Compliance & Regulations/Cross-jurisdictional/NIST CSF
ISO / Cross-jurisdiction · Global — voluntary

NIST CSF 2.0

The NIST Cybersecurity Framework version 2.0 — six functions (Govern, Identify, Protect, Detect, Respond, Recover) with broad global adoption.

Regulator
National Institute of Standards and Technology
Jurisdiction
Global — voluntary
Status
Active — version 2.0 released February 2024.
In force since
Active
Regulator's source
Who it applies to

Voluntary for any organisation.

Audit / certification status

Continuous evidence pipeline available; audit support included for all customers.

What it requires

What NIST CSF actually requires.

These are the obligations a regulated entity owes — the things an assessor or supervisor will ask about.

01

Six functions: Govern, Identify, Protect, Detect, Respond, Recover.

02

Implementation tiers and target profiles.

How Safeguard maps to it

Pre-mapped controls. Continuous evidence.

Each requirement above is bound to live telemetry — not screenshots. The mapping below is what your auditor or regulator sees.

CSF 2.0 profile builder with subcategory-level evidence.

Crosswalks to ISO 27001, SOC 2, and PCI-DSS.

Evidence we produce

Artifacts your auditor accepts.

Each evidence artifact is signed and timestamped. Auditors can verify integrity without trusting Safeguard.

Current and target profile comparison.

Per-subcategory evidence binding.

Ready for NIST CSF?

Bring the framework. We'll walk the controls with you — section by section, evidence packet by evidence packet, with the regulators you actually have to answer to.

Safeguard | Software Supply Chain Security Platform | Zero CVE + Self-Healing