← Standards & Code Updates Center
Framework Update · OT / Industrial Controls Security

NIST CSF — What Changed for OT Security

A practical, plain-language look at what shifted between NIST Cybersecurity Framework 1.1 and 2.0 — written in our own words for OT and industrial-control security practitioners, not a substitute for reading the actual published framework.

Framework
NIST CSF
Version tracked
2.0
Previous version
1.1
Publisher
NIST
Review date
2026-08-14
Cycle
Non-fixed; 2.0 published 2024

Adoption caveat: unlike NEC, NFPA 72, ASHRAE 90.1, or ASCE 7, NIST CSF is a voluntary framework, not a code adopted into legal force by a jurisdiction. Whether an organization follows 1.1 or 2.0 (or a specific sector-mapped variant) depends on internal policy, client/contract requirements, insurance requirements, or a specific regulatory framework that references it — always confirm which version any specific contract, client, or regulatory requirement actually points to before assuming 2.0 automatically applies.

2.0 vs. 1.1 — Change Areas at a Glance

FunctionTopicWhy it matters for your work
GOVERNNew sixth core functionA prior OT/ICS security program built against CSF 1.1's five functions is missing an explicit governance layer by CSF 2.0's structure — worth a gap review even if the underlying technical controls haven't changed, since governance documentation is increasingly what auditors and insurers ask for directly.
ScopeExpanded applicability beyond critical infrastructureSmaller engineering firms and system integrators working on industrial control projects who previously treated CSF as "not written for us" should reconsider — the 2.0 framing explicitly includes them, and clients increasingly expect CSF alignment as a baseline expectation regardless of firm size.
IDENTIFY / PROTECTSupply chain risk managementSystem integrators and vendors providing remote access or maintenance to industrial control systems should expect clients to ask more specifically about supply-chain security practices — this is one of the more consequential practical shifts for anyone in the OT vendor ecosystem, not just end-user operators.
ImplementationImplementation examplesTeams that found CSF 1.1's outcome statements too abstract to translate into concrete OT network or PLC-level controls now have an official companion reference to draw from — worth revisiting even for a mature program, since the examples can surface gaps the abstract language didn't make obvious.
PROTECTAlignment with OT-specific guidance (e.g., NIST SP 800-82)Industrial control and SCADA security programs that previously had to do significant translation work to map CSF onto OT-specific controls should find that translation work meaningfully reduced under 2.0 — worth revisiting existing crosswalk documentation.

This table summarizes the structural and scope changes between CSF versions, described here in our own words. It is not a line-by-line diff of framework text and should not be used as a substitute for the official NIST publication.

What Each Change Area Means in Practice

GOVERNNew sixth core function

CSF 2.0 added a sixth function, Govern, alongside the original five (Identify, Protect, Detect, Respond, Recover) — formalizing organizational cybersecurity governance, risk strategy, and oversight as a distinct, ongoing function rather than folding it into Identify.

Why it matters

A prior OT/ICS security program built against CSF 1.1's five functions is missing an explicit governance layer by CSF 2.0's structure — worth a gap review even if the underlying technical controls haven't changed, since governance documentation is increasingly what auditors and insurers ask for directly.

ScopeExpanded applicability beyond critical infrastructure

CSF 2.0 broadened its stated scope from being written primarily for critical infrastructure to being explicitly applicable to organizations of any size, sector, and cybersecurity maturity — including industrial and OT environments beyond the original critical-infrastructure framing.

Why it matters

Smaller engineering firms and system integrators working on industrial control projects who previously treated CSF as "not written for us" should reconsider — the 2.0 framing explicitly includes them, and clients increasingly expect CSF alignment as a baseline expectation regardless of firm size.

IDENTIFY / PROTECTSupply chain risk management

Supply chain risk management was elevated and expanded within CSF 2.0, reflecting growing recognition that OT/ICS security risk frequently originates from third-party vendors, integrators, and remote-access relationships rather than the operator's own network alone.

Why it matters

System integrators and vendors providing remote access or maintenance to industrial control systems should expect clients to ask more specifically about supply-chain security practices — this is one of the more consequential practical shifts for anyone in the OT vendor ecosystem, not just end-user operators.

ImplementationImplementation examples

CSF 2.0 introduced "implementation examples" for each subcategory — concrete, illustrative actions organizations might take — as a companion resource to the framework's outcome-based language, intended to make the framework more directly actionable.

Why it matters

Teams that found CSF 1.1's outcome statements too abstract to translate into concrete OT network or PLC-level controls now have an official companion reference to draw from — worth revisiting even for a mature program, since the examples can surface gaps the abstract language didn't make obvious.

PROTECTAlignment with OT-specific guidance (e.g., NIST SP 800-82)

CSF 2.0's broader framing and updated reference tools improve alignment with OT/ICS-specific NIST guidance, making it easier to map CSF functions directly onto industrial control system security practices rather than treating OT as an awkward fit for an IT-oriented framework.

Why it matters

Industrial control and SCADA security programs that previously had to do significant translation work to map CSF onto OT-specific controls should find that translation work meaningfully reduced under 2.0 — worth revisiting existing crosswalk documentation.

What to Update in Your Documentation and Practices

1Confirm whether your organization, client, or regulatory framework references CSF 1.1 or 2.0 specifically — many existing contracts and compliance frameworks were written against 1.1 and haven't been updated to reference 2.0 explicitly.
2Add or formalize a Govern function in existing security documentation if the program was originally built against the five-function 1.1 structure.
3Review supply-chain and third-party remote-access security practices specifically — this is one of the more consequential practical shifts for OT vendors and integrators.
4Use the official CSF 2.0 implementation examples to re-audit existing OT/ICS controls for gaps the more abstract 1.1 language may have obscured.
5Re-map any existing CSF-to-OT crosswalk documentation (e.g., linking CSF functions to NIST SP 800-82 or IEC 62443 controls) against the 2.0 structure.
6Update any client-facing security documentation or proposals that cite "CSF" without specifying a version, since the version now matters more given the structural changes.

About This NIST CSF Update Summary

This page summarizes, in our own words, the structural and scope changes between NIST Cybersecurity Framework 1.1 and 2.0, focused specifically on what matters for OT and industrial-control security practitioners. It is an educational summary and change-awareness tool, not a compliance reference or a substitute for the official NIST publication.

⚠️ Values used in this tool are drawn from our own summary of NIST CSF version differences, not the official NIST publication text as an educational convenience and may not reflect the current adopted edition or local amendments. Always verify against the current official published standard before using any value for a real design, installation, or compliance decision. See our full disclaimer.

Why CSF Versions Matter for OT/ICS Security Programs

Unlike a building code, NIST CSF has no fixed revision cycle and no jurisdiction that enforces it — it is a voluntary framework whose applicability depends on internal policy or external requirement (contract, insurance, or a regulatory framework that references it). CSF 2.0, published in 2024, made structural changes — most notably adding the Govern function and broadening scope beyond critical infrastructure — that are significant enough that a security program built against 1.1 is not automatically equivalent to one built against 2.0, even if the underlying technical controls are similar.

How We Track This

We review NIST CSF publications and summarize the changes most relevant to OT, SCADA, and industrial-control security practice on this site, in our own explanatory language — we do not reproduce NIST's publication text verbatim beyond brief, clearly-attributed references. Where our SCADA/industrial-controls content references specific CSF functions or categories, we note which version that reference is based on.

Frequently asked questions

Do I have to use CSF 2.0 instead of 1.1?

Not automatically — NIST CSF is voluntary, and whether 1.1 or 2.0 applies depends on what your organization, client, or any regulatory framework you follow specifically references. Some sector-specific frameworks and contracts still reference 1.1 explicitly and haven't been updated. Always confirm which version any specific requirement points to.

Where can I read the actual NIST CSF 2.0 text?

NIST publishes CSF 2.0 for free directly (nist.gov/cyberframework), including the framework core, implementation examples, and informative references. This page is a summary and change-awareness tool, not a substitute for the official publication.

Is NIST CSF specific to OT/industrial control systems?

No — CSF is a general-purpose cybersecurity framework applicable across IT and OT environments. For OT-specific technical guidance, NIST also publishes SP 800-82 (Guide to Operational Technology Security), which is commonly used alongside CSF to map the framework's functions onto industrial-control-specific controls.

Related tools & guides

SCADA & Industrial Controls StudioStandards & Code Updates Center