NIST CSF 2.0 compliance, mapped and measured.
NIST CSF 2.0 is a voluntary cybersecurity framework built around six Functions — Govern, Identify, Protect, Detect, Respond, Recover — used by organisations worldwide to structure a risk-based security programme. grComply seeds the full NIST.CSWP.29 Core as a comprehensive, audit-ready control library: 6 Functions, 22 Categories, and 106 Subcategories, each tracked to a live completion status rather than a static profile spreadsheet. Findings from grComply's own scanning feed Detect and Protect directly, and the same evidence can credit ISO 27001, SOC 2, or CIS Controls at once.
What is NIST CSF 2.0? The NIST Cybersecurity Framework 2.0 is a voluntary, outcome-based framework from the US National Institute of Standards and Technology, organising cybersecurity risk management into six Functions — Govern, Identify, Protect, Detect, Respond, and Recover. It's framework-agnostic by design, which is why it maps cleanly onto ISO 27001, SOC 2, and CIS Controls rather than competing with them.
How grComply benefits your NIST CSF 2.0 programme
All six Functions in one live tree
GV, ID, PR, DE, RS, and RC sit as the domain layer; 22 Categories and 106 Subcategories track to completion, not a Profile spreadsheet someone updates once a year.
Findings map straight into Detect & Protect
External and internal scanning auto-maps CVE-enriched findings into the relevant DE/PR Subcategory, with a confidence score a human confirms.
Risk register feeds Govern & Identify
GV.RM and ID.RA populate from the same configurable risk register grComply runs platform-wide — not a separate CSF-only spreadsheet.
One control satisfies CSF and ISO/SOC 2 together
Cross-framework mapping means a single implemented control credits NIST CSF plus any other adopted standard, evidence uploaded once.
Respond & Recover backed by audit-grade workflow
The same observation, response, and peer-review discipline grComply applies everywhere gives RS/RC evidence a defensible trail, not a tabletop-exercise slide.
AI-drafted narratives, human-confirmed
A BYOK assistant drafts CSF outcome narratives against your own control text; nothing publishes without a human decision.
All six Functions, seeded as a live control tree
Each Function below is seeded from NIST.CSWP.29 — not a paraphrase — down to Category level, with real Subcategory outcome statements underneath.
Govern (GV)
Establish, communicate, and monitor the organisation's cybersecurity risk management strategy, expectations, and policy — the Function CSF 2.0 added to make governance a first-class outcome rather than an implied prerequisite.
Identify (ID)
Determine the organisation's current cybersecurity risks — asset inventory, risk assessment, and improvement planning, populated from the same configurable risk register grComply runs for every other framework.
Protect (PR)
Safeguards to manage cybersecurity risk — identity management, awareness and training, data security, and platform resilience, with the training module able to close PR-series awareness outcomes directly.
Detect (DE)
Find and analyse possible attacks and compromises — the Function grComply's scanning feeds directly, with CVE-enriched findings auto-mapped to the relevant Category.
Respond (RS)
Take action on a detected incident — managed through the same auditor-observation and structured-workflow discipline grComply applies to every other framework's incident-adjacent controls.
Recover (RC)
Restore assets and operations affected by an incident — recovery planning and improvement evidence versioned and dated, not a one-off disaster-recovery PDF.
Evidence grComply already models for NIST CSF 2.0
Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.
| Control | Evidence type | Example |
|---|---|---|
| GV.RM — Risk Management Strategy | Risk register export | Configurable risk register entry with likelihood/impact scoring and treatment plan |
| DE.CM — Continuous Monitoring | Vulnerability scan report | External/internal scan results enriched with NVD, OSV, and CISA KEV context |
| PR.AT — Awareness and Training | Training completion attestation | Compliance-mapped course completion record from the training module |
| ID.AM — Asset Management | Asset inventory export | CMDB or scan-derived asset inventory tied to the Identify function |
| RS.MA — Incident Management | Observation/response record | Structured auditor-observation workflow entry with a full timeline |
Why this matters: NIST CSF 2.0's six Functions are deliberately generic enough to sit above almost any other standard — which is exactly why grComply's cross-framework mapping lets one implemented control (an access-control policy, say) credit CSF's PR.AA, ISO 27001's A.8.2, and SOC 2's CC6.1 all from a single piece of evidence.
NIST CSF 2.0, in the live workspace
The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to NIST CSF 2.0.






NIST CSF 2.0 in grComply
What is NIST CSF 2.0?
NIST CSF 2.0 is a voluntary, outcome-based cybersecurity framework organised into six Functions — Govern, Identify, Protect, Detect, Respond, and Recover. It's widely used as a common language for cybersecurity risk management and often mapped onto more prescriptive standards like ISO 27001 or SOC 2.
Does grComply support the full NIST CSF 2.0 Core?
Yes — grComply seeds the complete Core from NIST.CSWP.29: 6 Functions, 22 Categories, and 106 Subcategories, marked as a comprehensive, audit-ready library rather than a condensed structural seed.
Can NIST CSF evidence also satisfy ISO 27001 or SOC 2?
Where the underlying control is genuinely equivalent, yes. Cross-framework mapping is data, not code, so a single control can be marked equivalent to nodes in ISO 27001, SOC 2, and CIS Controls, and evidence uploaded once counts everywhere it applies.
How does scanning feed the Detect function?
External and internal vulnerability scanning produces CVE-enriched findings that auto-map, with a confidence score, to the relevant Detect or Protect Subcategory — a human confirms or reassigns the mapping before it counts as evidence.
Is NIST CSF 2.0 the same as NIST 800-53?
No. CSF 2.0 is a high-level, outcome-based framework; NIST SP 800-53 is a detailed control catalog behind FedRAMP and most US federal system authorisations. grComply can load 800-53 as an additional framework via import if a programme needs both.
What's new in CSF 2.0 versus CSF 1.1?
CSF 2.0 added Govern as a sixth Function, elevating governance, risk strategy, and supply-chain risk management to the same first-class status as the original five Functions — grComply's seed reflects this 2.0 structure.
Does grComply support NIST CSF organisational Profiles?
The seeded Core provides the full Function/Category/Subcategory outcome statements a Profile is built from; tenant-specific scoping — which Subcategories apply, target vs current state — uses the same N/A and exemption logic grComply applies to any framework.
Can we run NIST CSF 2.0 alongside a regional framework?
Yes. A tenant can be assigned NIST CSF 2.0 plus any other seeded or imported framework, tracked to its own completion status or bundled into a mapping-set profile. See the full catalog on the Compliance Frameworks page.
See NIST CSF 2.0 mapped into your control library
Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →
Talk to us about NIST CSF 2.0
Tell us where your NIST CSF 2.0 programme stands today, and we'll route it to the right product specialist.
- A product specialist replies personally — not a bot
- No obligation after the first conversation
- WhatsApp support also available 24/7
By submitting, you agree to be contacted about your enquiry. We respect your privacy.
Book a meeting directly
Pick a time that works for you — 30 minutes with a product specialist, no sales script.
Ready to bring NIST CSF 2.0 into one control library?
We respond within one working day — or reach us instantly on WhatsApp.