Assess your cybersecurity program against all six NIST CSF 2.0 functions and 22 categories, including the new Govern function, with a checklist built for OT and ICS environments.
The NIST Cybersecurity Framework is the most widely used cybersecurity framework in the United States, and version 2.0 brought the biggest change in its history. Released in February 2024, CSF 2.0 introduced a sixth function, Govern, which now sits at the center of the framework and wraps the five that came before it.
If you are working from older material, you will still see the five-function model. That model is out of date. This checklist is built on CSF 2.0—all six functions and 22 categories—and is specifically written for OT (Operational Technology) and ICS (Industrial Control Systems). It maps the framework to industrial realities and to IEC 62443, rather than treating it as IT-only.
For each category you get a plain-language description, an assessment prompt, and a status field, plus maturity scoring against the four CSF tiers: Partial, Risk Informed, Repeatable, and Adaptive.
NIST CSF 2.0 is a flexible, risk-based framework that works best in OT when it is mapped to the standards built for industrial systems. It pairs naturally with IEC 62443 for control-system security and NIST SP 800-82 for ICS guidance. Arista Cyber helps operators run CSF as the program-level framework while implementing the OT-specific controls underneath it. Our OT cybersecurity services and IEC 62443 playbook go further than any checklist can, and we bring functional safety expertise most firms cannot.