EdLaw nat/us/nist-csf/README.md

language: en · status: in-force · last checked: 2026-09-04

NIST Cybersecurity Framework (CSF) 2.0

Voluntary cybersecurity risk-management framework published by the US National Institute of Standards and Technology: The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, 2024-02-26 (doi:10.6028/NIST.CSWP.29). Per the document, it "provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks" and "offers a taxonomy of high-level cybersecurity outcomes"; it "does not prescribe how outcomes should be achieved". The CSF Core is a hierarchy of Functions, Categories, and Subcategories; the six Functions are Govern, Identify, Protect, Detect, Respond, Recover (Govern was added in 2.0).

Applicability to EdTech

Not law — but the reference point US K-12 cybersecurity guidance is aligned to (the CDT K-12 brief recommends institutional policies "ideally aligned with the NIST Cybersecurity Framework"), and a common ask in district procurement alongside SOC 2. Mapping product security controls to CSF 2.0 functions answers a large share of US security questionnaires.

Contents

README-level only; the CSF Core taxonomy (Appendix A of CSWP 29) can be added as a fact document if RFI usage warrants it — the source is public and freely reproducible.

Sources