← Blog

Explainer

NIST CSF 2.0: The Subcategories to Start With When You Have No Program

By Parker Brissette · September 14, 2026 · 6 min read

Almost everyone tells a brand new program to start with an asset inventory. Under NIST CSF 2.0 that advice is out of date, and following it is how a one-person security function spends a year building a spreadsheet that nobody owns.

The framework has 106 subcategories. You are going to do eight.

Which eight, and in what order? The failure mode I keep seeing is not a bad pick. It is picking all of them, scoring every row 1 through 5, presenting the heat map to a board that nods politely, and having no capacity left in the fiscal year to change anything that was scored.

Govern is where a one-person program starts now

CSF 2.0 arrived on February 26, 2024 with six functions instead of five, 22 categories, and those 106 subcategories. Govern is the addition. In 1.1 the governance material lived inside Identify as the ID.GV category, which put it alongside the asset work rather than ahead of it. (The crosswalk NIST published with the release maps ID.GV straight into the new Govern function, which is a quick way to see that most of this is a reorganization of obligations you already had.)

GV.RR-02 goes on the board first. It asks that roles and authorities for managing cybersecurity risk are established, and then actually enforced. In a county government with one security hire, that is a one page memo naming who decides and who actually does the work. It costs a meeting. Every other subcategory below has an ownership problem hiding inside it, and GV.RR-02 is the only one that addresses ownership head on. This is the hill I will die on. If the memo does not exist, your shiny new inventory is being maintained by nobody in particular by March.

Pair it with GV.PO-01. Not a fifty page policy. Four pages saying what the organization does about cyber risk, signed by a person who controls budget.

The eight, in the order I would work them

This is the subset I would defend to an assessor, and the sequence is the argument, not the membership.

I genuinely do not care whether you track this in a GRC platform or a spreadsheet. At this size the tool is not the constraint. Do run it through the crosswalk if you also owe CIS or SOC 2 evidence, because these eight cover a surprising amount of both, and mapping once is cheaper than doing the same work twice under two labels.

Criticality beats completeness, and this is where I lose people

ID.AM-05 asks you to rank the assets you just wrote down. People skip it, because it reads like a second pass over work they only just finished. What I keep seeing instead is a complete inventory with no ranking anywhere in it, which behaves exactly like no inventory at 2 a.m. when the question on the bridge call is which of the 340 machines actually matters.

A rural hospital has maybe a dozen systems where an outage turns into a patient safety event. Everything else is inconvenience, expensive inconvenience in some cases, but inconvenience. If you cannot name that dozen from memory, the inventory is not yet doing its job. The ranking is also what keeps the next three years tractable, because every later subcategory gets scoped to the short list before it gets scoped to all 340.

If you are the one security hire at a county government and the commissioners want a maturity number by the end of the quarter, the ranked list is what you present. Not the heat map.

What you are not doing in year one

Detect, Respond, and Recover are absent from that list on purpose, with one exception. RS.MA-01 says the incident response plan gets executed with relevant third parties once an incident is declared, and you should write that plan even if you cannot staff its execution, because the third parties in that sentence are your insurer and your outside counsel and their after-hours numbers belong somewhere other than in your head.

DE.CM-01, network monitoring, is a real subcategory and a real budget line. Organizations that skip straight to it end up paying a managed provider to watch assets they cannot enumerate. That is an expensive way to discover you needed ID.AM-01.

The piece I am still unsure about is the Organizational Profile. The Current and Target Profile structure is what 2.0 gives you in place of arguing about Tier numbers, and it is better than a Tier number. Whether anyone outside federal contracting will accept one as an audit artifact, two and a half years in, I do not know, and I have not yet seen a customer security questionnaire ask for it.

Eight subcategories is not a program. It is the slice of a program that one person can actually finish this year, which is the only slice that counts when there is one of you. Run the self assessment against those eight, write down what is missing, and come back for the next eight in July. The other 98 are not going anywhere.

nist csfcsf 2.0governancesmall businessrisk management

Go deeper