Frameworks

NIST CSF 2.0, scored on a real scale.

The CSF is not pass/fail. TruOps records maturity per category and function so you can see where you are, where you want to be, and what closes the gap.

NIST CSF 2.0 · readinessevidence current
NIST CSF 2.0 · coverage maturity by function (0–5)
GV Governpartial · 48%
ID Identifysatisfied · 96%
PR Protectsatisfied · 99%
DE Detectpartial · 71%
RS Respondpartial · 57%
RC Recoveropen · 22%
The same work also counts toward
NIST 800-5339% · partials shown
CIS Controls55% · partials shown
ISO 2700153% · partials shown

Mappings are typed exact, partial, or inferred, each with a citation.

Illustrative example
In short

The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, organizes cybersecurity outcomes into six functions: Govern, Identify, Protect, Detect, Respond, and Recover, broken into categories and subcategories. It is voluntary and outcome-based; organizations use profiles to describe current and target states and tiers to describe how rigorous their risk management is.

This page is for you if
  • The board asked for a maturity score and you have a consultant spreadsheet from two years ago
  • You need current vs. target profiles, not a pass/fail dashboard
  • Examiners or insurers reference CSF 2.0 and you need to trend it
Published by
U.S. National Institute of Standards and Technology
Current version
CSF 2.0 (February 2024)
Functions
Govern · Identify · Protect · Detect · Respond · Recover
Structure
22 categories, 106 subcategories

What changed in 2.0

CSF 2.0 added the Govern function, which covers cybersecurity strategy, roles, policy, oversight, and supply chain risk management, and broadened the framework's scope from critical infrastructure to organizations of any size or sector. It also added implementation examples and quick-start guides.

The actual challenge

CSF is not pass/fail. Flattening it into implemented/not implemented throws away the only number leadership can act on: how mature each category actually is.

  • A one-time workshop produced a score that cannot be reproduced.
  • Govern was added in 2.0 and nobody has re-scored.
  • The same work is redone for ISO or SOC 2 because the CSF assessment lives alone.

Bring one real document. Watch the program get set up from it.

What you are probably using today

Almost nobody starts NIST CSF 2.0 from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.

What you use nowWhere it breaksWith TruOps
Spreadsheets, shared drives, and emailThe program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period.
SOC 2 automation toolsThey are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model.Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have.
Enterprise GRC suitesThey can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project.AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project.
A consultant maturity workbookTrue the week of the workshop. No owners, no evidence, no trend.Upload it. TruOps records maturity per requirement, charts it by function, and keeps it tied to evidence as controls change.

Profiles and tiers

A current profile describes the outcomes you achieve today; a target profile describes where you want to be. Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe the rigor of your cybersecurity risk governance and management. Many organizations also score each subcategory on a maturity scale to prioritize work.

How TruOps helps with NIST CSF 2.0

Pick NIST CSF 2.0 as your anchor, or map it to the framework you already run. TruOps keeps NIST CSF 2.0's own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.

Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your NIST CSF 2.0 assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.

Upload a completed NIST CSF maturity assessment and TruOps records maturity per requirement without flattening it into implemented/not implemented, then charts it by function and category.

If this is your situation

Bring the last CSF assessment. TruOps will record it on a 0–5 scale by function and category, without flattening it, and show the gap to target.

How TruOps helps

Anchor or map
Run NIST CSF as your spine or map it to another framework; work counts once.
Pre-filled assessment
Your NIST CSF assessment opens with the answers your evidence supports already filled, each cited.
Honest coverage
Partial coverage is reported as partial, with the remaining requirements listed.
Continuous monitoring
Technical controls checked against your tools hourly to quarterly.
Findings with fixes
Failed checks become grouped findings with a recommended action.
Audit-ready snapshots
Results saved as of their date, with the evidence trail attached.

Questions

What are the six functions of NIST CSF 2.0?

Govern, Identify, Protect, Detect, Respond, and Recover.

Is NIST CSF mandatory?

No. It is voluntary guidance, though some regulators, contracts, and insurers reference it.

Can TruOps score NIST CSF maturity?

Yes. Posture is recorded on each framework's own scale, including maturity from 0 to 5, and can be charted by function and category.

How is NIST CSF different from NIST 800-53?

CSF describes outcomes; SP 800-53 is a detailed catalog of controls. CSF subcategories are commonly mapped to 800-53 controls.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

Does TruOps replace our auditor, QSA, or certification body?

No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.