Regulatory Playbook · United States

NIST CSF 2.0 Compliance Checklist for OT

Assess your cybersecurity program against all six NIST CSF 2.0 functions and 22 categories, including the new Govern function, with a checklist built for OT and ICS environments.

6Functions
22Categories
106Subcategories
4Maturity tiers
Maturity Assessment
NIST CSF 2.0 Compliance Checklist for OT
  • What changed in CSF 2.0 and the new Govern function
  • All six functions mapped across 22 categories
  • Function-by-function assessment built for OT and ICS
  • Maturity scoring against the four CSF tiers
  • A board-ready way to report program maturity
  • IEC 62443 and NIST SP 800-82 mapping for OT

The NIST Cybersecurity Framework is the most widely used cybersecurity framework in the United States, and version 2.0 brought the biggest change in its history. Released in February 2024, CSF 2.0 introduced a sixth function, Govern, which now sits at the center of the framework and wraps the five that came before it.

If you are working from older material, you will still see the five-function model. That model is out of date. This checklist is built on CSF 2.0—all six functions and 22 categories—and is specifically written for OT (Operational Technology) and ICS (Industrial Control Systems). It maps the framework to industrial realities and to IEC 62443, rather than treating it as IT-only.

What is inside The checklist walks all six CSF 2.0 functions

For each category you get a plain-language description, an assessment prompt, and a status field, plus maturity scoring against the four CSF tiers: Partial, Risk Informed, Repeatable, and Adaptive.

01
FUNCTION 1 · NEW
Govern (GV)
Strategy, policy, roles and responsibilities, risk management strategy, oversight, and supply chain risk management. New in 2.0 and central.
02
FUNCTION 2
Identify (ID)
Asset management, risk assessment, and the understanding of your OT environment—everything else builds on.
03
FUNCTION 3
Protect (PR)
Identity and access control, training, data and platform security, and the resilience of your technology infrastructure.
04
FUNCTION 4
Detect (DE)
Continuous monitoring and adverse event analysis, so incidents in OT are found quickly.
05
FUNCTION 5
Respond (RS)
Incident management, analysis, reporting, and mitigation when an OT incident occurs.
06
FUNCTION 6
Recover (RC)
Incident recovery planning and communication, so critical operations are restored safely.

Who it is for

Built for the people who own the program
  • OT and ICS security leaders building or benchmarking a program
  • CISOs and security teams reporting program maturity to the board
  • Compliance and GRC leads mapping OT security to a recognized framework
  • Operators who need a common language between IT and OT security
  • Consultants and integrators assessing OT programs against CSF 2.0

Why use it

  • Move from the old five functions to the new six. Work from CSF 2.0 — assess maturity against the latest functions, including the new Govern pillar, not the retired 1.1 model.
  • Built for OT, not just IT. This checklist is mapped to real OT and industrial requirements, and aligned with IEC 62443 for relevance in engineering and operational settings.
  • Score your maturity across the four CSF tiers. Evaluate each function and category using the tiered approach designed by NIST to benchmark progress and gaps.
  • Speak one language to the board. The CSF is the framework recognized by executives — use its language and scoring to clearly report security status and needs.

NIST CSF, IEC 62443, and OT Security

NIST CSF 2.0 is a flexible, risk-based framework that works best in OT when it is mapped to the standards built for industrial systems. It pairs naturally with IEC 62443 for control-system security and NIST SP 800-82 for ICS guidance. Arista Cyber helps operators run CSF as the program-level framework while implementing the OT-specific controls underneath it. Our OT cybersecurity services and IEC 62443 playbook go further than any checklist can, and we bring functional safety expertise most firms cannot.

Frequently Asked Questions

The NIST Cybersecurity Framework, CSF 2.0, is a voluntary, risk-based framework for managing cybersecurity risk, published by the US National Institute of Standards and Technology in February 2024. It is the most widely used cybersecurity framework in the United States and applies across IT and OT.
The six functions are Govern, Identify, Protect, Detect, Respond, and Recover. Govern is new in version 2.0 and sits at the center of the framework, covering strategy, policy, roles, risk management, and oversight.
The biggest change is the addition of the Govern function, raising governance to a function in its own right. CSF 2.0 also broadened its scope to all organizations and strengthened supply chain risk management. In total it has six functions, 22 categories, and 106 subcategories.
The four tiers describe maturity: Tier 1 Partial, Tier 2 Risk Informed, Tier 3 Repeatable, and Tier 4 Adaptive. Tiers describe maturity, not a compliance score.
Yes. CSF 2.0 is framework-agnostic and applies to OT and ICS as well as IT. In industrial environments it works best when mapped to IEC 62443 and NIST SP 800-82, which provide the control detail CSF leaves to the organization.
It turns CSF 2.0 into a function-by-function and category-by-category assessment tool, with tier scoring, written for OT. For hands-on support, explore our OT cybersecurity services.