What NIST changed in CSF 2.0
NIST published Cybersecurity Framework 2.0 on February 26, 2024, superseding CSF 1.1 (April 2018) in the framework's first major revision since its 2014 origin.
The changes that matter most for state agencies:
A new Govern function (GV). CSF 2.0 introduces Govern as a sixth function that frames the other five. It covers organizational context, risk management strategy, roles and responsibilities, policy, oversight, and supply chain risk management. In CSF 1.1, these topics were scattered across the Identify function or not addressed explicitly. Govern makes them first-class requirements.
Supply chain risk management elevated. The Govern function makes third-party cybersecurity risk management a standalone category (GV.SC). For states that run Medicaid systems, benefits platforms, ERP, or managed security services on third-party infrastructure, this surfaces a documentation obligation most state contracts don't currently satisfy.
Broader stated audience. CSF 1.1 positioned itself as guidance for critical infrastructure. CSF 2.0 explicitly addresses all organizations of any size and sector, including government, and updated its implementation examples accordingly.
What the Govern function actually requires state agencies to demonstrate
CSF 2.0's Govern function has six categories. Each names a set of outcomes — not controls, but evidence of organizational capability.
GV.OC — Organizational Context
Document the organization's mission, stakeholder expectations, legal and regulatory obligations, and how cybersecurity risk fits the overall enterprise risk posture. For a state agency, this means a current written alignment between the cybersecurity program and the agency's statutory obligations — relevant state statutes, any FISMA-equivalent state law, federal program requirements that carry security conditions (Medicaid, UI, FTI, SNAP) — and the state CISO's documented authority to act on them.
The gap that surfaces here: agencies frequently reference NIST 800-53 as their control baseline without documenting which federal program obligations drive that requirement, what state law governs the agency's security posture independently, or how the CISO's authority is scoped relative to agency IT directors.
GV.RM — Risk Management Strategy
Document the organization's risk appetite, risk tolerance thresholds, and how cybersecurity risk decisions connect to those thresholds. "We follow NIST 800-53 Moderate" is a control baseline, not a risk management strategy. The Govern function asks: who can formally accept residual risk in a specific system category, at what level, and based on what documented evidence?
This is the Govern category where most state agencies have the largest gap. Risk acceptance happens informally — a patch is deferred because a legacy system can't be taken offline, an encryption standard isn't met because a vendor's migration is pending — without documented approval at the appropriate authority level. CSF 2.0 asks for a structure that makes those decisions visible and auditable.
GV.RR — Roles, Responsibilities, and Authorities
Document who owns cybersecurity decisions, who executes them, and who holds authority to accept or escalate risk. The state CIO, CISO, agency heads, and oversight bodies — legislature's IT oversight committee, governor's office, state auditor — each play distinct roles. CSF 2.0 expects that structure to be written down, not reconstructed from memory when an incident occurs.
GV.PO — Policy
Cybersecurity policies must be current, documented, and approved by organizational leadership. For states, this category frequently reveals policies last reviewed three or more years ago, agency-level policies that conflict with updated state-level policy, or policies that reference deprecated standards.
A practical indicator: if the agency's written policy still cites CSF 1.1 as the baseline in October 2026, GV.PO is almost certainly not met at Tier 2 (Risk-Informed) or above.
GV.OV — Oversight
Organizational leadership reviews cybersecurity program performance, receives metrics, and formally acts on findings. For a state CISO, this means evidence — not just activity — that the annual security report reaches appropriate decision-makers and that findings produce documented responses.
Many state CISOs file excellent annual assessments that don't receive formal responses from leadership. GV.OV asks for the closed loop: review, response, and documentation that leadership has seen and acted on what the assessment found.
GV.SC — Cybersecurity Supply Chain Risk Management
Supplier cybersecurity requirements, contract obligations, and monitoring practices are in place for systems and services that affect the agency's cybersecurity posture. This is where GovRAMP and StateRAMP procurement requirements interact with the framework — and where the limits of procurement-side authorization become visible.
A GovRAMP High authorization demonstrates that a cloud product met a specific control baseline at authorization time. GV.SC also requires ongoing monitoring, contract language that establishes security obligations, and a defined process for responding to supplier incidents or changes in security posture. Requiring GovRAMP High at procurement without documented post-contract monitoring meets the entry condition for GV.SC but not its ongoing requirements.
The documentation gap this surfaces in state programs
State cybersecurity programs have focused largely on controls: what is deployed, whether vulnerability scans run, whether patch cycles are met. NIST CSF 1.1 supported that approach — the five original functions map naturally to technical and operational capabilities.
The Govern function asks for something different: evidence that risk decisions are made deliberately, documented at the appropriate authority level, and reviewed regularly by leadership. A state agency can have a mature technical security posture and a weak Govern profile at the same time.
Common gaps that appear when agencies attempt to document GV.RM's risk management strategy:
- No formal risk appetite statement. Many state IT programs operate with an informal shared understanding of acceptable risk rather than a leadership-approved written threshold. "We try to patch within 30 days of critical CVE publication" is a target, not a risk appetite statement. A documented threshold specifying which system categories require zero residual risk above a defined severity and which permit time-limited exceptions, under what approval conditions, is.
- Undocumented risk acceptance decisions. Exceptions to security standards — deferred patches, legacy systems below encryption minimums, unsupported OS still in production — are common in state environments. When those exceptions lack formal documentation of who approved them and under what conditions, GV.RM has a gap regardless of how technically reasonable the deferral was.
- Isolated cybersecurity metrics. Many state CISOs track technical metrics (patch compliance rate, mean time to detect, vulnerability aging) but don't have a regular, documented cycle where leadership receives those metrics and formally records a response. GV.OV requires the closed loop.
- Inherited supplier dependencies without documented governance. A statewide benefits platform running on infrastructure from a vendor whose last security attestation was never reviewed, managed under a master services agreement that contains no cybersecurity requirements — GV.SC asks for documented supplier oversight, not just an active contract.
Using CSF 2.0 as a gap-assessment tool
NIST provides an Organizational Profile structure in CSF 2.0: agencies document their current profile (what they do now) and a target profile (what they want to achieve), then identify and prioritize gaps. The framework offers four implementation tiers (Partial, Risk-Informed, Repeatable, Adaptive) for each function.
A practical starting point for state agencies that need to update a CSF 1.1 baseline:
- Map existing artifacts to Govern categories. What does the agency have that already addresses each GV category? Risk management strategy elements may exist in capital planning or enterprise risk management documents; roles and responsibilities may appear in IT governance policies, delegation orders, or position descriptions; supply chain practices may live in existing contract templates. Document what exists before concluding nothing does.
- Distinguish documentation gaps from capability gaps. Some Govern gaps represent missing documentation of practices that already exist. Others represent actual absent capabilities. The two require different remediation paths: documentation gaps can close quickly with directed staff effort; capability gaps require program investment and budget justification.
- Establish a policy review cycle. GV.PO requires current, leadership-approved policies. For many state agencies, establishing a two-year policy review cycle with documented approval authority would move the agency from Tier 1 (Partial) to Tier 2 (Risk-Informed) in the Govern function with no new technical investment.
- Add a governance agenda item to CISO reporting cycles. If cybersecurity metrics reach leadership but produce no formal documented response, GV.OV is only partially met. A simple action register — noting which findings were accepted, which were assigned remediation, and by whom — closes the documented loop.
- Inventory active supplier relationships against GV.SC requirements. Which systems involve third-party suppliers? Do those contracts contain documented security obligations? Is there an assigned owner for monitoring supplier security posture changes? For states using cooperative contracts or statewide enterprise agreements, monitoring responsibility is frequently unassigned after procurement closes.
What the CSF 2.0 profile exercise actually takes
NIST provides a reference implementation for CSF 2.0 with outcome-level implementation examples. A state agency completing an initial current profile against the Govern function should expect — as a practitioner estimate, not a published benchmark:
- 3–5 days of structured review for an experienced analyst working through existing governance artifacts
- Involvement from legal or general counsel to confirm the regulatory obligation inventory (GV.OC)
- IT security leadership to document risk appetite thresholds (GV.RM)
- A governance-level sign-off mechanism for oversight documentation (GV.OV) — whatever the state's equivalent of a formal IT policy board or cabinet-level review
This is a documentation and governance exercise, not a security implementation project. The implementation investment comes when documented gaps are prioritized for remediation and sequenced into the security program budget.
The connection to AI governance
The Govern function's requirements — documented risk appetite, authority matrices, supplier oversight practices, regular leadership review cycles — are the same organizational infrastructure that effective AI governance requires. A state agency building the documented decision-making structure for CSF 2.0 Govern compliance is building most of what an AI risk management program under NIST AI RMF 1.0 also needs. The AI RMF's Govern function is structurally parallel: it asks who owns AI risk decisions, how they're escalated, and how strategy connects to operational practices. State agencies working toward CSF 2.0 Govern compliance can address both simultaneously rather than running parallel governance documentation efforts.
Sources and further reading
- NIST Cybersecurity Framework 2.0, NIST, February 26, 2024
- CSF 2.0 Core with implementation examples, NIST — the publication page links to the xlsx Core with all outcomes, implementation examples, and informative references by subcategory
- NIST IR 8286C: Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight, NIST, September 14, 2022 — enterprise risk management companion to CSF, covers risk appetite documentation
- CISA NIST CSF 2.0 Resources, CISA — implementation guidance and SLTT-specific resources
- MS-ISAC Cybersecurity Framework Resources, CIS / Multi-State Information Sharing and Analysis Center
Spartan X's advisory work in state AI and cybersecurity strategy addresses the governance layer that both CSF 2.0 and AI risk frameworks require: documented decision authority, risk appetite alignment, and leadership oversight structures. The Govern function documentation exercise is, in practice, the same foundation that makes subsequent AI deployment and security program investments accountable.



