NIST CSF 2.0, the website owner's edition

Six questions every website owner should be able to answer. Most can answer two.

The NIST Cybersecurity Framework boils security down to six jobs. Here's what each one means for your website, and an 18-point self-check to see which jobs nobody is doing.

Updated October 8, 2026

Most website owners only do one of the six.

They protect. They buy a security plugin, turn on HTTPS, maybe add a firewall. Then they stop.

It feels like enough. But think about what happens on the day protection fails, because one day it will.

Would you notice? Who would you tell? How fast could you get the site back? Who even decides any of this?

If the answer is a shrug, that's the gap attackers live in.

The US National Institute of Standards and Technology, NIST, publishes a free framework that most of the security world uses to describe this. Version 2.0 came out in 2024. It splits security into six functions: Govern, Identify, Protect, Detect, Respond and Recover.

It was written for whole organizations, from hospitals to power companies. So we translated each function into what it means for one website and the services behind it, and turned it into 18 yes-or-no questions.

Tick the ones that are true today. It takes about ten minutes.

The NIST CSF 2.0 website self-check

Govern

New in version 2.0, and placed at the center of the framework on purpose. Every other function fails without it.

On a real site: the owner thinks the developer handles security. The developer thinks the host does. The host's contract says it's the customer's job. Nobody patched anything for 14 months.

In our audit: Standard area 01 (scope and ownership), 02 (risk) and 07 (suppliers).

Identify

You can't protect a plugin you forgot you installed, or a test site you forgot you built.

On a real site: the store runs 41 plugins. The owner can name nine. Three haven't been updated by their makers in four years.

In our audit: Standard area 01 (scope), 02 (risk assessment) and 04 (patching).

Protect

The function everyone knows. The OWASP Top 10 guide goes deeper on the website itself.

On a real site: the admin login has a strong password. It's also shared by four people, one of whom left the company in 2023.

In our audit: Standard area 03 (access), 04 (configuration), 05 (application security) and 06 (data protection).

Detect

The function website owners skip most. It's why so many break-ins are discovered by a customer, a bank or Google instead of the owner.

On a real site: a card skimmer sits on the checkout page for 11 weeks. The owner finds out when the payment processor calls about fraud reports.

In our audit: Standard area 08 (backups and monitoring). Fortified Watch keeps checking every month.

Respond

Decisions made in a panic are expensive. Decisions made in advance are cheap. Our hacked website guide is a good start.

On a real site: the owner restores last night's backup to make the problem go away. It contained the backdoor. The site is hacked again by Friday.

In our audit: Standard area 09 (incident response). We give you a plan template and walk through it with you.

Recover

Every backup works until you need it. The only proof is a restore.

On a real site: the host's nightly backups live in the same account as the site. Ransomware encrypts both.

In our audit: Standard area 08 (backups) and 09 (incident response). We test a restore with you instead of taking it on trust.

0 / 18

Tick each statement that is true for your site.

Send my score for a free review

Where did you lose points?

If you're like most website owners, Protect scored fine. Detect, Respond and Recover didn't.

That's not a coincidence. Protect is the part security products sell. The other three are habits, plans and checks, and nobody sells those in a plugin.

It's also exactly what our Certification Audit covers. A real person tests your site like an attacker, then checks the ownership, suppliers, monitoring, response plan and backups around it like an auditor, against a standard built on ISO/IEC 27001. You get a plain-English report, every finding ranked by risk, a retest, and the Hacker Fortified Certified badge when the serious issues are gone.

Then Fortified Watch keeps the Detect function running every month, so you're not relying on a customer to tell you.

The best time to find out is before they do.

Start a free written conversation

The six functions

What each function means for a website.

NIST CSF 2.0 has 6 functions, 22 categories and 106 subcategories. Here are the categories that matter most for a website, in our own words.

FunctionFor your websiteSelf-check
Govern (GV)Context, risk strategy, roles, policy, oversight and supply chain.Who owns the site's security, what you can't afford to lose, and what your host, developer and plugin makers are responsible for.n1–n3
Identify (ID)Asset management, risk assessment and improvement.A list of every plugin, account and service. Regular checks for known weaknesses. Lessons written down after every incident.n4–n6
Protect (PR)Identity and access, awareness, data security, platform security and resilience.Two-step logins, personal accounts, timely updates, HTTPS everywhere and keeping less customer data.n7–n9
Detect (DE)Continuous monitoring and adverse event analysis.File-change and malware alerts, new-admin alerts, and logs kept somewhere safe.n10–n12
Respond (RS)Incident management, analysis, reporting and mitigation.A written hacked-site plan, knowing your notification duties, and a fast way to take the site offline.n13–n15
Recover (RC)Recovery plan execution and communication.Off-site, automatic backups, a tested restore, and a clear limit on how long you can be down.n16–n18

Questions

About NIST CSF 2.0.

What is the NIST Cybersecurity Framework 2.0?

It's a free framework from the US National Institute of Standards and Technology for managing cybersecurity risk. Version 2.0, published in February 2024, organizes security into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It's written for organizations of every size and sector, not just government.

Can my website be NIST CSF certified?

No. There is no official NIST CSF certification for any organization or website. The framework is voluntary guidance. Anyone selling a NIST certificate is selling their own mark. What you can do is assess your site against the framework and show your results. Our own badge, Hacker Fortified Certified, is our mark too, and we say so.

What changed in NIST CSF 2.0?

The biggest change is a sixth function, Govern, which covers who owns security decisions, how risk is managed and how suppliers are handled. Version 2.0 also widened the framework's audience from critical infrastructure to all organizations and added quick-start guides, including one for small businesses.

How does NIST CSF relate to ISO 27001?

They cover much of the same ground. ISO/IEC 27001 is a certifiable management system standard with a defined set of controls, while NIST CSF is a voluntary framework describing outcomes. NIST publishes mappings between the two. Our audit is built on ISO/IEC 27001 and our findings can be read against the CSF's six functions.

A customer asked us to "align with NIST". What do they want?

Usually, evidence that you've thought about all six functions, not just Protect: an owner, a risk list, monitoring, an incident plan and tested backups. A completed self-check like the one above, followed by an independent review, is a strong answer.

Is Hacker Fortified affiliated with NIST?

No. We're an independent website security firm, and this is our own plain-English guide. The official framework and its quick-start guides are free at nist.gov/cyberframework.

Function and category names refer to the NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, published February 26, 2024. Use of NIST material does not imply endorsement by NIST. The current version is always at nist.gov/cyberframework.