The NIST CSF 2.0 Checklist
A NIST CSF 2.0 checklist turns the federal framework into a plain-English action list. It groups everything under six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Work through each section and you’ll know roughly where your business stands.
This is a working reference, not the complete official standard, which runs past 100 detailed subcategories. Think of this page as the version you’d actually hand to an IT person or a manager and expect them to use.
If you’re new to the framework itself, start with our plain-English guide to what NIST CSF 2.0 is first. This page assumes you already know the basics and just want the checklist.
Key Takeaways
- NIST CSF 2.0 has six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
- Govern is new to 2.0. It covers strategy, roles, policy, and oversight.
- The framework is voluntary. There’s no fine for skipping it and no official “certified” status to earn.
- Checking every box here doesn’t tell you how consistently you actually do these things. That’s what a real gap analysis is for.
- Small businesses have their own NIST-published starting guide, separate from the enterprise version.
How to Read This Checklist
Each function below has a short list of plain-English items. Work through the ones that apply to your business. If an item is already in place, check it off. If it’s missing or shaky, that’s a gap worth addressing.
NIST’s official CSF 2.0 core document organizes these functions into Categories and Subcategories with specific outcome language. This checklist simplifies that structure into items you can actually act on, without needing to parse federal document formatting first.
| Function | What it covers | Who typically owns it |
|---|---|---|
| Govern (GV) | Strategy, roles, policy, oversight | Leadership + IT |
| Identify (ID) | Asset inventory, risk register, vendor risk | IT / security lead |
| Protect (PR) | Access control, encryption, backups, training | IT / MSP |
| Detect (DE) | Monitoring, logging, alerting | IT / MSP |
| Respond (RS) | Incident response plan, communication plan | Leadership + IT |
| Recover (RC) | Tested restoration, recovery plan, review | IT / MSP |
Govern Checklist
Govern is the newest of the six functions. It didn’t exist as its own category before CSF 2.0. NIST elevated it because governance decisions are supposed to drive the other five functions, not sit as an afterthought once the technical work is done.
Work through these items:
- [ ] A written cybersecurity risk management strategy that leadership has actually reviewed and approved.
- [ ] Someone specific is accountable for cybersecurity decisions. Not “IT handles it,” a named role.
- [ ] Documented security policies that staff can find and read.
- [ ] A regular process for checking whether the strategy is working, not just whether it exists.
- [ ] A way to account for cybersecurity risk from vendors and suppliers, not just internal systems.
These map to the five categories inside Govern: Organizational Context, Risk Management Strategy, Roles and Responsibilities, Policy, and Oversight, plus a supply chain risk piece. For the full breakdown of what each of those actually means in practice, see our deep dive on the Govern function.
If you’re a smaller business wondering how much of this actually applies to you, NIST published a Quick-Start Guide specifically for small businesses, scaled down from the enterprise version. We break that down further in our guide to NIST CSF 2.0 for small business.
Identify Checklist
Identify is about knowing what you have and what could go wrong with it. You can’t protect what you haven’t inventoried.
- [ ] A current inventory of hardware, software, and where sensitive data lives.
- [ ] A basic understanding of which systems are critical to running the business.
- [ ] A risk register, even a simple spreadsheet, listing known risks and their likely impact.
- [ ] A process for assessing risk from vendors who touch your systems or data.
- [ ] Documentation of what regulations or contracts shape your security obligations.
Most businesses have pieces of this already. The gap is usually that it’s scattered across someone’s head, an old spreadsheet, and a vendor contract nobody’s reread in two years.
Protect Checklist
Protect covers the safeguards that limit damage if something goes wrong. This is the function most people picture when they hear “cybersecurity.”
- [ ] Multifactor authentication on email, remote access, and any system with sensitive data.
- [ ] Encryption for sensitive data, both at rest and in transit.
- [ ] Regular security awareness training for staff, not a one-time onboarding video.
- [ ] A patch management process that actually gets systems updated on a schedule.
- [ ] Backups that run automatically and cover everything critical.
- [ ] Limits on who has admin access, reviewed periodically.
This is also where the cost of skipping the basics shows up fastest.
That gap exists mostly because SMBs skip items on this exact list.
Detect Checklist
Detect is about noticing something’s wrong before it becomes a crisis. Protect reduces the chance of an incident. Detect shortens how long one goes unnoticed.
- [ ] Monitoring in place for network activity and endpoint behavior.
- [ ] Logging of key events, kept somewhere they can’t be quietly deleted.
- [ ] Alerts configured for unusual activity, not just a dashboard nobody checks.
- [ ] A defined threshold for what counts as “worth investigating.”
A lot of small businesses have logging turned on somewhere and nobody watching it. That’s not detection. That’s a filing cabinet.
Respond Checklist
Respond is what happens once you know something’s wrong. Winging it in the moment is how a bad day becomes a bad month.
- Have a written incident response plan that names who does what.
- Define a communication plan: who gets told internally, and who gets told externally (customers, insurers, regulators, if applicable).
- Assign someone to lead the response before an incident, not during one.
- Build in a reporting step, so incidents get documented for later review.
If your response plan currently lives in someone’s memory, that’s the single highest-leverage gap to close on this whole checklist.
Recover Checklist
Recover is about getting back to normal operations, and getting better at it each time.
- [ ] Backups that are actually tested by restoring them, not just confirmed to exist.
- [ ] A documented recovery plan with realistic timelines for critical systems.
- [ ] A defined order of what gets restored first.
- [ ] A post-incident review process that feeds lessons back into Govern and Protect.
That last item matters more than it looks. Recovery without review means you rebuild the same weak points you just watched fail.
What This Checklist Can’t Tell You
Checking every box above tells you whether something exists. It doesn’t tell you how well it’s done, or how consistently.
Tiers measure rigor, not checkboxes. NIST’s own framework separates those two questions with CSF Tiers, which describe how rigorously an organization manages risk. A business can have a written policy (Govern, checked) and still operate at Partial, the lowest tier, if that policy is ignored in practice. Higher isn’t automatically the right target either. It depends on your risk tolerance, resources, and what makes financial sense for your business.
Profiles measure the gap. The other piece a checklist misses is the distance between where you are and where you should be. NIST calls this a Current Profile versus a Target Profile. Comparing the two is what actually produces a prioritized action plan, not just a to-do list with no order.
For a more structured version of that comparison, walk through our full NIST CSF 2.0 self-assessment. It goes further than checking boxes.
See Where You Stand
Turn this checklist into a scored snapshot. The free NIST CSF 2.0 Risk-Check gives you an instant, plain-English read on where your gaps likely are. It’s a simplified starting point, not an official NIST assessment.
Take the free NIST CSF 2.0 Risk-Check
Related Guides
- What Is NIST CSF 2.0? A Plain-English Guide
- NIST CSF 2.0 Self-Assessment: Where Does Your Business Actually Stand?
- NIST CSF 2.0 for Small Business: What It Actually Takes
- The NIST CSF Govern Function, Explained
Frequently Asked Questions
What are the 6 functions of NIST CSF 2.0?
Govern, Identify, Protect, Detect, Respond, and Recover. Govern is the newest addition, added in the 2.0 update to cover strategy, roles, policy, and oversight. The other five cover the operational side: knowing your assets, defending them, spotting trouble, responding to it, and recovering afterward.
Is NIST CSF 2.0 mandatory?
No. It’s voluntary guidance, not a law, and there’s no regulator that fines a business for skipping it. It gets enforced indirectly, through vendor contracts, cyber insurance applications, or as a benchmark regulators point to after a breach involving unreasonable security practices.
CSF 2.0 also widened its scope beyond critical infrastructure to any organization, regardless of size or sector, and added small business specific guidance that didn’t exist before.</p> </details>
Do small businesses actually need to follow NIST CSF 2.0?
It’s optional, but NIST built a dedicated Small Business Quick-Start Guide specifically because the framework applies to organizations of any size. Insurers, banks, and customer security questionnaires increasingly reference it as a recognized baseline, which is why many small businesses adopt it voluntarily.
What is a CSF Profile?
A Profile describes your cybersecurity posture in terms of the framework’s functions and categories. A Current Profile shows what you’re actually doing today. A Target Profile shows what you want to be doing. Comparing the two is how you turn a checklist into a prioritized plan.
What are CSF Tiers?
Tiers describe how rigorously you manage cybersecurity risk, not how many boxes you’ve checked. There are four: Partial, Risk Informed, Repeatable, and Adaptive. A higher tier isn’t automatically the goal for every business. It depends on your risk tolerance and resources.
Is there a free NIST CSF 2.0 checklist PDF?
This page works as a plain-English checklist you can save or print. For an official, more technical version, NIST publishes the full CSF 2.0 core document and small business guide directly on nist.gov. This page is meant as the faster, working reference in between.
Get Help Closing the Gaps
Checking boxes is the easy part. Knowing which gaps actually matter for your business, and fixing them, is where most companies get stuck. LeadingIT helps Chicagoland businesses build out CSF 2.0-aligned programs, from the Govern paperwork to the Protect and Detect tooling that backs it up.
See our NIST CSF 2.0 compliance services or book a call to talk through where your business stands.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
