What NIST CSF 2.0 is and how it applies to OT environments
The NIST Cybersecurity Framework (CSF) 2.0, published by the National Institute of Standards and Technology in 2024, is a voluntary framework that organises cyber risk management into six functions: Govern, Identify, Protect, Detect, Respond, Recover. Born in the United States, it is today an international reference standard.
The novelty of version 2.0 is the Govern function, which elevates cybersecurity to a corporate governance topic: policies, roles, responsibilities and risk oversight become an explicit prerequisite for the other five operational functions.
Unlike NIS2 or the CRA, NIST CSF is not a legal obligation in the EU, but it is widely required in enterprise contracts, supply-chain due diligence and cyber insurance policies, and is often used as a reference framework to structure OT/ICS security programmes.
For industrial environments, the CSF provides a common language between IT and OT: it lets you map asset inventory, vulnerability management, detection and incident response capabilities onto the six functions, and build a prioritised maturity roadmap.
NIST CSF 2.0
NIST Cybersecurity Framework 2.0
Voluntary NIST framework adopted globally as a common language to describe cybersecurity maturity and capabilities. Version 2.0 (2024) introduces the GOVERN function and extends coverage to all organisations - not only US critical infrastructure.
- 01GOVERN: governance, risk strategy, roles and responsibilities
- 02IDENTIFY: asset management, business environment, risk assessment
- 03PROTECT: access control, data security, protective technology
- 04DETECT: anomalies, continuous monitoring, detection processes
- 05RESPOND + RECOVER: planning, communications, mitigation, recovery
MON5 directly covers the IDENTIFY (asset management, communications, vulnerability identification) and DETECT (anomaly detection, continuous monitoring) functions on the OT perimeter. The evidence produced supports GOVERN (management reporting) and RESPOND (event correlation, EPSS-driven prioritisation).
- →ID.AM - Asset Management on the OT network
- →ID.RA - Risk Assessment based on CVE + EPSS
- →DE.CM - Continuous monitoring of industrial traffic
- →DE.AE - Real-time anomaly detection
- →Dashboards and reports supporting GOVERN and RESPOND
- Govern (GV)
- Function introduced in version 2.0: establishes strategy, policy, roles and risk oversight at the organisational level, as a prerequisite for the other functions.
- Identify (ID)
- Function covering the understanding of risk context: inventory of assets, data, systems and vulnerability assessment.
- Protect (PR)
- Function covering safeguard measures: access control, training, data protection, maintenance, segmentation.
- Detect (DE)
- Function covering the timely identification of anomalous events and potential security incidents.
- Respond (RS)
- Function covering the actions to take following a detected incident: containment, communication, mitigation.
- Recover (RC)
- Function covering the restoration of capabilities and services impaired by an incident, and the lessons learned to strengthen resilience.
Is NIST CSF 2.0 mandatory for European companies?+
No, NIST CSF is a voluntary US framework, but it is recognised as an international best practice and is frequently required by enterprise customers, cyber insurers and global supply chain contracts.
How does MON5 map to the six NIST CSF 2.0 functions?+
MON5 covers GOVERN (risk oversight and policies), IDENTIFY (asset inventory and CVE/EPSS risk assessment), PROTECT (segmentation), DETECT (anomaly detection) and RESPOND (alerting and incident logs).
What did NIST CSF 2.0 change compared to version 1.1?+
NIST CSF 2.0 added the GOVERN function, which introduces cybersecurity governance, roles, responsibilities and risk oversight as a prerequisite to the other five operational functions.
Does NIST CSF 2.0 replace ISO 27001 or IEC 62443?+
No, they are complementary and often used together: the CSF provides a high-level structure to organise the security programme, ISO 27001 provides a certifiable management system, and IEC 62443 gives specific technical requirements for industrial control systems.
Where do you start applying NIST CSF 2.0 in an OT environment?+
Typically with a self-assessment across the six functions to identify the "current profile" and define a "target profile"; for most industrial companies the initial weak point is Identify, due to the lack of an up-to-date OT asset inventory.
Does NIST CSF 2.0 require certification?+
No, unlike ISO 27001 the CSF does not involve formal third-party certification; it is a self-assessment and risk-communication framework, often used to report cyber maturity to the board and to customers.
How is maturity measured against NIST CSF 2.0?+
Through implementation "tiers" (from Partial to Adaptive) that describe how formalised, repeatable and embedded in organisational culture the risk-management processes are: a qualitative profile per function, not just a score.
Which NIST CSF 2.0 functions does MON5 help cover?+
MON5 provides direct evidence for Identify (asset inventory, CVE/EPSS risk assessment), Detect (anomaly detection) and partially Protect (segmentation data); the Govern, Respond and Recover functions remain complementary organisational activities.
Let's figure out what you really need.
Show us the OT perimeter and the regulations you need to cover: we will tell you what MON5 documents directly, where complementary work is needed, and which tier to start from - no hard selling.