NIST CSF 2.0 works best as a shared maturity language across teams, not a control checklist. Here is the practical read of each function for an operator running critical infrastructure.

Govern

Do you have a documented risk strategy, clear roles, and real oversight of third-party and supply chain risk -- or does cybersecurity governance exist only informally?

Identify

Do you have a current, accurate asset inventory and a risk assessment that reflects your actual environment, not one written once and never revisited?

Protect

Are your safeguards -- access control, segmentation, hardening, training -- proportionate to the consequence of the assets they protect?

Detect

Can you actually see a relevant threat scenario happening, or does your monitoring coverage exist mostly on an architecture diagram?

Respond

Is there a rehearsed, OT-aware incident response plan with clear authority for isolation decisions -- or would the first real incident be the first real test of the plan?

Recover

Can you restore operations safely and verify integrity before reconnecting systems, and do you capture lessons learned afterward, or does the program reset to zero after every incident?

Score each function honestly on a simple maturity scale and invest first in your weakest function -- not evenly across all six.