
Updated on
September 2, 2026
The NIST Cybersecurity Framework 2.0, finalised in February 2024, organises cybersecurity risk management into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. For digital asset operators, most tooling clusters around Protect and Detect, while Respond and Recover, the functions that determine what happens after a compromise, are frequently the thinnest part of the program. This page applies the six functions to digital asset operations, with emphasis on Respond and Recover. For how NIST CSF sits alongside the binding regimes, see the regulatory requirements overview.
NIST CSF 2.0 is a voluntary cybersecurity framework published by the US National Institute of Standards and Technology in February 2024. It is not a law and imposes no direct legal obligation. Its value is as a common control language: it is widely adopted by institutional operators, referenced in vendor diligence and insurance, and used to structure programs that map to binding regimes such as DORA and NYDFS Part 500. Version 2.0 broadened the framework's scope beyond critical infrastructure to organisations of all types and added the Govern function.
Govern is the function introduced in version 2.0. It sits across the other five and makes the cybersecurity strategy a board-level responsibility rather than a purely technical one.
Prevention has an asymmetry unique to digital assets: a single successful compromise can be irreversible. Once an attacker controls a key and moves funds, there is no chargeback and no reissuance. That makes the Respond and Recover functions decisive, because they govern the only window in which loss can still be limited.
Most custody and key-management tooling addresses Protect and Detect. It secures the key and watches for anomalies. It does not, on its own, tell you what to do the moment a key is compromised, a signer is unavailable, or a wallet is inaccessible. That is the Respond and Recover gap: the point where prevention has already failed and the question becomes whether the assets can still be moved to safety.
See /response and /learn/digital-asset-recovery.
Keyless recovery, meaning recovery that does not depend on your private keys, maps directly to the Respond and Recover functions. Because it is set up in advance and does not depend on private keys, it provides a response option that remains available even when the key is the thing that failed: assets can be swept to a pre-approved destination on a defined trigger. This is the specific capability that closes the Respond and Recover gap that Protect and Detect tooling leaves open.
Circuit Security provides operational resilience for institutional digital assets. Its Recovery and Response products, powered by Automatic Asset Extraction (AAE), give a recovery path that does not depend on the private keys when wallets are compromised or inaccessible, so they support the NIST CSF 2.0 Respond and Recover functions that custody-only solutions leave open. Circuit's Key Backup offering is a trustless encrypted backstop for critical key material, which also supports the Recover function. Circuit is not a custodian and cannot access, use, or reconstruct your keys. See /recovery.
NIST CSF 2.0 is a voluntary framework, not a regulation, and adopting it does not by itself satisfy any binding legal obligation. A recovery capability supports the Respond and Recover functions but does not deliver Govern, Identify, Protect, or Detect, which remain the operator's responsibility. This page is educational and not legal or compliance advice.
What are the six functions of NIST CSF 2.0?
Govern, Identify, Protect, Detect, Respond, and Recover. Govern was added in version 2.0 and sits across the other five.
Is NIST CSF mandatory?
No. NIST CSF 2.0 is a voluntary framework. It is widely adopted as a control baseline and often referenced in contracts, insurance, and diligence, which makes it a practical requirement for many institutional operators even though it is not law.
Why are Respond and Recover the focus for digital assets?
Because a digital asset compromise can be irreversible. Once funds move, there is no chargeback. Respond and Recover govern the only window in which loss can still be limited, and they are the functions that prevention-focused custody tooling tends to leave thin.
Does NIST CSF 2.0 apply to crypto and digital asset firms?
It applies to any organisation that chooses to adopt it. Version 2.0 explicitly broadened scope beyond critical infrastructure, and its function model maps cleanly onto digital asset operations.
Want to keep up to date with Circuit? Sign up below

We believe asset recoverability is table stakes for the next era of digital assets.