U.S. National Institute of Standards and Technology · NIST Cybersecurity Framework 2.0
Does NIST CSF require a penetration test?
The NIST Cybersecurity Framework is a voluntary structure for organizing a security program. Version 2.0, published in 2024, added Govern to the original five functions and broadened the audience beyond critical infrastructure.
The short answer
There is nothing to require, because CSF is voluntary and has no certification. Its risk assessment and continuous monitoring categories are where testing fits, and organizations mapping to CSF commonly cite penetration testing as an ID.RA activity.
Who it applies to
Any organization that wants a common vocabulary for its security program. It is not certifiable, and there is no NIST CSF audit.
In detail
CSF 2.0 organizes outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in the 2.0 revision and covers strategy, roles, policy and supply chain, which is where most of the new material sits.
The framework is a structure for talking about security, not a control set to be audited. That makes it useful to a startup as an organizing tool, and useless as an answer to a customer asking what assurance you hold. Companies asked for NIST CSF by a buyer are usually being asked whether they have a coherent program, and a SOC 2 or ISO 27001 answers that more directly.
What to have in scope
- Whatever the organization's own risk assessment scopes, since there is no external assessor to satisfy
Questions people ask
Can you get certified in NIST CSF?
No. The Cybersecurity Framework is voluntary guidance with no certification scheme and no accredited assessors. Organizations self-assess against it or use it to structure a program that is then certified under ISO 27001 or reported on under SOC 2.
What changed in NIST CSF 2.0?
Version 2.0, published in 2024, added Govern as a sixth function covering strategy, roles, policy and supply chain risk, and broadened the framework's stated audience from critical infrastructure to organizations of all kinds.
Related frameworks
This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.