NIST CSF 2.0 Explained: A Practical Framework for SMEs
NIST CSF 2.0, the second major version of the NIST Cybersecurity Framework, is one of the most useful tools an SME can adopt when it is trying to bring order to a security programme that has grown up piecemeal. Released in February 2024, it gives you a shared language for talking about cyber risk, a logical structure for organising what you do, and a simple way to decide what to improve first. Best of all, it is voluntary and outcome-based, so you can start using it this week without booking an auditor.
If your organisation has bought some tools, written a few policies and run the odd training session, but nobody can say with confidence how well protected you actually are, the NIST Cybersecurity Framework is built for exactly that situation. It does not tell you which product to buy. It describes the outcomes a mature security programme should achieve and lets you decide how to get there.
Most Irish SMEs either have never heard of NIST CSF 2.0 or assume it is a heavyweight American standard meant for large enterprises. Neither is true. It scales down beautifully, and it is increasingly the backbone that smaller organisations use to make sense of everything else.
What NIST CSF 2.0 Is, and What It Is Not
The framework is voluntary guidance, not a certification. There is no NIST CSF certificate to hang on the wall and no pass or fail. Instead it describes cybersecurity outcomes, organised so that a board member, an IT manager and an external advisor can all look at the same picture and understand it.
That is its real strength for an SME. It is a common language and an organising structure. You can use it to run a security programme on its own, or you can use it as a map that connects to other frameworks you may need later, such as ISO 27001 or NIS2. Because it is outcome-based rather than prescriptive, it fits a five-person IT team as comfortably as a five-hundred-person one.
The Six Functions
The framework organises everything into six high-level Functions. Version 2.0 added GOVERN, and it deliberately wraps around the other five rather than sitting alongside them.
- GOVERN. New in 2.0, this establishes and monitors your cybersecurity strategy, roles, responsibilities, policies and risk appetite. It is the layer that ensures cyber risk is managed as a business risk, with real ownership, and it informs how you carry out the other five Functions.
- IDENTIFY. Understand what you have and what could go wrong: your assets, data, suppliers and the risks to them. You cannot protect what you have not catalogued.
- PROTECT. Put safeguards in place to keep services running and limit the impact of an incident: access control, training, data security and maintenance.
- DETECT. Find attacks and anomalies quickly, through monitoring and analysis, so a small problem does not become a large one unnoticed.
- RESPOND. Take action once something is detected: contain it, communicate, investigate and mitigate.
- RECOVER. Restore normal operations and learn from the incident so you come back stronger.
Read together, these six Functions describe the full lifecycle of managing cyber risk, from setting direction to bouncing back. The addition of GOVERN is the most important change in 2.0, because it puts strategy and accountability at the centre, which is exactly where most SMEs are weakest.
How the Structure Fits Together
Underneath the Functions, the framework drills down in a simple hierarchy: Functions contain Categories, and Categories contain Subcategories.
| Level | What it is | Example |
|---|---|---|
| Function | The highest-level outcome area | PROTECT |
| Category | A group of related outcomes within a Function | Identity management and access control |
| Subcategory | A specific, measurable outcome | Access permissions are managed on least-privilege principles |
You do not need to memorise every Subcategory. The point is that the structure lets you move from a boardroom-level conversation about six Functions down to a concrete, checkable outcome, all within the same framework. That traceability is what makes it so useful for reporting up and delegating down.
Implementation Tiers: How Rigorous Are You?
The framework also offers Implementation Tiers, which describe the rigour and maturity of your approach to managing cyber risk. There are four, running from Tier 1 to Tier 4.
- Tier 1, Partial. Risk is managed in an ad hoc, reactive way, with little organisation-wide awareness.
- Tier 2, Risk Informed. There is some awareness and some process, but it is not consistent across the business.
- Tier 3, Repeatable. Practices are formally approved, consistent and regularly updated.
- Tier 4, Adaptive. The organisation actively improves, learning from incidents and adapting to a changing threat landscape.
Tiers are not grades to chase for their own sake. A small, low-risk business may be perfectly comfortable operating at Tier 2 in some areas. The value is in choosing the tier that matches your risk appetite and then being honest about where you actually sit today.
Profiles: The Current Versus Target Trick
This is where the framework becomes genuinely practical for an SME. A Profile is simply a snapshot of which outcomes you are achieving. You build two of them.
Your Current Profile records where you stand right now across the Functions and Categories. Your Target Profile records where you want, or need, to be, given your risks, obligations and resources. The gap between the two is your improvement plan, ready made.
In practice an SME would work through it like this. First, assess your Current Profile honestly, marking each area as strong, partial or absent. Second, set a realistic Target Profile, informed by your sector, your customers and any regulations that apply to you. Third, list the gaps and prioritise them by risk and effort, tackling the high-risk, low-effort items first. That single exercise turns a vague sense of "we should probably improve our security" into a costed, sequenced roadmap you can put in front of a board.
Where NIST CSF 2.0 Fits Alongside ISO 27001
A common question is whether adopting the NIST Cybersecurity Framework means abandoning ISO 27001, or vice versa. It does not. They do different jobs and work well together.
The framework is a flexible, voluntary backbone for organising and prioritising your programme. ISO 27001 is a certifiable standard you can be formally audited against, which customers and tenders increasingly demand. Many SMEs use NIST CSF 2.0 first to get their bearings and build a coherent programme, then pursue ISO 27001 certification when the business case appears. Because the framework maps cleanly to other standards, the work you do organising around its six Functions is rarely wasted. It becomes the scaffolding for whatever certifiable standard you adopt next.
Common Mistakes
- Treating it as a certification to pass. It is voluntary guidance. Chasing a nonexistent certificate misses the point and wastes effort.
- Skipping GOVERN. The temptation is to jump straight to tools under PROTECT and DETECT. Without governance, ownership and strategy, those tools drift and decay.
- Aiming for Tier 4 everywhere. Maturity should match risk. Over-investing in low-risk areas starves the areas that actually matter.
- Building a Current Profile and never a Target. Assessing where you are is only half the exercise. Without a Target Profile you have a report, not a plan.
- Doing it once and filing it away. Profiles and tiers should be revisited as your business and the threat landscape change.
How ShieldIQ Helps NIST CSF 2.0
ShieldIQ walks you through the NIST Cybersecurity Framework in plain language, letting you assess your Current Profile across all six Functions and set a realistic Target Profile without needing to decode the full standard yourself. Because the platform maps NIST CSF 2.0 to other frameworks like ISO 27001 and NIS2, the answers you give once are reused everywhere, so your CSF backbone becomes the foundation for whatever certifiable standard you pursue next. You get a prioritised, board-ready roadmap instead of a spreadsheet nobody opens.
Run a free NIST CSF 2.0 assessment to see where you stand โ