NIST Cybersecurity Framework 2.0 — Gap Analysis
NIST Cybersecurity Framework 2.0 — Govern, Identify, Protect, Detect, Respond, RecoverAbout NIST Cybersecurity Framework 2.0
The NIST Cybersecurity Framework (CSF) 2.0 was published in February 2024, replacing the long-standing 1.1 version. It expands from 5 to 6 Functions by adding GOVERN (a cross-cutting function covering governance, strategy and supply chain) and broadens applicability beyond critical infrastructure to organisations of any sector and size. Each Function contains Categories and Subcategories representing cybersecurity outcomes.
Issuing Body
US National Institute of Standards and Technology (NIST)
Edition
2024
Coverage
6 Functions, 22 Categories of cybersecurity outcomes — a flexible framework applicable to any sector, size or jurisdiction.
Typical Users
Critical infrastructure operators, federal contractors, supply-chain partners, and any organisation managing cybersecurity risk.
How to use this tool
1. Work through each clause. For each requirement, choose Compliant, Partial, Non-compliant, or leave as Not assessed.
2. Add notes against any requirement to record evidence, gaps, or corrective actions.
3. Click Save progress in the sidebar — data is stored locally in your browser, never uploaded.
4. Export the report as TXT, CSV, JSON or print to PDF for your audit file.
Note: This tool is a guided self-assessment. It does not replace a third-party audit and the authoritative version of the standard must be obtained from the issuing body.
ISO Xpert — Get in touch
UK-based consultancy specialising in management-system gap analysis, training and certification preparation across ISO, API, Halal, GFSI, ESG, cybersecurity and industry-specific standards.
Phone / WhatsApp
Office
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, UK