NIST CSF 2.0 checklist: the six functions, including Govern
NIST CSF 2.0's six functions — including Govern — mapped to the evidence auditors expect, each outcome flagged auto vs. manual.
What NIST CSF requires
NIST CSF 2.0 is organized into 6 functions, 22 categories, and 106 subcategories: Govern, Identify, Protect, Detect, Respond, and Recover. Each outcome must be both designed and operating — auditors want evidence it worked throughout the period, not just that it existed on paper.
The control checklist
All 22 categories across the six CSF 2.0 functions, including the new Govern function. Use the table below as your working checklist — 22 line items. Controls marked Auto can be monitored continuously by SBCMSP; Manual controls need a documented process and human evidence.
| Control | Requirement | Coverage |
|---|---|---|
| Govern (GV) | ||
| GV.OC | Organizational context | Manual |
| GV.RM | Risk management strategy | Manual |
| GV.RR | Roles, responsibilities & authorities | Manual |
| GV.PO | Policy | Manual |
| GV.OV | Oversight | Manual |
| GV.SC | Cybersecurity supply-chain risk | Manual |
| Identify (ID) | ||
| ID.AM | Asset management | Auto |
| ID.RA | Risk assessment | Auto |
| ID.IM | Improvement | Manual |
| Protect (PR) | ||
| PR.AA | Identity management, authentication & access control | Auto |
| PR.AT | Awareness & training | Manual |
| PR.DS | Data security | Auto |
| PR.PS | Platform security | Auto |
| PR.IR | Technology infrastructure resilience | Auto |
| Detect (DE) | ||
| DE.CM | Continuous monitoring | Auto |
| DE.AE | Adverse event analysis | Auto |
| Respond (RS) | ||
| RS.MA | Incident management | Manual |
| RS.AN | Incident analysis | Manual |
| RS.CO | Incident response reporting & communication | Manual |
| RS.MI | Incident mitigation | Manual |
| Recover (RC) | ||
| RC.RP | Incident recovery plan execution | Manual |
| RC.CO | Incident recovery communication | Manual |
Evidence you must collect
For every control, an auditor expects evidence it operated throughout the review period. Common examples:
- Access reviews with timestamps and approver
- Change tickets linked to deployments
- Encryption and configuration snapshots
- Vendor / supplier risk assessments on file
Automating the checklist
Roughly two-thirds of NIST CSF controls can be monitored automatically. SBCMSP watches those continuously, collects timestamped evidence, and flags drift — so the audit becomes a review of a report you already have, not a month-long scramble.
Frequently asked questions
What are the six functions of NIST CSF 2.0?
Govern, Identify, Protect, Detect, Respond, and Recover. Govern is new in 2.0 and sits at the center, establishing the organization's risk-management strategy, expectations, and policy.
How is NIST CSF 2.0 structured?
The Core has 6 functions, 22 categories, and 106 subcategories. The subcategories are the outcome-based statements you assess yourself against.
Is NIST CSF a certification?
No. It is a voluntary framework of outcomes, not a certifiable standard — organizations self-assess or use it to structure a third-party assessment.
Which NIST CSF outcomes can be automated?
Many Protect and Detect subcategories — asset inventory, configuration, access control, and continuous monitoring — can be evidenced automatically. Govern and Recover outcomes still require documented policy and process.