NIST CSF 2.0, the website owner's edition
Six questions every website owner should be able to answer. Most can answer two.
The NIST Cybersecurity Framework boils security down to six jobs. Here's what each one means for your website, and an 18-point self-check to see which jobs nobody is doing.
Updated October 8, 2026
Most website owners only do one of the six.
They protect. They buy a security plugin, turn on HTTPS, maybe add a firewall. Then they stop.
It feels like enough. But think about what happens on the day protection fails, because one day it will.
Would you notice? Who would you tell? How fast could you get the site back? Who even decides any of this?
If the answer is a shrug, that's the gap attackers live in.
The US National Institute of Standards and Technology, NIST, publishes a free framework that most of the security world uses to describe this. Version 2.0 came out in 2024. It splits security into six functions: Govern, Identify, Protect, Detect, Respond and Recover.
It was written for whole organizations, from hospitals to power companies. So we translated each function into what it means for one website and the services behind it, and turned it into 18 yes-or-no questions.
Tick the ones that are true today. It takes about ten minutes.
The NIST CSF 2.0 website self-check
Where did you lose points?
If you're like most website owners, Protect scored fine. Detect, Respond and Recover didn't.
That's not a coincidence. Protect is the part security products sell. The other three are habits, plans and checks, and nobody sells those in a plugin.
It's also exactly what our Certification Audit covers. A real person tests your site like an attacker, then checks the ownership, suppliers, monitoring, response plan and backups around it like an auditor, against a standard built on ISO/IEC 27001. You get a plain-English report, every finding ranked by risk, a retest, and the Hacker Fortified Certified badge when the serious issues are gone.
Then Fortified Watch keeps the Detect function running every month, so you're not relying on a customer to tell you.
The best time to find out is before they do.
The six functions
What each function means for a website.
NIST CSF 2.0 has 6 functions, 22 categories and 106 subcategories. Here are the categories that matter most for a website, in our own words.
| Function | For your website | Self-check |
|---|---|---|
| Govern (GV)Context, risk strategy, roles, policy, oversight and supply chain. | Who owns the site's security, what you can't afford to lose, and what your host, developer and plugin makers are responsible for. | n1–n3 |
| Identify (ID)Asset management, risk assessment and improvement. | A list of every plugin, account and service. Regular checks for known weaknesses. Lessons written down after every incident. | n4–n6 |
| Protect (PR)Identity and access, awareness, data security, platform security and resilience. | Two-step logins, personal accounts, timely updates, HTTPS everywhere and keeping less customer data. | n7–n9 |
| Detect (DE)Continuous monitoring and adverse event analysis. | File-change and malware alerts, new-admin alerts, and logs kept somewhere safe. | n10–n12 |
| Respond (RS)Incident management, analysis, reporting and mitigation. | A written hacked-site plan, knowing your notification duties, and a fast way to take the site offline. | n13–n15 |
| Recover (RC)Recovery plan execution and communication. | Off-site, automatic backups, a tested restore, and a clear limit on how long you can be down. | n16–n18 |
Questions
About NIST CSF 2.0.
What is the NIST Cybersecurity Framework 2.0?
It's a free framework from the US National Institute of Standards and Technology for managing cybersecurity risk. Version 2.0, published in February 2024, organizes security into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It's written for organizations of every size and sector, not just government.
Can my website be NIST CSF certified?
No. There is no official NIST CSF certification for any organization or website. The framework is voluntary guidance. Anyone selling a NIST certificate is selling their own mark. What you can do is assess your site against the framework and show your results. Our own badge, Hacker Fortified Certified, is our mark too, and we say so.
What changed in NIST CSF 2.0?
The biggest change is a sixth function, Govern, which covers who owns security decisions, how risk is managed and how suppliers are handled. Version 2.0 also widened the framework's audience from critical infrastructure to all organizations and added quick-start guides, including one for small businesses.
How does NIST CSF relate to ISO 27001?
They cover much of the same ground. ISO/IEC 27001 is a certifiable management system standard with a defined set of controls, while NIST CSF is a voluntary framework describing outcomes. NIST publishes mappings between the two. Our audit is built on ISO/IEC 27001 and our findings can be read against the CSF's six functions.
A customer asked us to "align with NIST". What do they want?
Usually, evidence that you've thought about all six functions, not just Protect: an owner, a risk list, monitoring, an incident plan and tested backups. A completed self-check like the one above, followed by an independent review, is a strong answer.
Is Hacker Fortified affiliated with NIST?
No. We're an independent website security firm, and this is our own plain-English guide. The official framework and its quick-start guides are free at nist.gov/cyberframework.
Function and category names refer to the NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, published February 26, 2024. Use of NIST material does not imply endorsement by NIST. The current version is always at nist.gov/cyberframework.