Issue 001 · Spring 2026Toronto · Global
NIST Cybersecurity Framework 2.0

NIST CSF 2.0.

Released in 2024, NIST CSF 2.0 is the updated U.S. National Institute of Standards and Technology cybersecurity framework. Adds the Govern function to the original five (Identify, Protect, Detect, Respond, Recover) and covers 106 subcategories.

§ Practitioner’s note

NIST CSF 2.0 is the assessment framework most U.S. federal contractors and many regulated industries (financial services, healthcare, critical infrastructure) align to. The 2.0 revision added a sixth function — Govern — recognizing that the previous five (Identify, Protect, Detect, Respond, Recover) skipped over the executive oversight and risk-management practices that determine whether a security program is sustained. Each of the 106 subcategories has informative references that map to other frameworks (ISO 27001, COBIT, CIS Controls), making CSF 2.0 a useful Rosetta Stone when you have to satisfy multiple frameworks at once.

Need help with NIST CSF 2.0?

We do this work every day for Canadian teams. Book a free 30-minute consultation.

Talk to MALTO Cyber →