Metaluxo
← Blog

NIST Cybersecurity Framework 2.0: What SMEs Need to Know

NIST Cybersecurity Framework 2.0: What SMEs Need to Know

The US National Institute of Standards and Technology released version 2.0 of its Cybersecurity Framework in February 2024. The update is the first major revision since the framework’s original release in 2014.

For SMEs, the most significant change is not technical. It is organisational. NIST CSF 2.0 introduces a new “Govern” function that explicitly places cybersecurity accountability at the executive and board level.


The six functions of CSF 2.0

FunctionFocusSME relevance
GovernStrategy, risk management, oversightHigh — defines who is responsible
IdentifyAsset management, risk assessmentHigh — you cannot protect what you do not know
ProtectAccess control, training, data securityHigh — the day-to-day controls
DetectMonitoring, anomaly detectionMedium — depends on size and budget
RespondIncident response, communicationHigh — every company needs a plan
RecoverBackup, resilience, lessons learnedHigh — recovery time is a business metric

The Govern function is new. It includes:

  • Cybersecurity risk management strategy
  • Roles and responsibilities
  • Policy and procedure documentation
  • Oversight of third-party risk
  • Regulatory and legal compliance

Why Govern matters for SMEs

The NIST framework has always been voluntary for private companies. But its influence extends through:

  • Cyber insurance requirements. Insurers increasingly reference NIST CSF when assessing applicant security postures.
  • Customer security questionnaires. Enterprise buyers ask whether suppliers align with recognised frameworks.
  • Regulatory expectations. While NIST is US-based, EU regulators reference it as a benchmark for “appropriate” security measures.

For an SME, the Govern function is the difference between having security controls and having a security programme. Controls are technical. A programme is governed, measured, and improved.


Practical implementation for SMEs

Govern: Name a security owner. Document three policies (information security, acceptable use, incident response). Review them annually.

Identify: Maintain an asset inventory. Conduct a risk assessment. Know your critical data and where it lives.

Protect: MFA. Encryption. Access control. Training. The basics, done consistently.

Detect: Enable logging on critical systems. Review alerts weekly. Have a threshold for escalation.

Respond: Write an incident response plan. Name roles. Test it annually.

Recover: Test backups quarterly. Document recovery time objectives. Know your critical path to resume operations.


At Metaluxo we map SME security programmes to NIST CSF 2.0 as part of our vCISO engagements. If a customer or insurer has asked for NIST alignment and you are not sure what that means, book a free 30-minute consultation and we will assess your current posture against the framework.

Roberto Arias — founder of Metaluxo. Virtual CISO work, ISO 27001 and incident response for small and medium businesses across the EU. Ask him a question →

Send us a message
Message us Book now