+91 98804 42758

NIST CSF Functions Explained

6 functions in the current version, here's exactly what each one covers

Sudhakar Varma Delivery Head, Avantcert
August 13, 2026 8 min read

The Short Answer

NIST CSF 2.0 organizes its guidance into 6 functions: Govern, Identify, Protect, Detect, Respond, and Recover. The original 2013 and 2014 versions of the framework had 5 functions, Identify through Recover; Govern was added in the 2024 revision. See our NIST CSF guide for the fundamentals, or our NIST CSF cost breakdown for the budget side.


The 6 Functions

  • Govern — the newest function, covering risk management strategy, roles and responsibilities, policy, and oversight of the entire programme. Sets the context the other five functions operate within.
  • Identify — asset inventory, risk assessment, and understanding organizational context. The foundation: you can't protect or detect against risks to assets you haven't identified.
  • Protect — safeguards to limit or contain the impact of a potential security event: access control, awareness training, data security, protective technology.
  • Detect — activities to identify the occurrence of a security event: continuous monitoring, anomaly detection, detection processes.
  • Respond — actions taken once an incident is detected: response planning, communications, analysis, mitigation.
  • Recover — activities to restore capabilities impaired by an incident: recovery planning, improvements, communications during restoration.

Govern logically comes first, since it sets the risk strategy everything else operates within, but in practice organizations often work on several functions in parallel rather than fully completing one before starting the next.

Why Govern Was Added in 2024

The original five functions, Identify through Recover, were largely operational and technical. They didn't explicitly capture how an organization sets risk strategy, assigns accountability, or oversees the programme as a whole, that context was implicit rather than assessed. CSF 2.0 made governance an explicit, assessed sixth function, reflecting a broader industry shift toward treating security governance as a distinct leadership responsibility rather than an assumed byproduct of the technical functions.

Not sure where your organization's gaps sit across the six functions?

A maturity assessment scores you against all six and prioritizes what to fix first.

Get a Free Quote

Where Most Organizations Are Weakest

Respond and Recover are commonly the least mature functions on a first assessment. Organizations tend to invest heavily in prevention (Protect) and detection (Detect), since those feel more immediately actionable, while incident response planning and recovery procedures get less attention until an actual incident forces the issue. This pattern is worth watching for specifically during a first maturity assessment.

How the Functions Relate to Other Frameworks

CSF's six functions and NIST SP 800-171's 14 control families cover overlapping ground, both address access control, incident response, and risk management, but organize it differently: CSF by outcome function, 800-171 by control family. Organizations pursuing both CSF alignment and CMMC certification typically map their existing 800-171 work into the corresponding CSF functions rather than treating the two as unrelated efforts. See our NIST CSF vs ISO 27001 comparison for how CSF relates to a certifiable management-system standard.

Ready to assess your organization against all six functions?

We've guided organisations across 40+ markets through NIST CSF maturity assessment.

Talk to an Avantcert Expert

Frequently asked questions about NIST CSF functions

Why was Govern added as a sixth function in CSF 2.0?

Because the original five functions, Identify through Recover, were largely operational and technical, and didn't explicitly capture how an organization sets risk strategy, assigns accountability, and oversees the rest of the programme. Govern was added in the 2024 revision to make that leadership and oversight layer an explicit, assessed part of the framework rather than an implicit assumption.

Are the six functions meant to be implemented in order?

Not strictly sequentially, though Govern logically comes first since it sets the risk strategy the other five functions operate within. In practice, organizations often work on several functions in parallel, particularly Identify and Protect, rather than fully completing one before starting the next.

Which function do most organizations find weakest on a first assessment?

Respond and Recover are commonly the least mature, since organizations often invest heavily in prevention, Protect, and detection, Detect, while incident response and recovery planning get less attention until an actual incident forces the issue.

Does each function have the same number of categories underneath it?

No, they vary. Identify and Protect, being broader operational functions, tend to have more categories and subcategories than Respond or Recover, though all six functions carry real assessed weight in a maturity evaluation.

How do the six functions map onto NIST 800-171 or CMMC controls?

CSF's functions and NIST 800-171's control families cover overlapping ground, both address access control, incident response, and risk management, but structured differently: CSF is organized by outcome function, 800-171 by control family. Organizations pursuing both CSF alignment and CMMC certification typically map their existing 800-171 work into the corresponding CSF functions rather than treating them as unrelated efforts.

Is Identify really a separate function, or is it just documentation?

It's a genuine function, not just paperwork, covering asset inventory, risk assessment, and understanding your organizational context, the foundation the other five functions depend on. You can't meaningfully protect or detect against risks to assets you haven't identified in the first place.

About Avantcert. Avantcert is a compliance consultancy that has guided 3,000+ organisations across 40+ markets through NIST CSF maturity assessment and gap remediation. See our NIST CSF service or request a free quote.

Ready to get certified?

Join 3,000+ organizations that trust Avantcert. Get a free, scoped quote today.