# NIST CSF 2.0 — Path to Tier 3 (July 2026)

CSF 2.0 (Feb 2024): **Govern** + Identify, Protect, Detect, Respond, Recover.

## Govern first

- [ ] Risk appetite / roles / policy cadence documented
- [ ] Supply-chain oversight; metrics to leadership

## AWS mapping (minimum)

- [ ] ID: Config + Resource Explorer + tagging
- [ ] PR: IAM Identity Center, KMS, WAF/ANF as needed
- [ ] DE: GuardDuty Org, Security Hub, optional Security Lake
- [ ] RS: EventBridge runbooks; tabletop
- [ ] RC: Backup + restore tests logged

## Counter-case

No CSF “certification.” Use ISO/SOC2/CMMC for external badges; CSF organizes outcomes.
