Skip to content
IjyaLabs logo
IjyaLabs
Beta — under testing and trial. Do not use for live compliance decisions, statutory submissions, or regulatory reliance. Readiness preparation only, not a certification or audit.
Advisory·NIST CSF 2.0
🛡️Beta

NIST CSF 2.0 Readiness

Build a current and target cybersecurity profile, validate implementation claims with evidence references, and produce a prioritized improvement roadmap. Free to start.

Useful without sign-in
22 Categories · 6 Functions
Before you start — what to have ready for NIST CSF 2.0

Gather these first. Every one of them is something the assessment will ask for, and finding them mid-way is where an assessment stalls.

Decide your scope first

This module works out which controls apply to you from your answers, so complete the scope step first. Starting without it assesses a population you did not choose.

  • Which systems, services and locations are in scope — write this down before you answer anything.
  • Who owns each area, so an answer about it is somebody’s to give.
  • The period the evidence should cover, where the framework opines on a period rather than a moment.

Gather these documents

What NIST CSF 2.0 is assessed against. Find them before you start — the assessment reads what you upload, not what you tell it.

  • Cybersecurity policy mapped to the CSF Functions (Govern, Identify, Protect, Detect, Respond, Recover)
  • Asset inventory and data flow documentation
  • Access control and identity management records
  • Continuous monitoring / detection configuration
  • Incident response plan
  • Recovery and business continuity plan

Have the right people

Who needs to be involved, and what changes if it is only you.

  • Someone who can find the documents — usually whoever owns the control day to day.
  • A second person to review what was uploaded, if you want reviewed coverage. They must not be the person who submitted or attached that evidence: no one reviews their own work.
  • One person can complete the whole assessment. Reviewed coverage will read zero, and that is accurate rather than a fault.
  • A reviewer’s acceptance is what raises a control from partial to proven, and every workspace has that during the open beta. It becomes something a plan includes once there is anything to buy.

Prepare the files

Upload only what the assessment needs. You are responsible for removing or masking personal and sensitive data that a control does not require — do it before you upload. Asset inventories and monitoring configs expose internal architecture and staff. Mask internal hostnames, IPs and personal contact details before uploading.

  • Upload digital documents only — a Word file, a spreadsheet, or a PDF with real text. A photograph or a scanned paper has no readable text, so it cannot be assessed or prove a control.
  • A scan or a photograph has no text to read, so it cannot prove a control. Export the original instead.
  • The same file cannot be uploaded twice to one library — it is recognised by its contents, not its name.
  • Upload the document itself, not a summary of it. A summary is your description of the evidence, not the evidence.
  • A document that is not about this framework will be accepted and matched against nothing. It still counts against your library, so it is worth checking before you send it.

Know what you will get

So the result is what you expected when you started.

  • You get a readiness position derived from the evidence you upload, and a list of where the gaps are.
  • You do not get an audit, an opinion, or a certification. Only a licensed auditor, an accredited certification body, or the relevant regulator can give you those.
  • Controls you upload nothing for are reported as UNEXAMINED — not as failed. That distinction is deliberate.
  • A document can support a control without proving it. Supporting evidence raises a control to partial; reaching proven takes evidence a second person independently reviewed and accepted.

What is NIST CSF 2.0?

The NIST Cybersecurity Framework 2.0 (February 2024) is a voluntary framework for managing cybersecurity risk. Version 2.0 adds a sixth function — Govern — covering strategy, policy, supply-chain risk, and board-level oversight that underpins all other functions.

CSF 2.0 is widely adopted by US federal contractors, SaaS companies, healthcare providers, financial institutions, and any organisation that wants a structured risk baseline before pursuing ISO 27001, SOC 2, or FedRAMP.

Start maturity assessment →

Who uses NIST CSF?

US federal contractors
NIST CSF is referenced by CISA, CMMC, and FedRAMP risk management programmes.
Healthcare organisations
HIPAA Security Rule alignment maps closely to CSF functions.
Financial institutions
OCC, FFIEC, and NYDFS guidance references the CSF maturity tiers.
SaaS and cloud providers
Enterprise buyers demand CSF self-assessments as part of vendor reviews.
Security teams
CISO and security leadership use the CSF to benchmark and prioritise investments.

The 6 CSF 2.0 Functions

GVGovern

Strategy, policy, risk management, supply chain, and oversight of cybersecurity.

IDIdentify

Asset inventory, risk assessment, improvement planning.

PRProtect

Identity, access, training, data security, technology protection.

DEDetect

Continuous monitoring and anomaly detection.

RSRespond

Incident management, analysis, mitigation, reporting, communications.

RCRecover

Incident recovery, restoration, communications.

Maturity Tiers

CSF 2.0 describes four implementation tiers. The goal is not always Tier 4 — choose a target tier that matches your risk tolerance and resource capacity.

1
Partial
Ad hoc practices, limited risk awareness, no formal policies.
2
Risk Informed
Cybersecurity risk informs decisions but is not org-wide or consistent.
3
Repeatable
Formal policies defined, approved, and consistently implemented.
4
Adaptive
Continuously improving; lessons learned feed back into practices.
CSF 2.0 vs CSF 1.1 — key changes
  • New Govern (GV) function — 6 categories covering policy, roles, risk strategy, and supply-chain oversight.
  • Expanded scope from critical infrastructure to all organisations.
  • CSF Profiles introduced — mapping current state to target state.
  • The Core contains 22 Categories and 106 Subcategories across all six Functions.
  • Implementation Examples added for each subcategory.