← Resources·Standards Guide

NIST CSF 2.0 for OT — what changed and what it means for you

The 2024 release of NIST Cybersecurity Framework 2.0 was the first major revision in a decade — a new Govern function, serious supply chain content, and a scope that now covers every organisation, not just critical infrastructure. This guide covers what changed, how the six functions read in an industrial context, and how CSF fits alongside IEC 62443 rather than competing with it.

9 min read
·
For controls and OT engineers
·
Free account
What changed

The four changes that matter

CSF 2.0 replaced version 1.1 in February 2024. Most of the underlying outcomes carried over — the changes are structural, and mostly aimed at the problems organisations actually had using it.

Scope: everyone, not just critical infrastructure
Version 1.x was the "Framework for Improving Critical Infrastructure Cybersecurity". CSF 2.0 drops that framing — it now explicitly addresses organisations of every size and sector. For OT operators the practical effect is wider adoption around you: suppliers, insurers, and corporate IT are increasingly speaking this language.
Govern — a new sixth function
The biggest structural change. Governance outcomes — risk strategy, roles and responsibilities, policy, and oversight — were pulled out of the other functions and elevated into a function of their own, feeding all five others. It exists because the common failure was never detection technology; it was nobody clearly owning cyber risk.
Supply chain risk, front and centre
Cybersecurity supply chain risk management (C-SCRM) gets a dedicated category under Govern (GV.SC). For OT that means vendors, system integrators, and remote support arrangements — historically the soft underbelly of industrial environments — are now an explicit, assessable part of the framework.
Profiles, tiers, and practical tooling
CSF 2.0 formalises organisational profiles (current vs target state) and community profiles for specific sectors and technologies, backed by quick-start guides and a searchable catalogue of implementation examples. The framework became noticeably more usable — less poster, more workbook.
Free account required
Keep reading with a free account

The rest of this guide is free — it just needs an account. Signing up also gets you the daily OT brief: curated OT security news, standards changes, and vendor advisories, every morning.

Create free accountSign in
Related guides
Guide
IEC 62443 Explained
The engineering standard CSF hands the “how” to
Guide
OT Cybersecurity for Controls Engineers
How functional safety concepts map directly to OT cyber