Onwyn › Standards › NIST Cybersecurity Framework 2.0
Scheme / framework · 2.0NIST Cybersecurity Framework 2.0
The NIST Cybersecurity Framework 2.0, published February 2024, organises cybersecurity outcomes into six functions, 22 categories and 106 subcategories. It is not a certifiable standard and there is no NIST audit: it is a way of describing where you are and where you intend to be, and it is increasingly what a US or international customer means when they ask for your security posture. Version 2.0 added GOVERN as a sixth function, moving governance and supply-chain risk from an afterthought to the frame everything else sits in. This pack works at category level, which is the granularity at which most organisations actually make decisions; the 106 subcategories sit underneath and are referenced where they carry weight. Use it to build a Current Profile and a Target Profile — the gap between them is the plan.
What this standard asks for
Every requirement in NIST Cybersecurity Framework 2.0, grouped the way the standard groups them. In the Semantic Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.
GOVERN — strategy, expectations and policy
6 requirements
- GV.OCOrganizational Context
- GV.RMRisk Management Strategy
- GV.RRRoles, Responsibilities and Authorities
- GV.POPolicy
- GV.OVOversight
- GV.SCCybersecurity Supply Chain Risk Management
IDENTIFY — understand the risk
3 requirements
- ID.AMAsset Management
- ID.RARisk Assessment
- ID.IMImprovement
PROTECT — safeguards
5 requirements
- PR.AAIdentity Management, Authentication and Access Control
- PR.ATAwareness and Training
- PR.DSData Security
- PR.PSPlatform Security
- PR.IRTechnology Infrastructure Resilience
DETECT — find what is happening
2 requirements
- DE.CMContinuous Monitoring
- DE.AEAdverse Event Analysis
RESPOND — act on it
4 requirements
- RS.MAIncident Management
- RS.ANIncident Analysis
- RS.COIncident Response Reporting and Communication
- RS.MIIncident Mitigation
RECOVER — restore
2 requirements
- RC.RPIncident Recovery Plan Execution
- RC.COIncident Recovery Communication
Profiles and tiers
2 requirements
- PROF.1Establish the Current Profile
- PROF.2Set the Target Profile and the tier
The documents you will end up with
The recommended document set for NIST Cybersecurity Framework 2.0 — 14 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.
The organisational policy the GOVERN function expects, establishing expectations and authority.
Risk appetite, tolerance statements and how cybersecurity risk is weighed against other enterprise risk.
Who is accountable for what, from the board to the operator.
How supplier risk is assessed, contracted for, monitored and ended — the GV.SC category in full.
Hardware, software, services, data and their criticality — the base every other function depends on.
Identity lifecycle, authentication strength and authorisation.
Role-based training and the awareness cycle.
Protection of data at rest, in transit and in use, matched to classification.
Configuration, maintenance and hardening of hardware, software and services.
How infrastructure is designed to withstand and adapt to adverse events.
What is monitored, how events are analysed, and what constitutes an incident.
Management, analysis, communication and mitigation of incidents.
Restoration of assets and operations, and the communication that goes with it.
Where you are, where you intend to be, and the prioritised gap between them.
Start NIST Cybersecurity Framework 2.0 today
Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.