TrustPoint

NIST Cybersecurity Framework 2.0

A voluntary, outcome-based framework that is most useful in the Gulf as a common language: the vocabulary you translate between a regulator control set and an international standard.

Publisher
NIST, United States
Version
2.0
Country
United States
Availability
Planned

What the framework is

The Cybersecurity Framework is published by the National Institute of Standards and Technology in the United States. It is voluntary and outcome-based: rather than prescribing controls, it describes cybersecurity outcomes organised into functions, categories and subcategories, and leaves the choice of control to you.

Version 2.0, published in 2024, made two significant changes. It added Govern as a function alongside the existing Identify, Protect, Detect, Respond and Recover, elevating governance, roles, policy and supply-chain risk from something implied to something explicit. And it widened the framework’s stated audience beyond critical infrastructure to organizations of any size or sector.

Why it matters in the Gulf

Very few organizations in the region are required to adopt the CSF. Its value here is different: it is an unusually good translation layer.

A GCC organization typically runs a national control set, an international management-system standard, and a sector framework. Those three describe the same underlying practice in three vocabularies. Because the CSF is outcome-based rather than control-based, it maps cleanly onto all of them, which makes it a useful spine for reasoning about coverage across the set.

It is also the vocabulary an international board, a group parent or a cyber insurer is most likely to already speak, which makes it a practical way to report a Gulf programme upward without re-explaining the local framework each time.

How TrustPoint supports it

NIST CSF 2.0 is planned for the TrustPoint library and is not available yet.

Once it is available, it will be assessed like any other framework in the platform: requirement by requirement, with evidence from the managed store, gaps carried onto a roadmap and results readable through the audience report templates or the OData feed.

Because Govern is now an explicit function, the Governance module carries more of the CSF than it did under version 1.1. The org tree, the perimeters, the policy lifecycle and the attestation records are the evidence for a meaningful part of that function.

What it maps to, and what that saves

The CSF is often used as a common vocabulary across ISO/IEC 27001, NCA ECC, CBO CS&RF and PCI DSS. TrustPoint does not yet include mapping sets between NIST CSF and those frameworks.

When mapping sets exist, each relationship is recorded (equal, subset, superset, intersecting or related) and suggestions are surfaced for review rather than applied silently. An outcome-based framework maps to a control-based one imperfectly by nature, and pretending otherwise is how a mapping saving turns into an audit finding.

Common questions

Is NIST CSF 2.0 available in TrustPoint?

Not yet. NIST CSF 2.0 is planned. The core library currently includes NCA ECC-1:2018, CBO CS&RF 2023, ISO/IEC 27001:2022, ISO/IEC 27002:2022 reference controls, standard risk matrices and the NCA ECC to ISO/IEC 27001:2022 mapping set.

How will it reach an air-gapped site?

The same way as other library content: packs are Ed25519-signed and versioned. Connected sites sync them daily; air-gapped sites install the same signed pack by manual upload, and the signature is verified before anything is installed.

Should we adopt the CSF if our regulator asks for NCA ECC?

Your regulator’s control set is the obligation; the CSF is not. Organizations usually add it because it gives them one vocabulary for reasoning across several frameworks and one shape for reporting upward. If neither of those is a problem you have, you do not need it.

What did version 2.0 change for an existing programme?

Most significantly it added the Govern function, which makes governance, roles, policy and supply-chain risk explicit rather than implied. For a programme built on version 1.1, the main new work is covering Govern. TrustPoint does not include CSF 1.1 or 2.0 today.

Commonly mapped to

Ask us about NIST CSF 2.0 availability.

A 45-minute working session focused on the frameworks and requirements that matter to your organization.