NIST CSF 2.0

NIST CSF 2.0 compliance, every outcome evidenced

NIST CSF 2.0 sets out cybersecurity as outcomes you assess and show, across its six functions. Secrato keeps the controls, policies and evidence behind each outcome connected to the Subcategory it serves, so your Current Profile stays current between reviews.

GDPR BY DESIGN
HOSTED IN BELGIUM
EU DATA SOVEREIGNTY
ENTERPRISE-GRADE SECURITY
GOVERN FUNCTION

Carry governance across the organisation

Connect cybersecurity strategy, policies, risks and controls across workspaces and entities. Apply central governance decisions while allowing approved local deviations where needed.

CORE OUTCOMES

Back outcomes with evidence

Connect evidence directly to the controls and CSF outcomes it supports. Keep records current through uploads, imports and integrations so teams can more easily demonstrate how cybersecurity outcomes are being achieved.

ORGANIZATIONAL PROFILES

See current posture against target

Compare current performance with target outcomes and keep the gaps visible across the CSF functions. Maintain compliance status, findings and readiness in one view so teams can prioritise the work needed to move towards the target profile.

THE REST OF THE PLATFORM

More ways Secrato supports NIST CSF 2.0

Beyond the core outcomes above, these capabilities support the wider NIST CSF 2.0 programme.

Compliance Engine

Manage requirements, controls, evidence, policies and status together, giving teams a current view of where implementation stands.

Risk Management

Keep risks tied to the controls and evidence behind them, with visibility into ownership, treatment and residual exposure.

Assessments

Scope, score and assign assessment work, with responses linked to the evidence and records behind them.

Global Governance

Cascade group-level decisions across workspaces while supporting approved local deviations where needed.

Framework Mapping

See where controls supporting CSF outcomes also address requirements in the other frameworks your organisation carries.

Audit Hub

Organise evidence, review control readiness and manage findings where assurance is needed across cybersecurity activities.

SUPPORTED FRAMEWORKS

One control. Multiple frameworks.

NIST CSF 2.0 is designed to work alongside other cybersecurity standards, so many CSF outcomes can be supported by controls an organisation already maintains for frameworks such as ISO 27001 or NIS2. The Unified Control Library maps those controls across the relevant outcomes and requirements, helping teams reuse existing work while seeing what remains to reach their CSF Target Profile.

Explore the other supported frameworks →

NIS 2

ISO 27001

CYFUN

GDPR

DORA

CRA

PCI DSS

TISAX

ISO/IEC 42001

ANSSI

ISO 9001

ISO 14001

BSI

ISO 22301

IEC 62443

+ More and growing

FAQs for NIST CSF 2.0 compliance software

What is NIST CSF 2.0?

NIST CSF 2.0 is a voluntary cybersecurity framework that organises outcomes across six functions: Govern, Identify, Protect, Detect, Respond and Recover. NIST CSF 2.0, published as final NIST CSWP 29 on 26 February 2024, is the operative edition of the NIST Cybersecurity Framework. It provides non-prescriptive guidance and a taxonomy of high-level cybersecurity outcomes that can be used by organisations regardless of size, sector or maturity.

CSF 2.0 is designed for organisations of any size, sector or cybersecurity-maturity level. It is generally voluntary guidance, but external legal, regulatory, contractual, customer or supply-chain requirements may require its use for particular organisations. 

Secrato supports CSF 2.0 by connecting governance, controls, policies, evidence and assessments to those outcomes, giving organisations a clearer view of their current posture, target state and the gaps between them.

Turn your CSF Profile into a working view of progress

A current profile is most useful when it continues to reflect how cybersecurity is actually being governed and improved. See how Secrato can connect CSF outcomes with the controls, risks and evidence behind them.

Secrato