NIST CSF 2.0: the common language of your security programme

The NIST Cybersecurity Framework is the most widely used way to structure and communicate a security programme. CSF 2.0 (February 2024) organises it into six functions — Govern, Identify, Protect, Detect, Respond, Recover — with Govern newly promoted to reflect what regulators everywhere now demand: cybersecurity as a board-owned discipline.

An honest framing first: CSF is voluntary and American, published by the US National Institute of Standards and Technology. In Europe it will not, by itself, discharge a legal obligation. What it does brilliantly is act as a lingua franca — the structure into which one control set is organised so it can serve NIS2, ISO 27001, SOC 2 and customer questionnaires at once.

How we use CSF

  1. Current and target profiles (expert-led). We assess your posture across the six functions and agree a target profile with your board — a readable, defensible statement of where you are going and why.
  2. Control mapping. Each CSF outcome is mapped to the concrete controls you run — and from there to the frameworks that legally or contractually bind you. NIST's own informative references and our NIS2/ISO mappings do the heavy lifting; see the compliance hub for the model.
  3. Continuous evidence (AI-led). The platform verifies the technological controls with deterministic rules and files evidence against the profile; an RAS expert counter-signs every cycle. Your CSF profile stops being a slide and becomes a live, evidenced picture.
  4. Board reporting. Progress against the target profile, in the Govern-first language CSF 2.0 was redesigned for — which is also the language of NIS2 management accountability.

For organisations with US federal exposure we also work against NIST SP 800-53 and SP 800-171 control catalogues, using the same mapping discipline.

Why RASDefense

RASDefense is the cybersecurity arm of RAS Institute, vetted through competitive EU procurement to hold three framework contracts with ENISA, the European Union Agency for Cybersecurity — a benchmark of methodological rigour, not an endorsement. Framework mapping and evidence discipline are exactly the analytical work that vetting tested. We apply it to your programme with EU-grade, GDPR-aligned data protection.

FAQ

Is the NIST Cybersecurity Framework mandatory in the EU?

No. NIST CSF is a voluntary framework published by the US National Institute of Standards and Technology. In Europe it is used as a common structure for security programmes and board reporting, while the binding obligations come from laws like NIS2 and national transpositions.

What changed in NIST CSF 2.0?

CSF 2.0, published in February 2024, added Govern as a sixth function alongside Identify, Protect, Detect, Respond and Recover, extended the framework's scope beyond critical infrastructure to all organisations, and put much more weight on governance and supply-chain risk — moves that align it closely with NIS2's management accountability.

Why use NIST CSF if I must comply with NIS2 anyway?

Because it is the clearest common language for organising one control set that must satisfy several obligations. A CSF profile gives the board a readable picture of posture and progress, while the underlying controls and evidence satisfy NIS2, ISO 27001 and SOC 2 simultaneously.

Make your compliance defensible.

Tell us where you are on the journey — we'll show you the fastest credible route to readiness, built on an EU-vetted methodology and agentic AI.

Email us