⚡ Every Mutex Systems product starts at £0 — create an account and go live today. See pricing →
grComply Compliance Frameworks Security Awareness Training TiLedger FlowChat Pricing Partners Resources About Reviews Contact Sign in to grComply Sign in to TiLedger Sign in to FlowChat
grComply framework · Cybersecurity framework

NIST CSF 2.0 compliance, mapped and measured.

NIST CSF 2.0 is a voluntary cybersecurity framework built around six Functions — Govern, Identify, Protect, Detect, Respond, Recover — used by organisations worldwide to structure a risk-based security programme. grComply seeds the full NIST.CSWP.29 Core as a comprehensive, audit-ready control library: 6 Functions, 22 Categories, and 106 Subcategories, each tracked to a live completion status rather than a static profile spreadsheet. Findings from grComply's own scanning feed Detect and Protect directly, and the same evidence can credit ISO 27001, SOC 2, or CIS Controls at once.

6 Functions · 22 Categories · 106 Subcategories — the full NIST.CSWP.29 Core, seeded and live.
Back to all frameworks WhatsApp us
6Functions (Govern → Recover)
22Categories
106Subcategories
ComprehensiveSeed depth

What is NIST CSF 2.0? The NIST Cybersecurity Framework 2.0 is a voluntary, outcome-based framework from the US National Institute of Standards and Technology, organising cybersecurity risk management into six Functions — Govern, Identify, Protect, Detect, Respond, and Recover. It's framework-agnostic by design, which is why it maps cleanly onto ISO 27001, SOC 2, and CIS Controls rather than competing with them.

Why it's different

How grComply benefits your NIST CSF 2.0 programme

All six Functions in one live tree

GV, ID, PR, DE, RS, and RC sit as the domain layer; 22 Categories and 106 Subcategories track to completion, not a Profile spreadsheet someone updates once a year.

Findings map straight into Detect & Protect

External and internal scanning auto-maps CVE-enriched findings into the relevant DE/PR Subcategory, with a confidence score a human confirms.

Risk register feeds Govern & Identify

GV.RM and ID.RA populate from the same configurable risk register grComply runs platform-wide — not a separate CSF-only spreadsheet.

One control satisfies CSF and ISO/SOC 2 together

Cross-framework mapping means a single implemented control credits NIST CSF plus any other adopted standard, evidence uploaded once.

Respond & Recover backed by audit-grade workflow

The same observation, response, and peer-review discipline grComply applies everywhere gives RS/RC evidence a defensible trail, not a tabletop-exercise slide.

AI-drafted narratives, human-confirmed

A BYOK assistant drafts CSF outcome narratives against your own control text; nothing publishes without a human decision.

Structure

All six Functions, seeded as a live control tree

Each Function below is seeded from NIST.CSWP.29 — not a paraphrase — down to Category level, with real Subcategory outcome statements underneath.

Govern (GV)

Establish, communicate, and monitor the organisation's cybersecurity risk management strategy, expectations, and policy — the Function CSF 2.0 added to make governance a first-class outcome rather than an implied prerequisite.

Identify (ID)

Determine the organisation's current cybersecurity risks — asset inventory, risk assessment, and improvement planning, populated from the same configurable risk register grComply runs for every other framework.

Protect (PR)

Safeguards to manage cybersecurity risk — identity management, awareness and training, data security, and platform resilience, with the training module able to close PR-series awareness outcomes directly.

Detect (DE)

Find and analyse possible attacks and compromises — the Function grComply's scanning feeds directly, with CVE-enriched findings auto-mapped to the relevant Category.

Respond (RS)

Take action on a detected incident — managed through the same auditor-observation and structured-workflow discipline grComply applies to every other framework's incident-adjacent controls.

Recover (RC)

Restore assets and operations affected by an incident — recovery planning and improvement evidence versioned and dated, not a one-off disaster-recovery PDF.

Evidence, mapped

Evidence grComply already models for NIST CSF 2.0

Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.

ControlEvidence typeExample
GV.RM — Risk Management StrategyRisk register exportConfigurable risk register entry with likelihood/impact scoring and treatment plan
DE.CM — Continuous MonitoringVulnerability scan reportExternal/internal scan results enriched with NVD, OSV, and CISA KEV context
PR.AT — Awareness and TrainingTraining completion attestationCompliance-mapped course completion record from the training module
ID.AM — Asset ManagementAsset inventory exportCMDB or scan-derived asset inventory tied to the Identify function
RS.MA — Incident ManagementObservation/response recordStructured auditor-observation workflow entry with a full timeline

Why this matters: NIST CSF 2.0's six Functions are deliberately generic enough to sit above almost any other standard — which is exactly why grComply's cross-framework mapping lets one implemented control (an access-control policy, say) credit CSF's PR.AA, ISO 27001's A.8.2, and SOC 2's CC6.1 all from a single piece of evidence.

Product screens

NIST CSF 2.0, in the live workspace

The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to NIST CSF 2.0.

FAQ

NIST CSF 2.0 in grComply

What is NIST CSF 2.0?

NIST CSF 2.0 is a voluntary, outcome-based cybersecurity framework organised into six Functions — Govern, Identify, Protect, Detect, Respond, and Recover. It's widely used as a common language for cybersecurity risk management and often mapped onto more prescriptive standards like ISO 27001 or SOC 2.

Does grComply support the full NIST CSF 2.0 Core?

Yes — grComply seeds the complete Core from NIST.CSWP.29: 6 Functions, 22 Categories, and 106 Subcategories, marked as a comprehensive, audit-ready library rather than a condensed structural seed.

Can NIST CSF evidence also satisfy ISO 27001 or SOC 2?

Where the underlying control is genuinely equivalent, yes. Cross-framework mapping is data, not code, so a single control can be marked equivalent to nodes in ISO 27001, SOC 2, and CIS Controls, and evidence uploaded once counts everywhere it applies.

How does scanning feed the Detect function?

External and internal vulnerability scanning produces CVE-enriched findings that auto-map, with a confidence score, to the relevant Detect or Protect Subcategory — a human confirms or reassigns the mapping before it counts as evidence.

Is NIST CSF 2.0 the same as NIST 800-53?

No. CSF 2.0 is a high-level, outcome-based framework; NIST SP 800-53 is a detailed control catalog behind FedRAMP and most US federal system authorisations. grComply can load 800-53 as an additional framework via import if a programme needs both.

What's new in CSF 2.0 versus CSF 1.1?

CSF 2.0 added Govern as a sixth Function, elevating governance, risk strategy, and supply-chain risk management to the same first-class status as the original five Functions — grComply's seed reflects this 2.0 structure.

Does grComply support NIST CSF organisational Profiles?

The seeded Core provides the full Function/Category/Subcategory outcome statements a Profile is built from; tenant-specific scoping — which Subcategories apply, target vs current state — uses the same N/A and exemption logic grComply applies to any framework.

Can we run NIST CSF 2.0 alongside a regional framework?

Yes. A tenant can be assigned NIST CSF 2.0 plus any other seeded or imported framework, tracked to its own completion status or bundled into a mapping-set profile. See the full catalog on the Compliance Frameworks page.

See NIST CSF 2.0 mapped into your control library

Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →

Get in touch

Talk to us about NIST CSF 2.0

Tell us where your NIST CSF 2.0 programme stands today, and we'll route it to the right product specialist.

  • A product specialist replies personally — not a bot
  • No obligation after the first conversation
  • WhatsApp support also available 24/7

By submitting, you agree to be contacted about your enquiry. We respect your privacy.

Prefer to talk it through?

Book a meeting directly

Pick a time that works for you — 30 minutes with a product specialist, no sales script.

Ready to bring NIST CSF 2.0 into one control library?

We respond within one working day — or reach us instantly on WhatsApp.

WhatsApp us