The NIST Cybersecurity Framework 2.0 defines six core functions for effective cybersecurity management. With the new Govern function, CSF 2.0 places strategic oversight at the center. We support you in implementing all six functions – from governance through detection to recovery.
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
Or contact us directly:










Since February 2024, NIST CSF 2.0 is the current version. The key update is the sixth function Govern, which establishes cybersecurity governance as a strategic leadership responsibility. Organizations should update existing CSF implementations to version 2.0.
Years of Experience
Employees
Projects
We follow a structured approach to implementing all six NIST CSF 2.0 core functions, ensuring both technical excellence and strategic alignment.
GOVERN Phase: Establishing cybersecurity governance, risk strategy and policies at the leadership level
IDENTIFY Phase: Comprehensive asset inventory, risk assessment and dependency analysis
PROTECT Phase: Implementation of access controls, data security and security training
DETECT Phase: Building continuous monitoring, anomaly detection and threat analysis
RESPOND Phase: Development of structured incident response processes and communication plans
RECOVER Phase: Establishing robust recovery processes and business continuity measures
"The systematic implementation of all five NIST CSF core functions with ADVISORI has fundamentally transformed our cybersecurity architecture. The comprehensive approach and structured execution have enabled us to develop a truly resilient and adaptive cybersecurity posture that not only minimizes risks but also enables business growth."

Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
We offer you tailored solutions for your digital transformation
Complete implementation of the Identify and Protect functions with comprehensive asset management and safeguards.
Building advanced detection capabilities and structured response and recovery processes.
Choose the area that fits your requirements
Integrating the NIST Cybersecurity Framework with existing standards like ISO 27001, BSI IT-Grundschutz, or DORA requires strategic planning and deep expertise. We handle the mapping, harmonization, and sustainable embedding in your organization.
A thorough maturity assessment based on the NIST Cybersecurity Framework 2.0 reveals exactly where your organization stands across all four implementation tiers and which steps lead to the next level. We develop data-driven roadmaps that systematically and measurably elevate your cybersecurity maturity – from baseline analysis through gap assessment to prioritized implementation.
NIST CSF 2.0 defines six core functions: Govern (GV), Identify (ID), Protect (PR), Detect (DE), Respond (RS) and Recover (RC). The Govern function was introduced in version 2.0 (February 2024) as the sixth function and forms the strategic center of the framework. Together, the six functions encompass
22 categories and
106 subcategories covering a complete cycle for cybersecurity management.
The Govern function (GV) establishes cybersecurity governance at the executive level. It encompasses
6 categories: Organizational Context (GV.OC), Risk Management Strategy (GV.RM), Roles and Responsibilities (GV.RR), Policy (GV.PO), Oversight (GV.OV) and Cybersecurity Supply Chain Risk Management (GV.SC). Govern sits at the center of the framework wheel because it informs how the organization implements all other five functions.
The key changes: CSF 2.0 adds Govern as the sixth core function, applies to all organizations (not just critical infrastructure), consolidates to
106 subcategories (from 108), explicitly integrates supply chain risk management, and improves mappings to international standards like ISO 27001. Organizations with existing CSF 1.1 implementations should conduct a gap assessment to plan their migration.
Identify covers Asset Management (ID.AM), Risk Assessment (ID.RA) and Improvement (ID.IM). Protect includes Identity Management and Access Control (PR.AA), Awareness and Training (PR.AT), Data Security (PR.DS), Platform Security (PR.PS) and Technology Infrastructure Resilience (PR.IR). Detect consists of Continuous Monitoring (DE.CM) and Adverse Event Analysis (DE.AE). Each category contains specific subcategories with measurable outcomes.
Respond (RS) includes Incident Management (RS.MA), Incident Analysis (RS.AN), Incident Response Reporting and Communication (RS.CO) and Incident Mitigation (RS.MI). Recover (RC) covers Recovery Plan Execution (RC.RP) and Incident Recovery Communication (RC.CO). Both functions activate during security incidents, with recovery insights feeding back into improving Protect and Detect capabilities.
NIST CSF 2.0 provides explicit mappings to international standards. Govern corresponds to DORA governance requirements (Art. 5‑6) and ISO 27001 leadership clauses (Ch. 5). Identify supports asset inventory requirements under NIS 2 Article 21. Detect and Respond cover DORA incident reporting obligations (Art. 17‑19). Recover addresses business continuity requirements across all three frameworks. An integrated compliance framework avoids duplicate assessments.
Implementation begins with a maturity assessment across all six functions, evaluating current state using the NIST Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive). A Current Profile is then created and compared against the Target Profile. The gap analysis prioritizes measures by risk and cost-benefit ratio. Implementation proceeds in phases, typically starting with Govern and Identify as the foundation for all other functions.
Discover how we support companies in their digital transformation
Klöckner & Co
Digital Transformation in Steel Trading

Siemens
Smart Manufacturing Solutions for Maximum Value Creation

Festo
Intelligent Networking for Future-Proof Production Systems

Bosch
AI Process Optimization for Improved Production Efficiency

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Our clients trust our expertise in digital transformation, compliance, and risk management
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
Direct hotline for decision-makers
Strategic inquiries via email
For complex inquiries or if you want to provide specific information in advance