How to Conduct a NIST Cybersecurity Framework 2.0 Assessment
NIST CSF 2.0 is the updated standard for cybersecurity risk management. Here is a practical guide to conducting an assessment that produces actionable results — not just a compliance binder.
By Tom Brennan
The NIST Cybersecurity Framework version 2.0, released in February 2024, adds a new Govern function to the original five (Identify, Protect, Detect, Respond, Recover), reflecting the growing recognition that cybersecurity is fundamentally a governance challenge.
What Is New in NIST CSF 2.0 and Why Does It Matter?
The addition of the Govern function signals a shift in how NIST views cybersecurity maturity. Governance is no longer an implicit assumption — it is an explicit, assessable function with its own subcategories covering organizational context, risk management strategy, roles and responsibilities, policies, and supply chain risk management. An organization with excellent technical controls but weak governance will show measurable gaps under CSF 2.0 that would have been invisible under CSF 1.1.
How Do You Conduct a NIST CSF 2.0 Assessment That Produces Results?
Phase 1: Scope and Context Setting
Before scoring a single control, establish the assessment scope — what systems, business units, and data types are in scope, and what regulatory frameworks apply. Many assessments fail because scope creep turns a focused engagement into an unmanageable exercise. A clear scope document, agreed upon before fieldwork begins, is the single most important factor in producing an actionable deliverable.
Phase 2: Current State Assessment Across Six Functions
Govern (New in 2.0)
Assess organizational cybersecurity risk strategy, policies, roles, and accountability. Is board-level visibility in place? Is the CISO empowered to act? Is there a documented supply chain risk management policy? Most organizations that have not specifically prepared for this function score poorly here — not because they lack controls, but because accountability has never been formally mapped.
Identify
Asset inventory, business environment understanding, risk assessment. Many organizations still struggle with a complete asset inventory — particularly for cloud workloads, SaaS applications, and OT/IoT devices. No risk assessment can be accurate if the asset inventory is incomplete.
Protect
Access control, awareness training, data security, and infrastructure resilience. Common gaps include inconsistent MFA enforcement, insufficient data classification, and access review programs that exist on paper but are not regularly executed.
Detect
Continuous monitoring, log management, and anomaly detection. The most frequent finding here is log retention configured too short for meaningful threat hunting, and alert fatigue from poorly tuned detection rules that suppress real signals.
Respond
Incident management, analysis, communication, and mitigation. Most organizations have an incident response plan. Far fewer have tested it within the past 12 months, and even fewer have a communication plan that accounts for regulatory notification obligations under HIPAA, NY DFS Part 500, or SEC rules.
Recover
Recovery planning, backup integrity, and recovery time objective testing. Backup programs that have never been tested against realistic scenarios frequently fail when actually needed. Testing recovery — not just backup — is the measurable standard.
What Does the Gap Analysis Produce?
A properly executed CSF 2.0 gap analysis produces a tier rating for each subcategory (Partial, Risk Informed, Repeatable, or Adaptive) and a prioritized remediation roadmap that accounts for actual risk impact — not just compliance checkbox completion. The goal is a living document the security team can use to track progress, not a report that goes into a binder.
Proactive Risk's MEASURERISK practice delivers NIST CSF 2.0 assessments with a specific emphasis on the Govern function — including the accountability mapping that most assessments skip. Contact us to schedule your assessment.
Free Compliance Resources
Accelerate your NIST CSF 2.0 assessment with Proactive Risk's free resources, available in the Downloads library:
- Security Incident Response Plan (SIRP) Template — a ready-to-customize SIRP aligned to NIST SP 800-61, covering the Respond and Recover functions with severity classification, RACI matrix, and regulatory notification guidance
- Department Alignment Interview & Role Mapping Checklist — a structured tool for mapping the 18 CIS v8.1 controls to the people who own them, directly supporting the Govern function's accountability requirements
Explore Related Resources