Manufacturers face a unique mix of cybersecurity risks, including legacy Operational Technology systems, remote vendor access, safety and equipment risks, and vulnerable industrial control systems. NIST Cybersecurity Framework (CSF) 2.0 provides the best practices necessary to manage those risks, with greater emphasis on governance and supply chain security. In September 2025, NIST released a draft “Manufacturing Profile” that builds on CSF 2.0 and applies specifically to manufacturing security needs. It provides industry best practices and guidance for reducing risk to manufacturing systems. To better understand how that guidance applies, it helps to first understand what has changed in CSF 2.0 and what its six core functions mean for manufacturers.
Why CSF 2.0 Matters for Manufacturers
Since its introduction in 2014, manufacturers have used the NIST Cybersecurity Framework (CSF) as a roadmap to manage and reduce cybersecurity risks within information and operational technology environments. In 2024, NIST released CSF 2.0 which added a dedicated governance function and heavier emphasis on supply chain risk. While the CSF was initially developed with critical infrastructure in mind, CSF 2.0 broadens its scope to organizations of varying sizes and industries. This update is especially relevant to manufacturing, which remains a frequent target for cyberattacks. IBM’s X-Force Threat Intelligence Index has ranked manufacturing as the most targeted industry globally for five consecutive years, accounting for more than 27% of identified cybersecurity incidents.
To further support manufacturing environments, NIST released the draft CSF 2.0 Manufacturing Profile (NIST IR 8183 Rev. 2) in September 2025. The profile provides a voluntary, structured approach to reducing risk across IT and OT systems, and strengthening operational resilience.
GOVERN: A New Addition in CSF 2.0
Clear cybersecurity governance defines how security decisions are made, who is accountable, and how risk is managed across an organization. CSF 2.0 formalizes this foundational concept through GOVERN, a new function added to the original five functions of Identify, Protect, Detect, Respond, and Recover. GOVERN addresses areas including roles and responsibilities, risk management, internal policy, supply chain risk, and leadership oversight. For manufacturers, this also includes third-party access management, remote maintenance connections, software integrations, and other supplier relationships that might affect production systems. The GOVERN function provides a bridge between an organization’s security program and executive leadership.
For additional details regarding governance in a compliance context, check out our blog, “how a vISO helps manufacturers prepare for CMMC, NIST 800-171, and customer audits.”
Applying the CSF 2.0 Functions to Manufacturing
The six CSF 2.0 Functions are designed to work together rather than as a step-by-step process. While GOVERN sets the direction for managing cybersecurity risk, the remaining five Functions address how manufacturers understand, protect, monitor, respond to, and recover their systems. NIST applies these Functions across both IT and OT environments.
IDENTIFY: This Function focuses on understanding current cybersecurity risk. The Manufacturing Profile calls for inventories of hardware, software, services, data, network connections, and external dependencies. These inventories can include PLCs, sensors, robots, HMIs, network equipment, engineering data, and vendor-supported systems. Assets are then prioritized based on their importance to production and business operations. ICS and OT environments include assets that standard IT discovery tools sometimes miss, and those are often the ones carrying the greatest operational risk.
PROTECT: Covers the safeguards used to manage those risks. For manufacturers, this can include access controls, multi-factor authentication, secure remote access, network segmentation, configuration management, tested backups, and protections for IT and OT systems. These controls may need to account for production requirements that make traditional IT practices, such as immediate patching or system downtime, harder to apply. Supply chain cybersecurity fits here, particularly for operations that share system access with defense customers or large enterprise buyers who audit vendor security as a condition of doing business.
DETECT: This Function provides guidance for finding and analyzing signs of a potential compromise. Manufacturing systems should be monitored for unusual activity, unauthorized access, configuration changes, and other events that could affect production. Continuous vulnerability management is paramount in OT environments, where limited visibility can make suspicious activity harder to spot.
RESPOND: When an incident occurs, what are the next steps? For manufacturers, response planning should account for both cybersecurity and operational impact. Immediate response includes containing the incident, coordinating with internal and external parties, communicating with leadership, and limiting disruption to manufacturing systems where possible.
RECOVER: This Function focuses on what happens after an incident, such as restoring affected systems, operations, and data. Recovery planning should address production continuity, recovery priorities, tested backups, system configurations, and restoring equipment to a known operational state.
Where Manufacturers Should Start
CSF 2.0 is meant to help organizations manage cybersecurity risk, not serve as a checklist. For manufacturers, implementation should start with a clear picture of the current environment, including IT and OT assets, business priorities, cybersecurity requirements, and existing safeguards.
NIST recommends using a Current Profile to document the cybersecurity outcomes that an organization is achieving today, and a Target Profile to define where it needs to be. Comparing the two helps identify gaps and develop a prioritized action plan based on risk, operational needs, and available resources.
The draft CSF 2.0 Manufacturing Profile can assist manufacturers in applying that process to production environments. It provides guidance specific to manufacturing across the six CSF Functions, and can be used as a roadmap for reducing cyber risk. It is intended to supplement, not replace, existing cybersecurity standards and requirements. For defense manufacturers, CSF 2.0 can complement other requirements (e.g., CMMC, NIST SP 800-171). Organizations that handle CUI must still meet the applicable contractual and regulatory requirements.
A cybersecurity readiness and risk assessment mapped against CSF 2.0 can help establish an organization’s security baseline and identify any gaps in those requirements.
Frequently Asked Questions
Is NIST CSF 2.0 mandatory for manufacturers?
For most private sector manufacturers, no. NIST describes CSF 2.0 as voluntary guidance for managing cybersecurity risk. However, customers, contracts, or other requirements may still influence how an organization uses the framework.
What is the NIST CSF 2.0 Manufacturing Profile?
The CSF 2.0 Manufacturing Profile (NIST IR 8183 Rev. 2) is draft NIST guidance that applies the framework to manufacturing systems and operations. It provides a voluntary, risk based roadmap that addresses areas including, OT security, supply chain risk management, platform security, and technology infrastructure resilience.
Where should manufacturers start with CSF 2.0?
Begin by understanding your current cybersecurity posture and defining the outcomes you’d like to achieve. From there, compare your current and target states, identify the gaps, and prioritize improvements based on risk and operational needs. CSF 2.0 is intended to be tailored to the organization.
Does CSF 2.0 apply to both IT and OT?
Yes. For manufacturers, the framework can be applied across both business IT and operational technology systems. The Manufacturing Profile provides more specific guidance for applying CSF 2.0 to manufacturing systems and operations.
Ready to Put CSF 2.0 Into Practice?
Applying CSF 2.0 in a manufacturing environment requires a clear understanding of both IT and OT risk, along with a practical plan for improvement. Vancord helps manufacturers assess their current security posture, prioritize gaps, and align cybersecurity efforts with frameworks such as NIST CSF 2.0 and CMMC.
Request a cybersecurity assessment to see where your organization stands, and where to focus next.



