What is the NIST Cybersecurity Framework (CSF)?
The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary, public-domain framework that organizes cybersecurity into six functions — Govern, Identify, Protect, Detect, Respond, and Recover — each broken into categories and subcategories of outcomes. It is a common language for managing cyber risk and a popular on-ramp before a formal audit. There is no NIST CSF certification.
The six functions
CSF 2.0 organizes security outcomes into six functions: Govern (added in 2.0, covering strategy, roles, and risk-management decisions), Identify, Protect, Detect, Respond, and Recover. Together they describe a full lifecycle from understanding your risk to recovering from incidents.
How it is structured
Each function contains categories, which contain subcategories, the specific outcomes you aim for. The framework also provides Implementation Tiers (how rigorous your practices are) and Profiles (your current versus target state), so you can measure and prioritize rather than treat it as pass/fail.
Voluntary, public-domain, and not certifiable
There is no official NIST CSF certificate. Organizations self-assess and align, sometimes with a third-party assessment, and use the framework as a shared vocabulary with customers, boards, and regulators. It is a superb starting point before committing to a certifiable standard like ISO 27001.
Where Keel fits
NIST CSF is free on every Keel plan. Keel ships the framework as a trackable control set, crosswalked to SOC 2, ISO 27001, and the rest, so the work you do for CSF counts toward whatever formal framework you pursue next.
FAQ
Can you get certified in NIST CSF?
No. There is no official NIST CSF certification. You assess your program against the framework and align to it, and some organizations commission an independent assessment, but there is no certificate to earn.
What changed in NIST CSF 2.0?
Version 2.0 added the Govern function and broadened the framework’s scope from critical infrastructure to organizations of all sizes and sectors.
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free