
- 01Govern is the sixth core function, sitting at the center of Identify / Protect / Detect / Respond / Recover. It formalizes what mature programs already did informally — strategy, accountability, risk appetite.
- 02Six categories under Govern: Organizational Context, Risk Management Strategy, Roles & Responsibilities, Policy, Oversight, and Cybersecurity Supply Chain Risk Management (C-SCRM).
- 03C-SCRM is now a first-class concern. For organizations with 60–80% of IT in SaaS, this is the most consequential paragraph in the framework.
- 04Maintain ONE 'risk register of record' that ties each significant risk to both an ISO 27001:2022 control and a CSF 2.0 sub-category. Dual-framework reporting burden drops 40–60%.
When NIST released CSF 2.0 in February 2024, the headline change was the addition of a sixth core function: Govern. Sitting at the center of Identify, Protect, Detect, Respond, and Recover, Govern formalizes what mature programs already did informally — set the strategy, accountability, and risk appetite that shape every other function.
What lives inside Govern
Govern contains six categories: Organizational Context, Risk Management Strategy, Roles, Responsibilities and Authorities, Policy, Oversight, and Cybersecurity Supply Chain Risk Management. Together they answer the questions a board should be asking quarterly.
- 01Who owns cybersecurity risk at the C-suite, and is that documented?
- 02What is our written risk appetite — quantified, not adjectival?
- 03Where are we exposed in our software and service supply chain?
- 04How do we prove the program is improving against KPIs, not feelings?
The supply-chain mandate
CSF 2.0 made cybersecurity supply chain risk management (C-SCRM) a first-class concern. Sub-categories now require contractually bound cybersecurity requirements, supplier due diligence proportional to criticality, and documented incident notification timelines from suppliers.
For organizations that have outsourced 60–80% of their IT footprint to SaaS, this is the most consequential paragraph in the framework.
Mapping CSF 2.0 to your current program
If you operate against ISO/IEC 27001:2022, the CSF 2.0 informative references give you a defensible mapping for board reporting. We recommend a single 'risk register of record' that ties each significant risk to both an ISO control and a CSF 2.0 sub-category — this collapses the dual-framework reporting burden by 40–60%.


