Issue 001 · Spring 2026Toronto · Global
← Resources·Articles§ Field note
·4 min read·By Marcus Tommy

NIST CSF 2.0: what changed and why it matters.

NIST CSF 2.0 added a sixth function called Govern. Here's what changed from 1.1, why it matters, and whether you need to redo your assessment.

NIST CSF 2.0 is not a rewrite. You still have the same five functions you already know, plus a sixth one that NIST moved to the centre of the wheel. Whether that sixth function changes your week or just your architecture diagram comes down to how seriously you were already treating governance.

What actually changed

The big one is Govern. In 1.1, governance was a category buried inside Identify, which is roughly where good intentions go to get ignored. In 2.0 it's a function of its own, sitting in the middle of the wheel and feeding the other five: Identify, Protect, Detect, Respond, Recover.

Govern is where the organizational questions now live: who owns cyber risk, what your risk strategy actually is and whether it's written down where people can find it, which roles carry which authority, and whether anyone checks that the policy is followed. NIST also moved cybersecurity supply chain risk management into Govern, instead of leaving it tucked under Identify the way 1.1 did.

Two smaller shifts are worth a line. The framework is no longer aimed only at critical infrastructure; NIST now writes it for any organization of any size, which mostly catches up to how people were already using it. There's also a growing set of implementation resources: the Quick-Start Guides and the Implementation Examples. NIST added two more guides as recently as March 2026, which makes 2.0 far easier to pick up than 1.1 ever was.

Why it matters

Governance was never actually absent from CSF. It was always implied. You couldn't run a credible Identify or Protect program without someone deciding what mattered and who was accountable for it. What 1.1 let you do was treat all of that as understood and never write it down. 2.0 takes that option away.

By making Govern its own function, NIST turned the organizational layer into something an assessor can point at and ask for evidence on. Not "do you have MFA," but "who decided MFA was required, who signed off on the exceptions, and where is that decision recorded." If your CSF work so far has been a stack of controls with no named owner and no risk strategy anyone in the boardroom has read, that's the gap 2.0 puts a spotlight on.

We see this split constantly. A financial services client usually has governance nailed, because regulators have been asking these exact questions for years, so 2.0 barely moves their needle. A fast-growing SaaS company that bolted on controls reactively tends to have the opposite problem: good tooling, no governance spine. For them, 2.0 isn't paperwork. It's the part of the framework that was quietly missing the whole time.

Do you have to redo your assessment?

Short answer: no, and you shouldn't start from scratch even if someone tells you to.

If you already have a CSF 1.1 assessment, most of it carries straight over. The five functions you assessed against still exist and still mean the same things. What changed is the frame around them, not the controls underneath. So the job is a remap, not a redo, and it comes in three passes:

None of this is mandatory unless a contract, a regulator, or a customer's security questionnaire says so, and more of them do every quarter. CSF is voluntary by design. Voluntary stops meaning much the first time a prospect's security team sends you a questionnaire built around 2.0's six functions and you're still answering in five.

Where to start

If your governance was already solid, 2.0 is mostly a relabelling exercise and you can get on with your day. If it wasn't, the remap is worth doing now, before someone makes you do it on a deadline.

Doing it by hand is a spreadsheet weekend nobody enjoys: matching old categories to new ones, chasing down evidence, staring at the blanks. That's the part we got tired of, so we built NISTForge to handle it. It's a self-serve assessment that walks your posture against all six functions and shows you exactly where the governance spine is missing. Run it yourself, or if you'd rather have a second set of hands, our team will do the remap with you.

Either way, don't let 2.0 sit on the someday pile. The frameworks your customers ask about have already moved, and you want to be there before they start asking.

§ Author
Marcus Tommy
Co-founder, MALTO Cyber

Marcus co-founded MALTO Cyber to help organizations deliver strategic technology programs with cybersecurity built in from day one. He leads firm strategy and product direction — bringing extensive Program and Portfolio Management experience to every client relationship, prioritizing the organizational vision, stakeholders, and customers behind every engagement.

LinkedIn →
§ Keep reading

More from this thread.

§ Subscribe

One email. A month.

Field notes shipped to your inbox monthly. No marketing, no upsells.

No spam. Unsubscribe anytime. About 1 email per month.