CSF 2.0 replaced version 1.1 in February 2024. Most of the underlying outcomes carried over — the changes are structural, and mostly aimed at the problems organisations actually had using it.
Scope: everyone, not just critical infrastructure
Version 1.x was the "Framework for Improving Critical Infrastructure Cybersecurity". CSF 2.0 drops that framing — it now explicitly addresses organisations of every size and sector. For OT operators the practical effect is wider adoption around you: suppliers, insurers, and corporate IT are increasingly speaking this language.
Govern — a new sixth function
The biggest structural change. Governance outcomes — risk strategy, roles and responsibilities, policy, and oversight — were pulled out of the other functions and elevated into a function of their own, feeding all five others. It exists because the common failure was never detection technology; it was nobody clearly owning cyber risk.
Supply chain risk, front and centre
Cybersecurity supply chain risk management (C-SCRM) gets a dedicated category under Govern (GV.SC). For OT that means vendors, system integrators, and remote support arrangements — historically the soft underbelly of industrial environments — are now an explicit, assessable part of the framework.
Profiles, tiers, and practical tooling
CSF 2.0 formalises organisational profiles (current vs target state) and community profiles for specific sectors and technologies, backed by quick-start guides and a searchable catalogue of implementation examples. The framework became noticeably more usable — less poster, more workbook.