NIST CSF 2.0 has six core functions, Govern, Identify, Protect, Detect, Respond, and Recover, and meeting it means documenting policies and evidence across all six, not just buying a scanning tool. Below is a practical, skimmable checklist you can use to gauge where your organization stands and what a real assessment will look for.
What Changed in NIST CSF 2.0
The 2024 update added a sixth function, Govern, on top of the original five (Identify, Protect, Detect, Respond, Recover). Govern formalizes what most assessors were already asking about informally: does leadership actually own cyber risk, is there a documented risk strategy, and does the board or executive team get regular reporting. If your last NIST CSF exercise predates 2024, treat this checklist as a re-baseline, not a refresh.
Govern: Leadership and Risk Strategy Checklist
- Documented cybersecurity risk strategy approved by leadership, not just an IT policy binder nobody reads.
- Named accountability, someone (often a fractional CISO for smaller firms) owns the program and reports on it.
- Supply chain risk policy covering how you vet vendors and subprocessors, especially SaaS tools touching customer data.
- Roles and responsibilities for security decisions are written down, not tribal knowledge.
- Legal and regulatory obligations mapped, including PIPEDA federally and Quebec's Law 25 if you handle Quebec residents' data.
Identify: Asset and Risk Inventory Checklist
- Asset inventory covering hardware, software, and data flows, including shadow IT and forgotten cloud accounts.
- Data classification that distinguishes public, internal, and sensitive/regulated data.
- Risk assessment performed at least annually, with findings tied to actual remediation tickets.
- Vendor and third-party inventory, especially for SaaS companies passing data through multiple subprocessors.
Protect: Access Control and Hardening Checklist
- Multi-factor authentication enforced on all privileged and remote access, not just the admin console.
- Least-privilege access control with periodic access reviews, not permissions granted once and forgotten.
- Data protection controls, encryption at rest and in transit, backup policies, and secure disposal.
- Security awareness training delivered on a schedule, with records kept as evidence.
- Configuration and patch management for endpoints, servers, and cloud infrastructure.
Detect: Monitoring and Anomaly Detection Checklist
- Continuous monitoring of networks and systems for anomalous activity, appropriately scoped to your environment's size.
- Logging and log retention sufficient to reconstruct an incident after the fact.
- Detection processes tested periodically, not assumed to work because a tool is installed.
Respond and Recover: Incident and Continuity Checklist
- Written incident response plan with defined roles, escalation paths, and communication templates.
- Tabletop exercises run at least annually so the plan gets tested before a real incident forces the issue.
- Breach notification procedures that account for PIPEDA timelines and any provincial requirements.
- Business continuity and disaster recovery plan, with backups actually tested for restoration, not just scheduled.
- Post-incident review process to feed lessons learned back into the Protect and Detect functions.
Common Gaps We See in Canadian SMBs and Scale-ups
Working with growth-stage companies across Toronto, Waterloo, Ottawa, Vancouver, Calgary, and Montreal, the same gaps show up repeatedly: the Govern function is thin because nobody owns risk full-time, the asset inventory is out of date within months of being built, and incident response plans exist on paper but have never been rehearsed. None of these are hard to fix, but they take an outside eye to catch before a customer's security questionnaire or an auditor catches them for you.
How This Differs From SOC 2 or ISO 27001
NIST CSF is a risk management framework, not a certification you can hand a customer as proof. Many Canadian tech companies use it as the internal roadmap that later feeds a SOC 2 report or ISO 27001 certification when a US enterprise customer demands one. If you are unsure which path fits your sales motion, our compliance solutions overview breaks down how these frameworks relate and where NIST CSF fits as a starting point.
Turning This Checklist Into a Real Posture
A checklist tells you what to look for, it does not tell you how far off you are or what to fix first. That is the gap a structured NIST CSF assessment closes: scoring your current maturity against all six functions, then building a prioritized roadmap instead of a to-do list that never gets tackled in order.
If you want a straight answer on where your organization stands against NIST CSF 2.0, or how it lines up with a SOC 2 or ISO 27001 push you're already planning, get in touch with traztech and we'll walk through it.