Skip to content
Security Updated Noah Stegman

NIST Cybersecurity Framework 2.0 for Small Business

A plain-English guide to NIST CSF 2.0 for small businesses: the six functions, the free NIST quick-start guide, a controls checklist, and a 12-month plan.

The NIST Cybersecurity Framework (CSF) 2.0 is free, voluntary guidance from the National Institute of Standards and Technology that organizes cybersecurity into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. A small business does not get certified in it and is not legally required to follow it. Its value is as a checklist of outcomes and a shared vocabulary, so that you, your insurer, and whoever manages your IT can agree on what is covered and what is missing. NIST publishes a short quick-start guide written specifically for small businesses.

This is general information, not legal advice.

Does the NIST Framework Apply to Your Business?

For most private businesses, nothing in the law requires using the CSF. NIST describes it as voluntary guidance that helps organizations, regardless of size, sector, or maturity, understand, assess, prioritize, and communicate their cybersecurity efforts.

It becomes relevant in four common situations:

Your situationHow the CSF helps
You have no formal security plan and do not know where to startThe small business quick-start guide gives a short list of actions under each function
A cyber insurance application or customer questionnaire asks about your controlsThe functions map closely to what those forms ask, so your answers come from a documented list instead of memory
You are covered by a specific rule such as HIPAA, the FTC Safeguards Rule, or PCI DSSThose rules are mandatory and come first. The CSF is a useful way to organize the work, since one control often satisfies several rules
A contract references NISTRead the wording carefully. Defense contracts usually point to a different NIST publication, SP 800-171, which is a specific set of requirements and not the same thing as the CSF

The first function in the quick-start guide asks you to list your legal, regulatory, and contractual cybersecurity requirements. That is the right first step, because a mandatory rule outranks voluntary guidance. Our guides to HIPAA IT requirements, the FTC Safeguards Rule, PCI DSS, and the CCPA cover the ones small businesses meet most often.

What Is CSF 2.0?

NIST published version 2.0 on February 26, 2024. The original 2014 framework was aimed at critical infrastructure. Version 2.0 is written for any organization, and its most visible change is a sixth function, Govern, placed at the center of the other five.

The framework has three parts:

  • The Core. Six functions, divided into categories and subcategories. Each subcategory is an outcome, for example that identities and credentials for authorized users are managed. The framework deliberately says what to achieve and leaves how to you.
  • Profiles. A profile is a description of where you are now (current profile) and where you want to be (target profile). The gap between them is your to-do list.
  • Tiers. Four labels, Partial, Risk Informed, Repeatable, and Adaptive, that describe how rigorous an organization’s risk management practices are. They help with internal conversations about how formal you want to be. They are not grades, and there is no certificate.

Everything is free on the NIST Cybersecurity Framework site, including the full document, a searchable reference tool, and a set of quick-start guides.

What Do the Six Functions Mean for a Small Office?

The descriptions and action items below follow NIST SP 1300, the Small Business Quick-Start Guide. The guide is only a few pages and worth reading in full.

Govern

Establish and monitor your cybersecurity strategy, expectations, and policy. For a small business that means:

  • Decide who is responsible for cybersecurity decisions, by name
  • List your legal, regulatory, and contractual requirements
  • Assess whether cybersecurity insurance is appropriate
  • Assess the risks posed by suppliers and vendors before signing with them
  • Keep written policies short enough that staff will read them, such as acceptable use rules for business and personal devices

Identify

Determine the current risk to the business. You cannot protect what you have not listed.

  • Keep an inventory of hardware, software, systems, and services. NIST’s sample inventory table has columns for the asset, its owner, the sensitive data it can reach, whether MFA is required to access it, and the risk to the business if it is lost
  • Inventory and classify your data
  • Record threats and planned responses in a simple risk register

Protect

Use safeguards to prevent or reduce risk. NIST calls multi-factor authentication “one of the fastest, cheapest ways you can protect your data” and recommends starting with the accounts that reach the most sensitive information.

  • Require MFA on every account that offers it, and consider a password manager
  • Restrict sensitive information to the employees who need it
  • Change default manufacturer passwords
  • Update and patch software regularly, with automatic updates on
  • Back up data regularly and test the backups
  • Turn on full-disk encryption for laptops and tablets
  • Train staff to recognize common attacks and report them

Detect

Find and analyze possible attacks and compromises.

  • Install and maintain antivirus and antimalware software on every business device
  • Know the common signs of an incident. NIST lists loss of usual access, an unusually sluggish network, antivirus alerts, multiple failed login attempts, and many bounced emails with suspicious content
  • Consider engaging a service provider to monitor computers and networks if you do not have the resources to do it internally

Respond

Take action on a detected incident. NIST says a basic plan, prepared in advance, should name the person who maintains the plan, list whom to contact with their responsibilities and authority, and state what must be reported, when, and how under your laws, regulations, contracts, and policies. NIST’s sample contact sheet includes a business leader, technical contact, state police, legal counsel, bank, and insurer.

Recover

Restore what was affected.

  • Know who, inside and outside the business, has recovery responsibilities
  • Check the integrity of backups before restoring from them
  • Write a short after-action report: what happened, what was done, and what will change

Technical Controls Checklist

The CSF does not mandate specific products. These are the technical controls that satisfy the quick-start guide’s action items in a typical small office, with the function each one supports.

ControlFunctionHow to verify it
Device, software, and cloud service inventoryIdentifyThe list exists, has an owner, and was updated in the last quarter
MFA on email, banking, accounting, payroll, remote access, and admin accountsProtectTest a sign-in from a new device. See why MFA matters
Business password manager and no shared loginsProtectEach person has an individual account in every system
Access matched to roles, removed at departureProtectReview the user list in Microsoft 365 or Google Workspace for former staff
Automatic updates and a patching routineProtectNo device is running an out-of-support operating system
Full-disk encryption (BitLocker, FileVault)ProtectEncryption status is reported for every laptop
Backups with an offsite or offline copyProtect, RecoverA test restore was done and recorded
Default passwords changed on routers, firewalls, cameras, and printersProtectCheck each device’s admin login
Managed endpoint protection on all computersDetectAlerts go to a named person, not an unread mailbox
Sign-in and audit logs enabled in cloud servicesDetectLogs are on and retained long enough to investigate
Written incident response plan with a contact sheetRespondPrinted copy exists, since the network may be down when you need it
Recovery order for critical systemsRecoverThe plan says what gets restored first

A 12-Month Plan

This sequence is a suggestion, not part of the framework. The order follows a simple principle: decide, list, protect, watch, rehearse. Backups move to the front because recovery matters most on the day everything else fails.

MonthsFocusWork
1 to 2Govern, IdentifyName the responsible person. List legal and contractual requirements. Build the inventory of devices, software, cloud services, and data
2 to 4Protect, RecoverMFA everywhere it is offered. Verify backups and run a test restore. Change default passwords. Turn on automatic updates
4 to 6ProtectPassword manager, role-based access cleanup, full-disk encryption, replace out-of-support systems, first round of staff training
6 to 9DetectManaged endpoint protection on every device, cloud audit logging, alert routing, decide who monitors
9 to 12Respond, RecoverWrite the incident response plan and contact sheet, walk through a scenario as a group, review insurance, write the current and target profile for next year

When Is the Full Framework More Than You Need?

The complete CSF 2.0 Core has more than a hundred subcategories. NIST says plainly that the framework is “not a one-size-fits-all approach”. A five-person office does not need to document a response to every subcategory, and doing so would take time away from the controls that reduce risk.

Reasonable limits for a small business:

  • Work from the quick-start guide, not the full Core
  • Keep the written output short: an inventory, a list of requirements, a handful of policies, an incident contact sheet, and a one-page gap list
  • Skip tiers unless a customer or insurer asks about them
  • If a mandatory rule applies to you, satisfy that rule’s specific requirements first and use the CSF to organize the rest

Common Mistakes

  • Treating the CSF as a certification. There is none. A vendor or provider can say its work aligns with the CSF, and you can ask which outcomes it covers.
  • Starting with purchases. The framework starts with Govern and Identify for a reason. Tools bought before the inventory often protect the wrong things.
  • Leaving Respond and Recover for last, then never reaching them. A contact sheet and a test restore take hours, not months.
  • Writing policies no one reads. A two-page acceptable use policy that staff have seen is worth more than a binder.
  • Confusing the CSF with SP 800-171 or SP 800-53. Those are detailed control catalogs used mainly in government contracting. The CSF is a higher-level outline.

Common Questions

Is the NIST Cybersecurity Framework mandatory for small businesses?

No. NIST describes the CSF as voluntary guidance. Private businesses are not required by law to adopt it. It may be referenced by an insurer, a customer contract, or a regulator as a recognized benchmark, and specific laws such as HIPAA or the FTC Safeguards Rule carry their own mandatory requirements that apply regardless of the CSF.

Can a business get NIST CSF certified?

No. NIST does not offer a certification or accreditation for the CSF. A business can assess itself against the framework, or hire an independent assessor to do so, and share the result. Be cautious with any marketing that implies an official NIST certification exists.

What changed from version 1.1 to 2.0?

Version 2.0, published February 26, 2024, added the Govern function, widened the intended audience from critical infrastructure to all organizations, expanded the guidance on supply chain risk, and introduced quick-start guides and implementation examples, including one written for small businesses.

How long does it take a small business to adopt the framework?

Working from the small business quick-start guide, the first useful outputs (a named owner, an inventory, MFA, verified backups) are a matter of weeks. Reaching a reasonable baseline across all six functions is realistic within about a year for a small office, which is why the plan above is spread over 12 months.

Do we need special software to use the CSF?

No. The inventory, risk register, and profile can live in a spreadsheet. NIST provides templates and a free online reference tool. Software becomes relevant for the controls themselves, such as endpoint protection, backup, and a password manager.

How Coastal Growth Co. Can Help

We can run the Identify step with you, building the inventory of devices, accounts, cloud services, and data, then turn the gaps into a prioritized plan and implement the technical controls: MFA, encryption, patching, backups, endpoint protection, and logging. The result is a short written record you can hand to an insurer or customer. See our managed IT services and networks and security pages, or contact us to talk through where your business stands.

Need a hand with this?

I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.

Let's talk arrow_forward

Get in touch

Talk with Noah

Tell me about your business and what is getting in the way. A recurring problem, an upcoming project, or a setup you would like a second opinion on.

noah@coastalgrowthco.com

Noah Stegman · Coastal Growth Co.

Your message goes to Noah. I will reply by email. Please leave out passwords and sensitive account details.