1. Home
  2. Insights

NIST CSF 1.0 vs 1.1 vs 2.0: what actually changed

  • NIST CSF
  • Governance

The NIST Cybersecurity Framework has had three versions since 2014. Clients often ask which one to follow and what really changed. Here is the short version.

CSF 1.0 (2014)

Written for US critical infrastructure after Executive Order 13636, it introduced the five functions that became the framework's backbone: Identify, Protect, Detect, Respond and Recover. The core had 22 categories and 98 subcategories. It was voluntary and flexible, and organisations well beyond the US soon adopted it.

CSF 1.1 (April 2018)

A refinement, not a rewrite. It added:

  • A supply chain risk management category.
  • Stronger identity guidance, including authentication and identity proofing.
  • Vulnerability disclosure under Respond.
  • A new section on self-assessment and measuring cybersecurity risk.

The core grew to 23 categories and 108 subcategories, and anything built on 1.0 carried over easily.

CSF 2.0 (February 2024)

The biggest change so far:

  • A sixth function, Govern. It covers strategy, roles, policy, oversight and supply chain risk. Cybersecurity becomes a board and enterprise risk topic, not only an IT one.
  • Wider scope. The title dropped "Critical Infrastructure". The framework now targets every organisation, of any size or sector.
  • A reorganised core. 22 categories and 106 subcategories. Supply chain risk moved into Govern, and improvement activities were brought together in a new Identify category (ID.IM).
  • Practical support. Implementation examples, quick-start guides, organisational profile templates and online references that map the CSF to other standards.

What this means in practice

If your policies or assessments still reference 1.1, plan the move to 2.0. In my experience, Govern is where most gaps appear. Many organisations have solid technical controls but no documented risk appetite, unclear cybersecurity roles, or weak oversight of third parties.

A practical first step is to map your current 1.1 profile to 2.0, then run a short gap assessment focused on Govern. It gives leadership a clear view of where governance needs to catch up with the controls already in place.

Share on LinkedIn All insights