

NIST rebuilt the Cybersecurity Framework in February 2024, and, for MSPs, NIST CSF 2.0 presents multiple new challenges and opportunities. Unlike the previous iteration, 1.1, CSF 2.0 is written for organizations of every size and sector, not only the critical infrastructure operators that the framework originally targeted. And, Governance came out of Identify and became GOVERN, the first of six Functions, carrying six Categories and a score of its own.
Naturally, these changes have given way to many questions of how businesses should operate under the new framework. NIST’s own Small Business Quick-Start Guide names managed service providers as the party a small business should bring these questions to.
So, let’s dive into what has changed with NIST CSF 2.0, how it affects businesses and the MSPs that manage them, and how to address NIST CSF 2.0 at scale.
NIST Cybersecurity Framework 2.0 is a voluntary framework of 106 cybersecurity outcomes, organized under six Functions, that a business uses to assess where its security program stands and decide what to improve next.
What it does not do is tell you how. NIST confirms this directly: the framework offers "a taxonomy of high-level cybersecurity outcomes" and does not dictate the practices or products used to achieve them.
The Core is organized into six Functions, 23 Categories, and 106 Subcategories. Each Subcategory is a single outcome statement, written so that an organization can say it is achieved, partially achieved, or not achieved, and point at evidence either way.
Two structures around the Core do the work of implementation. Tiers describe the rigor of an organization's cybersecurity risk governance and management practices, from Tier 1 (Partial) through Tier 4 (Adaptive). Profiles describe outcomes: a Current Profile records what is achieved today, a Target Profile records what the organization is aiming at, and the gap between them is the roadmap. Community Profiles give a sector or use case a shared baseline to start from.
If you're still weighing which baseline to standardize on across your book of business, the comparison between NIST CSF and CIS Controls is a more useful starting point than either document on its own.
In CSF 1.1, governance was a single Category (ID.GV) tucked inside Identify. In 2.0 it is GOVERN, the first of six Functions, with six Categories underneath it: Organizational Context (GV.OC), Risk Management Strategy (GV.RM), Roles, Responsibilities, and Authorities (GV.RR), Policy (GV.PO), Oversight (GV.OV), and Cybersecurity Supply Chain Risk Management (GV.SC).
NIST positions GOVERN as informing how the other five Functions get implemented rather than sitting beside them, so an assessment now produces a standalone governance score next to Protect and Detect. A client with excellent tooling, no named risk owner, and no reporting cadence used to score reasonably well. Now the gap has its own column.
CSF 1.1 was written for critical infrastructure and adopted well beyond it. CSF 2.0 drops the pretense and states its audience as organizations of all sizes and sectors, including industry, government, academia, and nonprofit.
That matters for MSPs because it removes the last reason a small client had to wave the framework off as something for utilities and hospitals. NIST reinforced it by publishing the Small Business Quick-Start Guide (SP 1300) for organizations with modest or no cybersecurity plans in place, which tells readers to take anything they are not comfortable handling themselves to whoever they rely on to reduce cyber risk, such as a managed security service provider.
GV.SC carries ten Subcategories covering supplier identification, assessment, contractual requirements, monitoring, and offboarding across the technology lifecycle. It lived as ID.SC in 1.1, and moving it under GOVERN turns it from an inventory exercise into an obligation with a named owner.
For an MSP this cuts both ways. You'll be the one helping clients populate a supplier register, and you'll also be the largest single entry in it. Verizon's 2026 Data Breach Investigations Report found that breaches involving a third party now account for 48% of all breaches, a 60% year-over-year increase. Clients working through GV.SC will ask you for the same attestations you're asking their other vendors for.
Protect now holds Identity Management, Authentication, and Access Control (PR.AA), Awareness and Training (PR.AT), Data Security (PR.DS), Platform Security (PR.PS), and Technology Infrastructure Resilience (PR.IR). The old PR.AC access control category was rebuilt around identity, and platform security and resilience were pulled out as distinct outcomes rather than being scattered across information protection processes.
Identify slimmed to three Categories: Asset Management (ID.AM), Risk Assessment (ID.RA), and Improvement (ID.IM). ID.IM is new, and it's the one MSPs tend to skip. It asks whether improvements are identified from evaluations, tests and exercises, incidents, and operational input, and whether they get incorporated, which turns the post-incident review into a framework outcome with a status.
Detect consolidated to Continuous Monitoring (DE.CM) and Adverse Event Analysis (DE.AE). Respond and Recover kept their shape.
Tiers in 2.0 characterize the rigor of governance and risk management practices, and NIST applies them to Profiles rather than treating them as a maturity grade stamped on the whole organization. That distinction matters in client conversations, because "we're a Tier 2" is a less defensible sentence than "our current profile reflects Tier 2 rigor in these areas, and the target is Tier 3 by Q3."
NIST also shipped a set of Quick-Start Guides that did not exist for 1.1, covering Organizational Profiles (SP 1301), Tiers (SP 1302), Enterprise Risk Management (SP 1303), Cybersecurity Supply Chain Risk Management (SP 1305), and Informative References (SP 1347). These are short, and they are the fastest way to get a technical team from "we read the framework" to "we can run an assessment."
Five things moved. Governance is now its own section with its own score, so policy, ownership, and oversight are graded separately from the tools you run. The framework is written for businesses of every size and sector, which puts your small clients in scope for the first time. Supplier risk became a governance requirement, and you are both the one helping a client build the register and the largest name on it.
Access control was rebuilt around identity, and a new category asks what the client changed after its last incident. Tiers now describe a specific profile instead of stamping a maturity grade on a whole company. If you run assessments for clients, the practical effect of all five is that a question set built for 1.1 needs rebuilding rather than renaming.
When a client fails a questionnaire or an audit, the findings are rarely about missing EDR. They're about a risk assessment nobody signed, an access review that hasn't run since onboarding, a policy set that references a domain controller retired two years ago. Those are governance outcomes, and they are now scored as such.
The governance gap is visible in your reporting whether or not it's in your contract. A client who scores 78% on Protect and 30% on Govern will ask you why. The answer is usually that nobody was asked to own it, which is a scoping conversation rather than a technical one.
Cyber insurance applications draw from the same control families the framework describes, which is why GRC documentation has become the deciding factor in underwriting. A Current Profile with dated evidence answers most of an application directly.
Several states have gone further and written frameworks into statute. Ohio was first in 2018, and the mechanism in these laws is an affirmative defense in breach litigation for organizations that had implemented a recognized framework such as NIST CSF or the CIS Controls. The defense depends on being able to show the program existed before the incident, which is an evidence problem rather than a tooling problem.
The operational argument for standardizing on CSF 2.0 across a client base is simple: it maps. NIST maintains Informative References tying CSF outcomes to SP 800-53, SP 800-171, and other resources, and the framework is routinely used as the crosswalk layer between CIS Controls v8.1, HIPAA, and CMMC. Assess once against CSF, and the regulatory obligations a given client carries resolve to controls you've already evaluated.
That is what makes CSF viable as a book-wide baseline instead of a per-client project. Managing compliance at scale across every client depends on not re-running the same assessment under five different names.
A first pass doesn't require a mature program. It requires a sequence you can repeat.
Start with an assessment that gathers information once and scores against CSF 2.0. Record each Subcategory as achieved, partially achieved, or not achieved, with the evidence and the date. Resist the urge to fix things during the assessment; the value of the first pass is an honest baseline, and remediation performed mid-assessment makes the baseline meaningless.
Six Categories, and most of the work is asking questions rather than touching systems. Who owns cybersecurity risk. What is the documented risk tolerance. When was the policy set last reviewed and by whom. Who receives security reporting and how often. Which suppliers have access to what, and what happens when one is offboarded.
Expect low scores. Expect the client to be surprised by them. That surprise is the opening for the engagement.
A Target Profile that an MSP writes alone is a wish list. One the client signs is a scope document. Pick the Subcategories that move first, attach owners and dates, and be explicit about what is deliberately being deferred. Deferred with a signature is a business decision; deferred silently is a finding waiting to happen.
Profiles drift because environments change and documentation doesn't. Monthly control status, quarterly risk review, annual reassessment. The test is whether the record exists on the day an auditor, an underwriter, or an adjuster asks for it, not whether it can be reconstructed in a week.
After every incident, every tabletop, every failed restore test, write down what changed as a result and which Subcategory it affects. This is the cheapest new outcome in CSF 2.0 to satisfy and the one most likely to be empty at the next assessment. It's also the difference between a framework program that runs continuously and one that gets rebuilt from scratch each year.
MSPs that build this capability tend to stop giving it away, and CSF prices better than most compliance work because the deliverable is concrete.
A CSF 2.0 assessment is a fixed-fee engagement with a defined output: a Current Profile, a scored gap list, and a prioritized roadmap. The roadmap produces remediation projects, and the remediation projects produce recurring revenue in monitoring, management, and the quarterly review cadence itself. The implementation path is repeatable enough to run across a book of business without bespoke work per client.
It also changes what you're in the room for. Presenting a governance scorecard to an owner or a board is a different conversation than reporting patch compliance, and it's the conversation that tends to precede budget. Keeping that scorecard current is where the hours go: monthly control status, quarterly risk review, and an ID.IM entry after every incident and failed restore test. Todyl GRC automates that cadence, so the evidence is collected and reported on schedule instead of being rebuilt the week before each client meeting.
NIST published a preliminary draft of the Cybersecurity Framework Profile for Artificial Intelligence (NIST IR 8596) in December 2025, developed with input from more than 6,500 community participants, with an initial public draft expected during 2026. It applies CSF 2.0 to three problems at once: securing AI systems, using AI in cyber defense, and defending against AI-enabled attacks. A companion draft on using AI for CSF analysis and reporting (SP 1353) is open for comment through October 15, 2026.
Worth tracking now, because the underlying risk is already in client environments. The 2026 DBIR found employee use of unapproved AI tools jumped from 15% to 45% in a single year. When the AI Profile lands, the governance questions it asks will be about tools that have been in production for two years.
No. The framework is voluntary and outcome-based, and NIST does not certify compliance with it. It becomes effectively mandatory through other channels: contract terms, insurance applications, state safe harbor statutes, and customer questionnaires that use it as the scoring model.
Yes, on your own schedule. CSF 2.0 is the current version and is what new assessments, mappings, and Quick-Start Guides are built around. Most 1.1 assessment content carries over, but the reorganization is significant enough that a mechanical crosswalk leaves gaps, particularly across GOVERN and the new ID.IM Category.
GOVERN establishes and monitors the organization's cybersecurity risk management strategy, expectations, and policy. It contains six Categories: organizational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management. In CSF 1.1 most of this content sat as a single Category inside Identify.
CSF describes outcomes and CIS prescribes safeguards. CSF tells you that authorized users are authenticated commensurate with risk; CIS tells you to enforce MFA on externally exposed applications. They are complementary, and most MSPs end up using CSF as the reporting and mapping layer with CIS as the implementation checklist underneath it.
No, and the wording matters. There is no certification body and no compliant state. What you can produce is an assessed Current Profile against the CSF Core, with evidence and dates, and a documented Target Profile. Describe deliverables as alignment or assessment rather than certification.
Yes. CSF outcomes map through Informative References to NIST SP 800-53 and SP 800-171, and CSF is widely used as the crosswalk layer for HIPAA and CMMC obligations. The mapping is what allows a single assessment to answer multiple regulatory questions, which is the practical reason to use CSF as the baseline across a mixed client base.
For a small or midsize client with a cooperative point of contact, a first Current Profile is typically a matter of days rather than weeks, and most of that time goes to collecting evidence rather than answering questions. The second assessment for a similar client is considerably faster once your evidence requests and question set are standardized.
Everything above is repeatable work: one Current Profile per client, a governance score that stands on its own, evidence carrying a date, and a mapping layer that keeps a single assessment answering five regulatory questions. What breaks it is running that in a spreadsheet per client. Todyl GRC supports CIS v8.1, CMMC, HIPAA, NIST CSF, and NIST SP 800-171 Rev 3, with automated compliance mapping, out-of-the-box security assessments, consolidated policy documentation, and multi-tenant reporting across every client.
Book a demo to see the platform in action.
Evaluate your security posture against AI-powered attacks and get recommendations to close any gaps.
Subscribe to our newsletter to get our latest insights.