NIST CSF 2.0 · GOVERN IDENTIFY PROTECT DETECT RESPOND RECOVER

The Cybersecurity Framework, pointed at your models.

CSF is voluntary, outcome-based and deliberately technology-neutral, which is exactly why it extends to an AI estate without modification. What it will not do is tell you which assets you forgot — and in an AI estate, that is most of them.


A tablet on a dark desk showing an audit summary dashboard with controls reviewed, issues identified and control effectiveness by category Illustrative materials
Outcome-based, which is why it stretches
Govern Identify Protect Detect Respond Recover

What is NIST CSF?

A voluntary framework from NIST that organises cybersecurity work into functions and describes outcomes rather than controls. Version 2.0 added a sixth function, Govern, and widened the audience from critical infrastructure to organisations of every kind. Because it is outcome-based it applies to an AI estate unchanged — the outcomes are the same, the assets are not.

  • Status Voluntary No certification and no penalties. Widely adopted by reference in contracts.
  • Version CSF 2.0 Added Govern, and broadened beyond critical infrastructure.
  • Shape Functions and outcomes Functions, categories and subcategories, describing outcomes rather than controls.
  • Scoping Tiers and Profiles Tiers describe rigour; Profiles describe where you are and where you intend to be.

Who should adopt NIST CSF?

The most commonly named security framework in US contracts after SOC 2, and the one most often used as the organising spine underneath the others.

  • Federal suppliers CSF is the vocabulary US public-sector security policy is written in, and it reaches contractors through the terms.
  • Critical infrastructure operators Its original constituency, and still where the community profiles are most developed.
  • Anyone running NIST AI RMF The two are built on the same logic. CSF for the estate and AI RMF for the models covers both without duplicating the governance work.
  • Boards wanting one picture Its function-level view is the clearest way to report posture without a control-by-control appendix.
  • Organisations with several frameworks CSF decides which outcomes matter; ISO 27001 or CIS Controls supply the how. Using it as the spine stops the others competing.
How we help

How iDharma supports NIST CSF compliance

Function by function, with the AI estate treated as first-class rather than as an annex.

Function What the assessment does
GovernWhether AI risk has an owner, a policy and a route to the board — and whether that route has ever actually been used.
IdentifyThe AI asset inventory: models, training data, artefacts, endpoints and the suppliers behind each. This is where most estates are incomplete.
ProtectAccess control over data and artefacts, secure development for ML pipelines, and supplier controls that reach model providers.
DetectWhether anything would notice model abuse, data exfiltration through outputs, or a poisoned training run.
RespondAn incident path covering AI-specific incidents, with a decision-maker who exists and is reachable out of hours.
RecoverRollback to a known-good model version, and what "known-good" means when the artefact is a set of weights.
ProfilesA current profile and a target profile, with the distance between them costed and sequenced.
Cross-framework mappingFindings tagged to AI RMF, ISO 27001 and the CIS Controls so one assessment answers more than one ask.

CSF and NIST AI RMF compose deliberately: CSF secures the estate the models run in, AI RMF addresses the risks the models themselves create. Same publisher, same logic, and findings map cleanly between them.

Capabilities

What the assessment produces

Six areas, each delivering an artefact rather than an opinion.

Asset inventory and system mapping

Identify comes first for a reason

Models, endpoints, notebooks, pipelines and training data, each with an owner and a dependency line to the business function it serves.

Risk assessment and threat modelling

The threats the estate actually faces

Training data integrity, model theft, prompt injection and leakage through outputs, assessed alongside the conventional threats rather than instead of them.

Control implementation tracking

Outcome to control to evidence

Each CSF outcome mapped to the control that delivers it and the record that proves it operated — which is what turns a framework into a programme.

Monitoring and detection workflows

Would anything notice?

Inference patterns, output as an egress path and pipeline integrity, with alerting that reaches a person who can act on it.

Incident response coordination

Exercised, not scheduled

A response path covering AI-specific incidents, named responders, and a rehearsal so the first attempt is not during a real one.

Recovery planning and improvement

The part that is usually theoretical

Rollback to a known-good model version, artefact integrity, and lessons that actually reach Govern rather than stopping at a retrospective.

Coverage

Complete NIST CSF categories coverage

All six functions assessed, with the categories beneath each scoped to the profile you are working toward.

6
Core functions in CSF 2.0
4
Implementation Tiers
100%
Functions covered by the assessment
GV Govern Strategy, roles, policy, oversight, supply chain
Covered by the assessment
ID Identify Assets, risk assessment, improvement
Covered by the assessment
PR Protect Identity, awareness, data security, platform
Covered by the assessment
DE Detect Continuous monitoring and adverse event analysis
Covered by the assessment
RS Respond Management, analysis, reporting, mitigation
Covered by the assessment
RC Recover Plan execution and communication
Covered by the assessment

Governance integration

Govern assessed as the function it now is rather than as an afterthought bolted onto the original five.

Profile management

A current profile and a target profile, with the gap between them treated as the plan the framework intends it to be.

Implementation tiers

A tier chosen deliberately and recorded, because a supervisor will ask why you drew the line where you did.

Multi-framework mapping

Findings tagged to AI RMF, ISO 27001 and the CIS Controls, so one body of evidence answers several asks.

The core

CSF 2.0 core functions

Six functions organising cybersecurity outcomes. Govern is listed first because 2.0 puts it first — a page that appends it to the old five is describing version 1.1 with an extra card.

Govern

New in 2.0, and the reason to re-read the framework

  • Organisational context and mission
  • Risk management strategy and appetite
  • Roles, responsibilities and authorities
  • Policy, oversight and board reporting
  • Supply chain risk management
  • AI risk owned at a named level

Identify

Assets, risk, improvement

  • Asset management including models and artefacts
  • Training data classified
  • Risk assessment across the estate
  • Inference endpoints catalogued
  • Improvement fed from real findings

Protect

Safeguards that actually reach

  • Identity, authentication and access control
  • Awareness and training that reaches ML teams
  • Data security in transit and at rest
  • Platform security and secure configuration
  • Technology resilience built in

Detect

Would anything notice?

  • Continuous monitoring of the estate
  • Adverse event analysis
  • Anomalous inference volume or pattern
  • Output monitored as an egress path
  • Alerting that reaches a human

Respond

Acting on it

  • Incident management and triage
  • Analysis that reaches root cause
  • Reporting and communication
  • Mitigation carried through
  • Who can disable a model, and how fast

Recover

Getting back

  • Recovery plan execution
  • Rollback to a known-good model version
  • Artefact integrity verified
  • Communication during recovery
  • Lessons folded back into Govern
Rigour

Implementation tiers

Tiers describe how rigorous your risk governance is — not how good your security is, and not a maturity score. They are a characterisation, and moving up one is a decision with a cost attached.

Tier 1

Partial

Ad hoc and reactive

  • Risk management is informal and case by case
  • Limited awareness of cyber risk
  • No organisation-wide approach
  • Supply chain risk largely unconsidered
Tier 2

Risk informed

Approved, not yet organisation-wide

  • Risk management practices approved but not established as policy
  • Awareness exists without a consistent approach
  • Some prioritisation informed by risk
  • Supply chain risk understood in places
Tier 3

Repeatable

Formal and consistent

  • Practices formally approved and expressed as policy
  • Organisation-wide approach to managing risk
  • Consistent methods updated as risk changes
  • Supply chain governance acted on consistently
Tier 4

Adaptive

Continuously improving

  • Practices adapted from lessons and predictive indicators
  • Risk-informed culture across the organisation
  • Real-time information used to improve
  • Supply chain risk managed at enterprise level

A tier is not a grade. Tier 4 is not the target for everyone, and choosing Tier 2 deliberately with the reasoning written down is a stronger position than claiming Tier 3 and having nothing behind it.

The method

Framework profiles

Profiles are how CSF is actually used. Two of them, and the distance between them is the programme — the framework is explicit that the gap, not the score, is the output.

Where you are

Current profile

Assessed, not asserted

  • Outcomes the organisation is achieving today
  • Evidence behind each rather than an opinion
  • Gaps named honestly, including the uncomfortable ones
  • Scoped to a system, a unit or the whole estate
  • The baseline every later comparison runs against
Where you need to be

Target profile

Chosen, and justified

  • Outcomes required by risk appetite and obligations
  • Informed by sector or community profiles where they exist
  • Sequenced by consequence rather than by ease
  • Costed, so the plan survives a budget conversation
  • Revisited as the estate and the threat change

The gap is the deliverable. A current profile on its own is a report; a target profile on its own is an aspiration. What you can act on — and what a board will fund — is the ranked distance between them.

Getting there

Implementation roadmap

CSF's own method: establish where you are, decide where you need to be, close the distance, then keep it closed. The phases overlap in practice.

  1. Phase 1

    Foundation

    Govern and Identify first

    • Establish AI risk ownership and escalation
    • Inventory the AI estate and its dependencies
    • Classify training data and artefacts
    • Agree the scope of the profile
    • Choose and record an Implementation Tier
  2. Phase 2

    Risk assessment

    Build the current profile

    • Assess each function against outcomes
    • Evidence rather than assertion
    • Threat model the AI-specific risks
    • Record gaps and rank by consequence
    • Set the target profile deliberately
  3. Phase 3

    Control implementation

    Close the distance

    • Protect: access, secure development, suppliers
    • Detect: monitoring that produces real alerts
    • Respond: a path that covers AI incidents
    • Recover: rollback tested rather than diagrammed
    • Owners and dates on every item
  4. Phase 4

    Continuous improvement

    Keep it closed

    • Re-assess against the target profile
    • Fold lessons back into Govern
    • Update as the estate changes
    • Report to whoever is accountable
    • Fix the review cadence
In context

NIST CSF vs other frameworks

These are not alternatives and choosing between them is usually the wrong question. CSF decides which outcomes matter; the others supply the how, the certificate or the report.

NIST CSF ISO 27001 SOC 2 CIS Controls
Type Voluntary framework Certifiable standard Attestation report Prioritised control set
Describes Outcomes A management system Controls against criteria Specific safeguards
Third-party seal None Certificate Auditor opinion None
Best at Deciding what matters Proving it is managed Answering a customer Deciding what to build first
Scoping device Tiers and Profiles Statement of Applicability System boundary Implementation Groups
Reaches AI The estate around the model The estate around the model The system boundary The infrastructure
Pairs with AI RMF for model risk ISO 42001 for AI ISO 27001 evidence CSF or ISO above it

Each of these has its own page: ISO 27001, SOC 2 and CIS Controls. For the risks the model itself creates rather than the estate around it, see NIST AI RMF.

Policy templates

Complete cybersecurity policy repository

Ready-to-use templates organised by function, with mapping across to ISO 27001 and the CIS Controls so one set of documents answers more than one question.

Govern & Identify

  • Cybersecurity Risk Management Policy
  • Roles & Responsibilities Charter
  • Asset Management Standard
  • Data Classification Policy
  • Supply Chain Risk Standard
  • Risk Assessment Procedure

+ 4 more policies

Protect

  • Access Control Policy
  • Identity & Authentication Standard
  • Data Security Standard
  • Secure Configuration Baseline
  • Secure Development Standard
  • Awareness & Training Plan

+ 4 more policies

Detect, Respond & Recover

  • Continuous Monitoring Standard
  • Logging & Alerting Procedure
  • Incident Response Plan
  • Incident Communications Plan
  • Recovery & Rollback Procedure
  • Post-Incident Review Standard

+ 3 more policies

Questions

Frequently asked questions

What comes up in every CSF scoping call.

1 The framework
Is NIST CSF mandatory?

No. It is voluntary and carries no penalties of its own. It becomes binding where a contract names it — which happens often enough in federal and critical-infrastructure supply chains that many organisations treat it as required.

What changed in CSF 2.0?

The headline change is a sixth function, Govern, which pulls strategy, roles, policy, oversight and supply chain risk into their own function rather than leaving them distributed. The scope also widened from critical infrastructure to organisations of every kind, and implementation examples moved online where they can be updated.

How does CSF relate to ISO 27001?

CSF describes outcomes; ISO 27001 certifies a management system. They are complementary rather than competing — CSF is the better spine for deciding which outcomes matter, ISO the better instrument for proving to a third party that the system around them is managed.

Is there a certification?

No. There is nothing to certify against, which makes CSF excellent as an organising framework and useless as a customer-facing claim on its own. Pair it with something certifiable if you need the latter.

2 Tiers and profiles
What are the four Implementation Tiers?

Partial, Risk Informed, Repeatable and Adaptive. They characterise how rigorous your risk governance is — not how good your security is. They are deliberately not a maturity model and not a grade.

What is the difference between a current and a target profile?

The current profile records the outcomes you are achieving today, with evidence. The target profile records the outcomes you need, given your risk appetite and obligations. The distance between them, ranked by consequence and costed, is the programme — and it is what a board will actually fund.

How long does implementation take?

The current profile takes weeks; closing the gap takes as long as the gap is wide. The useful discipline is to cost the target profile honestly at the start, because an uncosted target is where CSF programmes quietly stall.

Do we need to reach Tier 4?

Almost certainly not. Tier 4 suits organisations facing sustained targeted attack. For most, choosing Tier 2 or 3 deliberately and recording why is a stronger position than claiming a tier you cannot evidence.

3 AI specifics
Does CSF cover AI risk?

It covers securing the systems AI runs in, which is a large part of the problem but not all of it. Risks the model itself creates — bias, confabulation, unsafe outputs — sit with NIST AI RMF. Running both is the complete answer, and they were designed to compose.

What does Detect look like for a model?

Monitoring inference patterns for abuse, treating outputs as an egress path that can leak training data, and checking training pipeline integrity. Most estates have none of this, because the model was treated as an application feature rather than as infrastructure.

What does Recover mean when the asset is a set of weights?

Rollback to a known-good version, which requires that versions are retained, integrity-checked and actually restorable. Worth testing, because the first time anyone tries is usually during an incident.

Does Govern change anything for an AI programme?

Materially, yes. Govern is where AI risk ownership, acceptable-use policy, supply chain risk over model providers and board reporting all belong. In 1.1 those were scattered; in 2.0 there is a single place to look and a single place to fail.

Get started

Ready to run CSF across your AI estate?

A current profile, a target profile, and the gap ranked by consequence rather than by ease.

This page is guidance on how we scope an assessment, not legal advice.