NIST CSF 2.0 works best as a shared maturity language across teams, not a control checklist. Here is the practical read of each function for an operator running critical infrastructure.
Govern
Do you have a documented risk strategy, clear roles, and real oversight of third-party and supply chain risk -- or does cybersecurity governance exist only informally?
Identify
Do you have a current, accurate asset inventory and a risk assessment that reflects your actual environment, not one written once and never revisited?
Protect
Are your safeguards -- access control, segmentation, hardening, training -- proportionate to the consequence of the assets they protect?
Detect
Can you actually see a relevant threat scenario happening, or does your monitoring coverage exist mostly on an architecture diagram?
Respond
Is there a rehearsed, OT-aware incident response plan with clear authority for isolation decisions -- or would the first real incident be the first real test of the plan?
Recover
Can you restore operations safely and verify integrity before reconnecting systems, and do you capture lessons learned afterward, or does the program reset to zero after every incident?
Score each function honestly on a simple maturity scale and invest first in your weakest function -- not evenly across all six.