Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 1353 (Initial Public Draft)

NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting

Date Published: August 19, 2026
Comments Due: October 15, 2026
Email Comments to: [email protected]

Author(s)

National Institute of Standards and Technology

Announcement

This new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing, and monitoring an organization’s progress toward achieving CSF 2.0 outcomes.

The document’s purpose is to:

  • Provide structured AI prompts as tools for practitioners to begin creating CSF-related artifacts in support of achieving CSF outcomes
  • Identify current state of practice for AI prompt engineering in CSF implementation and analysis

While the focus was not to write about AI best practices or to provide cybersecurity guidelines thereof, there are places where specific precautions are denoted with the /!\ notation. 

This guide includes three notional use cases, examples of prompts for structuring natural language inputs to produce specified CSF 2.0 outputs from a generative AI model, simulated organizational files for a fictitious company, tips for getting started, and more.

  • USE CASE 1 illustrates the use of an AI-assisted review to evaluate organization cybersecurity policy, strategy, and risk governance in alignment with the CSF 2.0 outcomes.
  • USE CASE 2 illustrates how to produce a draft Organization Current State Profile – mapping artifacts and personnel interview notes to CSF 2.0 outcomes, documenting any assumptions, and recording observed gaps in the interviews and evidence.
  • USE CASE 3 illustrates how to draw upon internal and industry references to create a draft CSF target state profile describing desired outcomes to meet mission objectives, stakeholder expectations, address the risk landscape, and fulfill requirements.

Use case examples illustrate a possible approach and are not prescriptive assessment or assurance methodologies. 

Note: The README file in the Supplemental Materials List contains the ZIP file checksums. 

Submit Your Comments:

The comment period is open through October 15, 2026, at 11:59 PM. Email comments to: [email protected]

Note: NIST is only seeking comments on the quick-start guide and supplied AI prompts. NIST is not seeking comment on the fictional organizational documents. Those are for illustrative purposes only.

This publication is the most recent within a portfolio of CSF 2.0 quick-start guides released by the CSF 2.0 project team since February 26, 2024. These resources offer tailored pathways for different audiences to engage with the CSF 2.0, making the Framework easier to implement. View all CSF 2.0 quick-start guides.

 

Control Families

None selected