The US National Institute of Standards and Technology released version 2.0 of its Cybersecurity Framework in February 2024. The update is the first major revision since the framework’s original release in 2014.
For SMEs, the most significant change is not technical. It is organisational. NIST CSF 2.0 introduces a new “Govern” function that explicitly places cybersecurity accountability at the executive and board level.
The six functions of CSF 2.0
| Function | Focus | SME relevance |
|---|---|---|
| Govern | Strategy, risk management, oversight | High — defines who is responsible |
| Identify | Asset management, risk assessment | High — you cannot protect what you do not know |
| Protect | Access control, training, data security | High — the day-to-day controls |
| Detect | Monitoring, anomaly detection | Medium — depends on size and budget |
| Respond | Incident response, communication | High — every company needs a plan |
| Recover | Backup, resilience, lessons learned | High — recovery time is a business metric |
The Govern function is new. It includes:
- Cybersecurity risk management strategy
- Roles and responsibilities
- Policy and procedure documentation
- Oversight of third-party risk
- Regulatory and legal compliance
Why Govern matters for SMEs
The NIST framework has always been voluntary for private companies. But its influence extends through:
- Cyber insurance requirements. Insurers increasingly reference NIST CSF when assessing applicant security postures.
- Customer security questionnaires. Enterprise buyers ask whether suppliers align with recognised frameworks.
- Regulatory expectations. While NIST is US-based, EU regulators reference it as a benchmark for “appropriate” security measures.
For an SME, the Govern function is the difference between having security controls and having a security programme. Controls are technical. A programme is governed, measured, and improved.
Practical implementation for SMEs
Govern: Name a security owner. Document three policies (information security, acceptable use, incident response). Review them annually.
Identify: Maintain an asset inventory. Conduct a risk assessment. Know your critical data and where it lives.
Protect: MFA. Encryption. Access control. Training. The basics, done consistently.
Detect: Enable logging on critical systems. Review alerts weekly. Have a threshold for escalation.
Respond: Write an incident response plan. Name roles. Test it annually.
Recover: Test backups quarterly. Document recovery time objectives. Know your critical path to resume operations.
At Metaluxo we map SME security programmes to NIST CSF 2.0 as part of our vCISO engagements. If a customer or insurer has asked for NIST alignment and you are not sure what that means, book a free 30-minute consultation and we will assess your current posture against the framework.