietly stall. An Organizational Profile describes how an organization sits against the CSF Core. The framework distinguishes two. A Current Profile “specifies the Core outcomes that an organization is currently achieving”. A Target Profile “specifies the desired outcomes that an organization has selected and prioritized”. The useful artefact is neither profile on its own. It is the delta between them. That gap, expressed as a prioritized list of outcomes not yet achieved, is the roadmap. It is also the document that translates cleanly into a budget request, because each line is an outcome rather than a product. CSF Tiers are the second mechanism, and the most commonly misused. The four Tiers, from Partial through Risk Informed and Repeatable to Adaptive, characterise the rigour of an organization’s cybersecurity risk governance and management practices. They are a description of how an organization manages risk, not a maturity score to be maximised. A small organization operating deliberately at Tier 2 with a well-understood risk appetite is applying the NIST CSF correctly. Chasing Tier 4 because it is the highest number is not. The third mechanism, Community Profiles, is where this article turns. A Community Profile is a reusable Target Profile baseline built for a particular sector, technology, or threat context, so that every organization facing the same problem does not rebuild the same analysis. That mechanism is exactly what NIST has now applied to artificial intelligence, and it is the piece that connects the NIST CSF to compliance monitoring for AI systems.

What changed from CSF 1.1 to CSF 2.0

Three changes matter for anyone reading the NIST CSF today. First, Govern was added. The five-function model implied that governance was an input to cybersecurity rather than part of it. Version 2.0 corrected that by making strategy, policy, roles, and oversight first-class outcomes with their own categories and subcategories. Second, the scope broadened. The 2014 framework was created under an executive order focused on critical infrastructure. CSF 2.0 dropped the qualifier entirely and addresses organizations of any size, sector, or maturity. Third, supply chain risk management was substantially reinforced, appearing as a dedicated category under Govern. That change anticipated the problem the AI profile now confronts directly, because an AI system is, from a security standpoint, largely an assembly of third-party components. Govern is also the function the AI work leans on hardest, which makes the 2.0 revision the precondition for everything in the next section. For a wider comparison of how the NIST CSF sits alongside other regimes, see our cross-mapping of NIST AI RMF, ISO 42001, the EU AI Act and OECD principles.

The Cyber AI Profile: when the asset you are protecting is an AI system

On 16 December 2025, NIST released the Cybersecurity Framework Profile for Artificial Intelligence, catalogued as NIST IR 8596 and referred to as the Cyber AI Profile. It is an Initial Preliminary Draft, authored within the Applied Cybersecurity Division and the National Cybersecurity Center of Excellence with MITRE. The process timeline is worth knowing, because the document is not yet stable. NIST opened a 45-day public comment period that closed on 30 January 2026, held a workshop on 14 January 2026, and plans an initial public draft during 2026. More than 6,500 people joined the community of interest contributing to it. The Profile is organized around three Focus Areas, quoted here from section 2.1 of the draft:

  • “Securing AI System Components (Secure): Focuses on managing cybersecurity challenges when integrating AI into organizational ecosystems and infrastructure.”
  • “Conducting AI-Enabled Cyber Defense (Defend): Focuses on identifying opportunities to use AI to enhance cybersecurity processes and activities, and understanding challenges when leveraging AI to support defensive operations.”
  • “Thwarting AI-Enabled Cyber Attacks (Thwart): Focuses on building resilience to protect against new AI-enabled threat vectors.”

The structural detail is the important one. The Cyber AI Profile does not invent a new framework. It is organized using the existing NIST CSF Functions, Categories, and Subcategories, and assigns a proposed priority to each Subcategory for each Focus Area. It is a prioritization overlay on the framework you already know, which means an organization already running the NIST CSF adopts it by re-weighting, not by starting over. The scope of Secure is broader than most AI security conversations. It covers “the AI systems themselves, their supply chains, including data and machine learning infrastructure, and the other systems and data that the AI system relies on.” Training data, model registries, vector stores, inference endpoints, and the orchestration layer are all in scope, not just the model. NIST is also developing COSAiS, a series of SP 800-53 Control Overlays for Securing AI Systems, described in the draft as implementation-focused guidance to help organizations customize and prioritize the most critical controls when using AI systems. That completes the stack: the NIST CSF supplies outcomes, the Cyber AI Profile prioritizes them for AI, and COSAiS supplies the controls. Understanding what counts as an in-scope system is a prerequisite, which we cover in our guide to AI systems and their governance.

NIST CSF, AI RMF, and ISO 42001: which framework does what

The most common question at this point is whether the NIST CSF and the NIST AI RMF compete. They do not, and NIST settles it explicitly in the Cyber AI Profile draft. The AI RMF, it states, “broadly addresses the responsible use of Artificial Intelligence (AI) systems and points to the NIST CSF and NIST Risk Management Framework (RMF) as some of the available tools for managing any associated cybersecurity risks.” Read that carefully: the AI framework delegates the cybersecurity portion of AI risk to the NIST CSF. The division of labour is defined by NIST, not inferred by vendors. Both frameworks happen to have a Govern function, which is a genuine source of confusion. They govern different objects. Govern in the NIST CSF concerns cybersecurity risk to the organization. Govern in the NIST AI RMF concerns risk arising from the AI system and affecting individuals, organizations, and society. An adversarially poisoned training set is a CSF Govern problem. A model that systematically disadvantages a protected group is an AI RMF Govern problem. Many real incidents are both. The wider stack resolves as follows:

  • NIST CSF: cybersecurity outcomes, voluntary, no certificate.
  • NIST AI RMF: AI-specific risk across Govern, Map, Measure, and Manage, voluntary, no certificate.
  • ISO/IEC 42001: a certifiable AI management system, covered in our guide to ISO 42001 and the AIMS standard.
  • SP 800-53: a control catalogue you implement, not an outcome taxonomy you assess against.

That last point answers the recurring question of whether SP 800-53 and the NIST CSF are the same thing. They are not, and they are not alternatives. SP 800-53 enumerates controls. The NIST CSF describes outcomes and points at control catalogues as Informative References. Organizations typically use both, with the CSF as the communication layer for executives and SP 800-53 as the implementation layer for engineers. One caveat on currency: the Cyber AI Profile draft notes that “per the AI Action Plan, the AI RMF is currently in revision and will be included in a future version.” Anyone building a long-lived crosswalk should expect the AI RMF side to move. NIST maintains official AI RMF crosswalks, including a mapping to ISO/IEC 42001.

Putting the NIST CSF to work on your AI estate

Four moves convert the theory into something operational. Start with Identify, not Protect. The Cyber AI Profile assumes you know which AI systems you run. Most organizations do not. Models reach production through business units, embedded vendor features, and individual employees, none of which appear in a traditional asset register. That inventory gap is the shadow AI problem, and it defeats every subsequent function of the NIST CSF, because an uninventoried model cannot be monitored, patched, or recovered. Use Govern to absorb AI risk rather than to duplicate it. The instinct is to stand up a parallel AI risk committee. The better move is to extend the existing cybersecurity risk appetite, roles, and policy statements to cover AI assets, so one governance structure covers both. CSF 2.0’s Govern categories are already shaped for this. Build an AI Target Profile. Take the Cyber AI Profile’s prioritized Subcategories, filter them to the Focus Areas that match your situation, and express the result as a Target Profile against your Current Profile. The delta is your AI security roadmap, in the same format your board already reads. Map outcomes to evidence once. The same access-control record, the same model inventory entry, and the same incident log can satisfy a NIST CSF subcategory, an AI RMF function, and an ISO/IEC 42001 clause simultaneously. Collecting that evidence once against a shared control set is the difference between a governance programme and a compliance treadmill, a point we develop in our AI risk management guide.

FAQ

What is the NIST CSF? The NIST CSF is the National Institute of Standards and Technology Cybersecurity Framework, a voluntary framework that describes high-level cybersecurity outcomes any organization can use to understand, assess, prioritize, and communicate its cybersecurity work. The current version is CSF 2.0, published in February 2024. It provides a taxonomy of outcomes organized into six functions rather than a prescriptive list of controls, and it deliberately does not specify how those outcomes should be achieved. What are the five pillars of the NIST CSF? There are six, not five. The five-function model (Identify, Protect, Detect, Respond, Recover) belongs to CSF 1.1. CSF 2.0 added Govern in February 2024, covering cybersecurity strategy, expectations, and policy. Sources still describing five pillars are describing the superseded version. Govern is not simply a sixth item in the list: it establishes the risk appetite and oversight that shape how the other five functions are prioritized. Is NIST 800-53 the same as the NIST CSF? No. SP 800-53 is a catalogue of security and privacy controls that organizations implement. The NIST CSF is a taxonomy of outcomes that organizations assess themselves against, and it links out to control catalogues such as SP 800-53 through Informative References. They operate at different levels and are commonly used together, with the CSF serving as the executive communication layer and SP 800-53 as the engineering implementation layer. Is the NIST CSF mandatory? The NIST CSF is voluntary and carries no certification. There is no accredited NIST CSF audit and no pass mark. It can nevertheless become effectively binding through other routes: US federal contracts, sector regulators, cyber insurance underwriting, and customer security questionnaires all reference it. Organizations frequently find they must demonstrate alignment with the NIST CSF contractually even though the framework itself imposes no obligation. Does the NIST CSF cover AI systems? It now does explicitly. In December 2025 NIST released NIST IR 8596, the Cyber AI Profile, a Community Profile applying the NIST CSF to artificial intelligence across three focus areas: securing AI system components, conducting AI-enabled cyber defense, and thwarting AI-enabled cyber attacks. It is an initial preliminary draft, with an initial public draft planned for 2026, so treat its priorities as directional rather than settled. How does the NIST CSF relate to the NIST AI RMF? They are complementary and NIST defines the boundary. The AI RMF addresses responsible use of AI systems and explicitly points to the NIST CSF as one of the available tools for managing the associated cybersecurity risks. In practice, the CSF handles the security of the AI system as an asset, while the AI RMF handles the risks the AI system creates for people and society. Both contain a Govern function, but they govern different objects.

Conclusion

The NIST CSF stopped being a purely cybersecurity artefact the moment NIST began profiling it for artificial intelligence. CSF 2.0 supplied the governance function that made this possible, and the Cyber AI Profile now uses that function to bring models, training data, and machine learning infrastructure inside the same framework that already governs the rest of the estate. For security teams, the practical consequence is that AI assets are no longer someone else’s governance problem. For AI teams, it means the security controls you were about to invent already have a home. The organizations that handle this well will not run two frameworks in parallel. They will run one control set, evidenced once, and reported against the NIST CSF, the AI RMF, and ISO/IEC 42001 at the same time. That is the work AI Sigil is built for: a single governed inventory of AI systems, mapped to the frameworks that apply to you, with the evidence attached.

NIST CSF 2.0: The Six Functions and the New AI Profile

NIST CSF 2.0 explained: the six core functions, Tiers and Profiles, plus how NIST's draft Cyber AI Profile extends the framework to AI systems.

ISO 42001 Certification: Process, Cost, and Timeline

The ISO 42001 certification process explained: the five phases, the 38 Annex A controls, realistic cost and timeline, and how it prepares you for the EU AI Act.

AIGP Certification: The Operator’s Guide to IAPP’s AI Governance Credential

A vendor-neutral guide to the IAPP AIGP certification: 2026 body of knowledge, exam format, cost, salary and how to prepare for the exam.

AI Compliance in 2026: The Operating Model, Not a Checklist

AI compliance is a continuous governance operating model, not a one-off checklist. Map EU AI Act, ISO 42001 and NIST AI RMF to controls and evidence.

AI Audit: A Governance Guide to Auditing AI Systems

An AI audit is a structured, evidence-based review of how AI systems are built, deployed, and governed. Learn the five audit types, the process, and a checklist.

Shadow Artificial Intelligence: Close the Governance Gap

Shadow artificial intelligence is the ungoverned AI your teams already use. See the risks, the EU AI Act inventory obligation, and how to govern it.