NIST CSF 2.0
NIST · Cybersecurity Framework SIGNET support: Compliance enablement
What it is
The NIST Cybersecurity Framework is the United States' voluntary framework for managing cybersecurity risk, organised around six functions — Govern, Identify, Protect, Detect, Respond, and Recover. Version 2.0, released in 2024, extended the framework's scope beyond critical infrastructure to organisations of every size and elevated governance and supply-chain risk to first-class concerns.
The framework is maintained by the US National Institute of Standards and Technology. Official reference →
How SIGNET supports it
NIST CSF sits in SIGNET's compliance enablement tier. SIGNET is a data standard, not a security control framework; the claim is not that SIGNET implements the CSF but that a SIGNET network's architecture supplies properties the framework asks organisations to achieve — particularly in its Govern function and its supply-chain risk emphasis.
Three properties do the work. Counterparty attestations of framework alignment travel as verifiable credentials, checkable and referenceable from eligibility policies rather than asserted in questionnaires. Governance is data: authority, thresholds, and approval routing are machine-readable Policy objects and agent Mandate bounds, so the organisation's rules are inspectable rather than tribal. And the record is tamper-evident: every material change is an append-only, hash-chained Event with provenance, giving the integrity and traceability that detection and response depend on when the question becomes what happened, and who authorised it.
Where it lives in the standard
- Trust Layer — Event, Provenance
- Agent Layer — Policy, Mandate
- Foundation Layer → Credential — attestations as data