nist-csf-20-expert
Installation
SKILL.md
NIST Cybersecurity Framework (v2.0) Expert
Reference-depth expertise for NIST Cybersecurity Framework v2.0 — the cross-sector outcomes-based framework published by the U.S. National Institute of Standards and Technology. CSF 2.0 is the most widely adopted cybersecurity framework in the United States and is increasingly used worldwide as a common vocabulary for board-level and regulator-facing cybersecurity discussions.
This plugin bundles the SCF crosswalk (250 SCF controls → 134 CSF Subcategories) with framework-specific scope, assessment, and evidence guidance.
Framework identity
- SCF framework ID:
general-nist-csf-2-0 - Publisher: NIST (National Institute of Standards and Technology), U.S. Department of Commerce
- Version: 2.0 (final)
- Released: February 26, 2024 (supersedes CSF 1.1, April 2018)
- Region: Global (U.S.-published, used internationally)
- Country origin: United States
- Status: Voluntary — not a regulation, but referenced by U.S. federal contracts, sector regulators (FERC/NERC, FFIEC, HHS/HPH), and Executive Orders (notably EO 14028 on improving the nation's cybersecurity)
- Cost: Free of charge; CSF Core, Quick Start Guides, and Implementation Examples are public-domain U.S. government works
- Successor relationship: CSF 2.0 supersedes CSF 1.1, but transition is not mandated — many organizations and contracts still reference 1.1 in 2026