NIST CSF Updates: New Governance and AI Risk Requirements Explained
A lot of California businesses still describe NIST compliance the same way they did in 2019: firewalls, patch cycles, an incident response binder nobody has opened since the tabletop exercise. That checklist mentality stopped matching reality when NIST published Cybersecurity Framework (CSF) 2.0 in February 2024, and the gap has only widened since. CSF 2.0 added a sixth core function -- GOVERN -- that sits at the center of the framework's wheel diagram, not off to the side as an afterthought. It informs how the other five functions (Identify, Protect, Detect, Respond, Recover) get resourced, staffed, and reported up to leadership. If your last NIST-aligned assessment was really just a network vulnerability scan with a compliance label on it, you are not assessed against the framework NIST actually publishes today.
GOVERN is built around six subcategories: organizational context, risk management strategy, roles and responsibilities, policy, oversight, and -- critically -- supply chain risk management (GV.SC). That last one is not a minor addition. GV.SC requires organizations to establish enterprise-wide policies for identifying, assessing, and managing cybersecurity risk across suppliers, not just scanning your own network perimeter. For a California business that outsources payroll, uses a cloud-hosted EHR, or runs its point-of-sale system through a third-party processor, GV.SC means your vendor's security posture is now explicitly part of your NIST profile -- documented, assessed, and revisited on a cadence, not assumed. This mirrors a pattern we've written about before: a single compromised vendor can cascade into every downstream client, which is exactly the scenario broken down in our piece on MSP supply chain risk and what a vendor breach really means for your business. NIST CSF 2.0 essentially codifies that same concern into a governance requirement instead of leaving it as best-practice advice.
The framework's scope language changed too, and it is easy to miss if you are working from an old summary instead of the actual document. CSF 2.0 states plainly that its guidance applies to information technology, the Internet of Things, operational technology, and all technology environments -- explicitly including cloud, mobile, and artificial intelligence systems. That is a meaningful expansion for property owners and multifamily operators running building automation, elevator controllers, or HVAC systems on OT networks that were historically air-gapped from the AI conversation entirely. If your access control panels, fire alarm monitoring, or building management system share a network segment with anything internet-facing, CSF 2.0's OT language now applies to that segment, and your GOVERN documentation needs to say so.
AI is the piece most California SMBs are underprepared for. NIST didn't fold AI risk directly into CSF's technical subcategories -- instead it points organizations toward the companion NIST AI Risk Management Framework (AI RMF) for AI-specific trustworthiness, bias, and safety concerns, while CSF's GOVERN function is where the two frameworks are meant to intersect at the strategy level. In practice that means a business using AI tools anywhere in its operations -- automated underwriting, AI-assisted diagnosis support, generative content tools touching client data, or even a chatbot handling intake -- needs a documented risk treatment for that AI use case sitting alongside its broader cybersecurity governance, not bolted on separately after the fact. Auditors and cyber-insurance underwriters are increasingly asking where that documentation lives, and "we haven't gotten to that yet" is becoming a harder answer to give.

This shift did not happen in a vacuum. NIST has continued publishing sector-specific profiles built on the CSF 2.0 structure -- including recent work addressing GPS/PNT service disruption, supply chain threats, and AI risk in critical infrastructure contexts -- signaling that the GOVERN-centric model is the permanent direction, not a one-time revision. For businesses that operate under multiple compliance obligations simultaneously -- a defense subcontractor also handling protected health information, or a financial services firm also subject to state privacy law -- this actually creates an opportunity. NIST CSF 2.0's GOVERN function overlaps substantially with governance requirements in SOC 2, ISO 27001, and CMMC, meaning a single well-documented governance program can support multiple framework mappings rather than requiring separate paperwork for each. We've covered this convergence in more depth in our post on SOC 2 and framework mapping, where one audit increasingly satisfies multiple frameworks -- the same logic now extends cleanly into NIST CSF 2.0.
For California defense subcontractors specifically, this matters on a compressed timeline. CMMC Level 2 assessments lean heavily on NIST SP 800-171, which itself maps closely to CSF's Protect and Detect functions -- but CMMC's own governance expectations are trending toward the same GOVERN-style accountability structure, with named risk owners and board-level (or ownership-level) visibility into cyber risk decisions. If your organization is racing toward the November 2026 CMMC Level 2 deadline, building your GOVERN documentation now does double duty, and we've laid out the specific milestones in our CMMC Level 2 readiness checklist.
Healthcare-adjacent and senior living operators face a parallel problem. A GOVERN-aligned risk strategy has to account for AI-enabled tools touching protected health information -- scheduling assistants, care documentation tools, remote monitoring platforms -- and NIST's framing pushes organizations to document why each tool was adopted, what risk assessment was performed, and who signed off. That is a substantially higher bar than "we ran antivirus and called it done," and it dovetails directly with obligations under HIPAA's Security Rule, which is why we wrote separately about HIPAA risk assessments for multifamily senior living IT systems -- the assessment methodology NIST CSF 2.0 now expects looks a lot like what HHS guidance already expects of covered entities and their business associates.
The honest reality for most California SMBs and mid-market operators is that nobody internally owns this. IT handles patching. Ops handles vendor contracts. Nobody sits at the intersection asking "does our AI vendor's risk profile get documented anywhere, and who signed off on it?" That gap is exactly what GOVERN is designed to close, and it is exactly where a generic compliance checklist -- purchased once and filed away -- fails a real assessment. Building a defensible GOVERN function means mapping your actual vendor relationships, actual AI tool usage, and actual OT/IT network boundaries against the CSF 2.0 subcategories, then keeping that mapping current as vendors and tools change.
Figuring out which framework -- or combination of frameworks -- actually applies to your business is the first blocker most owners hit, and it's worth resolving before you spend money on an assessment aimed at the wrong target. Our free Compliance Framework Finder walks through your industry, data types, and existing obligations to identify which frameworks (NIST CSF, CMMC, HIPAA, SOC 2, and others) actually apply to your organization, so you're not paying for a NIST-aligned audit when your real exposure is elsewhere -- or missing NIST alignment when a client contract or cyber-insurance renewal is about to require it.
Mytek Pros holds California contractor's license #1116987, DIR public-works registration PW-LR-1001158430, and BICSI certification, and is DBE/DVBE/MBE certified -- credentials that matter here because NIST CSF 2.0 GOVERN documentation has to reflect how your systems are actually built and maintained, not just how a policy document says they should be. Our NIST framework alignment service builds your GOVERN, Identify, and Protect documentation around the network, OT, and AI tooling you actually run -- including the supply chain risk assessments GV.SC now requires -- so the paperwork matches the environment an assessor or insurer will actually find. If your last NIST assessment predates 2024, it's assessing a framework that no longer exists in its original form. Call (619) 353-5702 or email inquire@mytekpros.com to get your GOVERN function built out before your next audit, insurance renewal, or client security questionnaire catches the gap first.
Questions about audits? Get in touch or explore our Audits services.
