NIST CSF in 2026: What AI risk is changing and the problem with self-assessment
Are you self-evaluating your security controls against the NIST CSF? Your NIST CSF controls may have been well-designed when they were built. But that was for a different operating environment and threat landscape.
So if you’re relying on internal judgement as to whether those controls still hold up, you’re probably less aligned (and more exposed) than you think. That’s the likely outcome of self-assessment: the “creator bias” is there, but current external benchmarks, scrutiny, or adversarial perspective isn’t.
The gap between where you think you are and where you really are is a major security risk. And AI-assisted attack methods have made that risk greater. In response, NIST has released draft guidance applying CSF 2.0 to AI risk. So, if your organisation hasn’t caught up with the base framework yet, what’s coming next will be a shock to the system.
What’s new in NIST CSF 2.0
In early 2024, NIST released CSF 2.0, the current standard at the same of writing.
These are the key changes introduced in NIST CSF 2.0
The Govern function
NIST CSF 2.0 adds a sixth function: Govern. Sitting above the other five functions, it formalises two crucial cyber security considerations: who’s accountable for cyber security decisions, and is that reflected in how the organisation operates?
Governance is a complex task, covering security policy, oversight and risk strategy. Overlook it even just a little, and your security controls won’t work as well as they should. Yet, that’s exactly what most organisations do, preferring to back their controls and avoid distributing accountability. That’s why governance is now a standalone function. And it’s one organisations need to get right before the focus moves to technical controls.
Cybersecurity Supply Chain Risk Management (C-SCRM)
You can have the strongest security controls money can buy, but they won’t matter if legitimate credentials sit in a less secure environment somewhere else.
Many recent high-profile data breaches (such as those impacting Qantas, MediSecure and several Australian educational institutions) have started the same way. The organisation gets compromised via a third-party suppliers. It’s not that those third parties are inherently less secure. The issue comes down to alignment between suppliers’ controls and your own – that alignment gap is what adversaries exploit. That’s why CSF 2.0 expects organisations to have full visibility on what access their suppliers have. Most don’t have that picture. In a fast-moving threat landscape, a questionnaire sent out once a year isn’t good enough.
Maturity Tier clarification
NIST have clarified the meaning and purpose of their maturity tiers.
NIST CSF 2.0 described tiers as a reflection of the maturity of your risk management practices. Your tier doesn’t necessarily reflect how compliant you are. And not every organisation needs to reach Tier 4 to maintain a secure environment. The right NIST CSF tier for your organisation depends on your operational reality, resources and risk appetite. A small professional services firm and a major bank shouldn’t be aiming for the same Tier. And Tier 4 controls on paper mean nothing if, in practice, they don’t offer the protection that well-managed Tier 3 controls do. To reflect this, NIST CSF assessments must rate what the controls are doing day-to-day, instead of what the documentation says they can do.
These updates clarify the security posture the current threat landscape demands. Still, a lot of the discussion you’ll find on NIST CSF, and a lot of the assessments being conducted against it, are still anchored to version 1.1. Procurement cycles and internal training materials take time to catch up.
NIST’s answer to AI risk – a work in progress
In December 2025, NIST released the preliminary draft of NIST IR 8596 — the Cybersecurity Framework Profile for Artificial Intelligence, or the Cyber AI Profile. It’s not a new framework. It’s a community profile built on CSF 2.0, applying its existing structure to AI-specific risk categories.
The profile organises AI risk into three focus areas.
Secure: covers the cyber security challenges that come with adopting AI and integrating it into your environment. Every AI tool embedded in your organisation is an attack surface that must be mapped.
Defend: covers the use of AI to enhance cyber security operations, and the risks that creates. AI-assisted threat detection is increasingly common, but with its productivity enhancements, it also introduces risks. To minimise it, you need clear understanding of what happens when those tools fail, produce bad outputs or get manipulated.
Thwart: covers resilience against adversaries already using AI to operate at scale. This includes controls that work against automated phishing, deepfakes, adaptive malware and evasion of traditional detection methods.
The Cyber AI Profile is still a preliminary draft. NIST expects to release an initial public draft later in 2026, with subsequent revision before it’s finalised. So, while not yet a mandate, the three focus areas are a useful reference point if you’re navigating AI risk against your NIST-aligned controls.
Most Australian organisations have exposure across all of them and governance around none. The urgency to close that gap should be high. According to the SANS Institute, the mean time‑to‑exploit has fallen from 2.3 years in 2019 to less than a day by 2026. Advanced AI models, such as Anthropic’s Mythos, are expected to turn this to near-instant. AI-enabled attacks require AI enabled defences.
But no AI defence strategy survives a weak foundation. Amid AI threats, the fundamentals still matter more than anything. So, before you can address AI risk, you’ll first need clarity on whether your security foundations hold up.
Where NIST CSF controls typically fall short
When we assess an organisation’s NIST alignment, we typically see the same issues come up – regardless of the organisation’s self-assessed security maturity.
Governance accountability
Security policies exist, but no one’s accountable for making sure everyone in the organisation follows them. Without clear governance at executive and board level, security decisions default to the technical teams that execute them. This is how security controls lose their consistency. Leadership believes a control is in place when it isn’t – because the technical team teams never got a clear mandate to implement and manage it from an accountable person. This is the issue the “Govern” function aims to solve.
Supply chain visibility
Most organisations have the best of intentions when it comes to managing third party risk and maintaining robust documentation for key vendors. Still, visibility across the entire supply chain often relies on assumptions rather than detailed mapping. Effective risk registers treat every vendor like they’re the only one, highlighting what data they can access and how critical they are to operations. Those details are what stops supplier compromise.
Incident response
While every organisation has a documented incident response plan, most aren’t truly ready to be tested by an actual incident. Tabletop exercises, when they happen at all, tend to validate the plan rather than pressure-test it. What’s more, most exercises avoid the governance aspect – who calls the breach, who notifies the regulator, who talks to the board. This is the first thing that gets exposed under real breach conditions, and failure here sets the tone for the entire response.
Control evidence quality
Security controls can look good on paper but fail as soon as they’re tested. NIST self-assessments often tick the first box without considering the second. To be truly NIST-aligned, your organisation needs to prove its controls actually work as intended. Any NIST CSF assessor worth their fee will look for evidence of this.
Notice a common theme? These challenges map perfectly to the very issues NIST aimed to address with 2.0. That’s the beauty of the NIST CSF. It’s comprehensive, well-governed and always evolving with the threat landscape. Aligning your controls with it gives you a solid north star for continuous security improvements. The organisations that treat NIST alignment as a one-off project or an annual box-ticking exercise won’t see its benefits. That’s not NIST’s problem.
Why now? NIST CSF 2.0 considerations for your next NIST CSF Assessment
The cyber threat landscape is already very different to a few years ago. NIST CSF 2.0 reflects those shifts. The emergence of AI-enabled threats means further disruption is on the horizon. If your NIST CSF assessment’s reliant on work a cyber security consultant did in 2023 or earlier, your accreditation doesn’t prove what it’s supposed to.
When done right, NIST CSF alignment makes a strong, continuous contribution to your organisation’s cyber security and regulatory compliance obligations. But self-assessments alone rarely reach that outcome. Resource constraints, inertia and self-assessment bias all work against objectivity. An independent assessment of your cyber security controls against NIST CSF is the only way to know for sure whether your security controls will hold up where NIST says they should.
What to expect from a NIST CSF Assessment
A NIST CSF assessment should give you clarity on where you stand right now, where you should be, how best to close the gaps – and in what order.
Your team, whether technical or non-technical, should be able to look at the assessment report and answer the following questions with confidence.
- Which gaps are the highest risk, and should be prioritised? The report’s findings should clearly classify every gap by exploitation risk, so everyone’s on the same page about what to fix first.
- Who owns each gap? “IT team” or “Security Team” is a copout answer here. The report should assign an accountable person to each gap. NIST CSF’s govern function makes this expectation clear. So should your NIST CSF assessment.
- What gets fixed when? This is the assessment’s ultimate outcome, combining the what and when into a detailed roadmap with a clear timeline. There’s a 90-day action plan covering high-priority “must-fix” items, and clear medium to long-term horizons for everything else.
And finally, for all this to hold up, the assessment report should be written and presented in plain language. Of course, a level of technical detail is unavoidable. But for every gap, there’s a business impact that can, and must, be articulated in a way that everyone can understand.
That’s the difference between an assessment that drives change and one that sits in a drawer
Slipstream Cyber’s approach to NIST CSF Assessments
A rapidly scaling financial services business was in a familiar position. Years of growth had outpaced its infrastructure, and therefore security governance. With APRA obligations creating board-level scrutiny, the question of where the business’s cyber security posture was a burning one. They needed to know not only where they stood, but what the benchmark for improvement was. An internal attempt to build their own cyber security framework had stalled. The roadblock? Without an external benchmark, there was no way to know if what they were measuring actually mattered.
That’s where we came in. We used NIST CSF as the benchmark to assess the organisation’s security controls against. NIST CSF’s comprehensive risk management methodology gave leadership a credible, recognised standard to measure against as they worked to make their controls fit for purpose.
The assessment revealed that security maturity across key controls was lower than the organisation’s scale and regulatory exposure required. But that wasn’t the real outcome. The NIST CSF assessment gave the board something they didn’t have before — a clear picture of where the gaps were, their potential impact how to address them. Findings were prioritised from immediate risks requiring urgent remediation down to issues that could be sequenced over the coming months. Each was framed in language the board could act on.
What started as a scoped assessment became a longer engagement. As the remediation program progressed, internal resource constraints slowed momentum. Slipstream’s embedded security expertise filled the gap, keeping the uplift on track without forcing the organisation to hire permanently for a transitional need.
Ultimately, the assessment was the starting point in an important journey for the organisation. It saw cyber security shift from a persistent board-level anxiety to a managed, measurable program of work. That’s what NIST CSF alignment is meant to deliver.
See where you stand: get a NIST CSF assessment
Looking to align your NIST security controls with today’s cyber threat landscape? An assessment is the first step is an assessment.
Slipstream’s cyber security consultants can help you get clarity on your security posture against NIST’s expectations, including around managing AI risk as updated guidance comes to light.
If you’re looking to assess alignment with other frameworks, such as the Essential Eight or ISO 27001, we can consolidate these into a single, comprehensive assessment. If you’re not sure what, if any, other frameworks your organisation should focus on, we can guide you on that as well.
Contact our team to find out more or book your assessment.
FAQ
What is the NIST Cybersecurity Framework
The NIST Cybersecurity Framework (NIST CSF), is a framework for managing cyber security developed by the U.S. National Institute of Standards and Technology (NIST). It provides a broad, comprehensive and risk-based approach to managing cyber security.
First released in 2014 and updated to version 2.0 in 2024, the NIST CSF is now widely used across industries as a common way to manage cyber risk. While originally developed for critical infrastructure in the United States, it’s now used by organisations of all sizes globally.
How is the NIST CSF different from other frameworks?
Unlike other frameworks that guide a more prescriptive approach, NIST CSF is flexible. It defines what a secure environment should look like, rather than outlining exactly how to achieve it. This allows you to apply it in a way that best fits your organisation’s environment.
As such, the Essential Eight is typically used as a structure to guide how you organise and communicate cyber risk. In Australia, organisations typically use the NIST CSF alongside local frameworks such as the Essential Eight, global standards like ISO 27001 or industry-specific standards such as APRA CPS 234.
What are the six core functions of NIST CSF 2.0
The NIST CSF 2.0 is structured around six core functions. Together, they span the full cyber security lifecycle, from strategy through to incident response and recovery.
Identify involves understanding the assets you have (across systems, data and the organisational capabilities they support) and the cyber security risks they carry. This includes asset management, risk assessment and understanding the business context behind your most important assets.
Protect focuses on putting safeguards in place to keep critical systems and data secure. This includes access controls, data protection and implementing security controls.
Detect ensures you can identify cyber security incidents as they occur through continuous monitoring, alerting and identifying unusual behaviour.
Respond defines how you act on incidents when they’re detected. It covers containment, investigation and stakeholder communication.
Recover outlines how to restore your organisation’s operations following a cyber incident. It includes recovery planning, follow-up stakeholder communications and acting on the lessons learnt from the incident.
Govern (new in 2.0) sits at the top, overseeing the other five functions. It defines how your organisation manages cyber risk is managed across your organisation, setting expectations, policy and accountability at a leadership level. Governance is what connects cyber security to enterprise risk and board oversight.
What are the NIST CSF implementation maturity Tiers?
The NIST CSF includes an implementation tier model (Tier 1-4) to help organisations assess and communicate their cyber security maturity.
The Tiers are:
Tier 1 (Partial): Risk management activities are reactive and informal, and are managed on an ad-hoc basis.
Tier 2 (Risk Informed): Risk management practices are approved, but not applied consistently across the organisation.
Tier 3 (Repeatable): Organisation-wide policies and processes are formally defined and consistently followed.
Tier 4 (Adaptive): The organisation continuously improves, adapting its approach based on lessons learned and predictive indicators.
This tier progression helps you measure your organisation’s security maturity, and provides tangible guidance for planning security improvements.
Which organisations should use the NIST CSF?
NIST CSF 2.0 is particularly suited to organisations that need a comprehensive, flexible approach to managing cyber security risk.
This includes large enterprises, organisations with international operations and those in highly regulated industries such as finance, healthcare and energy.
It’s also well suited to organisations already using other NIST standards, or those looking to complement the use of tactical controls and frameworks (such as the Essential Eight) with a stronger strategic governance layer.
What are NIST CSF’s Strengths as a cyber security risk management framework?
Comprehensive coverage: the NIST CSF addresses the full cyber security lifecycle, from governance through to recovery.
Flexible and adaptable: as a standardised framework, it works across organisations of any size or sector.
Risk-based approach: it helps you understand the highest-risk areas of your security posture, so you know where to focus your resources and effort.
Global recognition: the framework is understood worldwide, giving you a common language to communicate your cyber security posture with international stakeholders.
Strong governance alignment: the Govern function seamlessly connects cyber security to business strategy.
Maps to other standards: the NIST CSF can easily align with other common cyber security frameworks such as ISO 27001, the Essential Eight and CIS Controls.