Learn

NIST CSF 2.0 for Digital Asset Operations

Updated on

September 2, 2026

The NIST Cybersecurity Framework 2.0, finalised in February 2024, organises cybersecurity risk management into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. For digital asset operators, most tooling clusters around Protect and Detect, while Respond and Recover, the functions that determine what happens after a compromise, are frequently the thinnest part of the program. This page applies the six functions to digital asset operations, with emphasis on Respond and Recover. For how NIST CSF sits alongside the binding regimes, see the regulatory requirements overview.

What is NIST CSF 2.0 and does it apply to crypto firms?

NIST CSF 2.0 is a voluntary cybersecurity framework published by the US National Institute of Standards and Technology in February 2024. It is not a law and imposes no direct legal obligation. Its value is as a common control language: it is widely adopted by institutional operators, referenced in vendor diligence and insurance, and used to structure programs that map to binding regimes such as DORA and NYDFS Part 500. Version 2.0 broadened the framework's scope beyond critical infrastructure to organisations of all types and added the Govern function.

What are the six functions of NIST CSF 2.0?

  • Govern (GV): establish and monitor the cybersecurity risk strategy, roles, and policy. For a digital asset operator, a board-owned risk strategy covering custody, signing, and asset recovery.
  • Identify (ID): understand assets, risks, and dependencies. An inventory of wallets, keys, signers, and the critical asset flows.
  • Protect (PR): safeguard assets and limit the likelihood of an event. Key management, access controls, HSMs, MPC, and segregation.
  • Detect (DE): find events and anomalies. Monitoring of on-chain activity, signing anomalies, and access.
  • Respond (RS): act during and after an incident. Contain a compromise and move assets out of reach of an attacker.
  • Recover (RC): restore assets, functions, and communications. Regain control of assets and resume operations.

Govern is the function introduced in version 2.0. It sits across the other five and makes the cybersecurity strategy a board-level responsibility rather than a purely technical one.

Why do Respond and Recover matter most for digital assets?

Prevention has an asymmetry unique to digital assets: a single successful compromise can be irreversible. Once an attacker controls a key and moves funds, there is no chargeback and no reissuance. That makes the Respond and Recover functions decisive, because they govern the only window in which loss can still be limited.

Most custody and key-management tooling addresses Protect and Detect. It secures the key and watches for anomalies. It does not, on its own, tell you what to do the moment a key is compromised, a signer is unavailable, or a wallet is inaccessible. That is the Respond and Recover gap: the point where prevention has already failed and the question becomes whether the assets can still be moved to safety.

  • Respond (RS) for a digital asset operator means the ability to contain the incident and act on the assets, not just triage the systems. If the only response option depends on a key the attacker already controls, there is no effective response.
  • Recover (RC) means regaining control of the assets and resuming operations. Restoring a server from backup does not recover assets an attacker has moved, and restoring a key does not help if the key was the point of compromise.

See /response and /learn/digital-asset-recovery.

What must an operator do in practice?

  • Map each of the six functions to concrete controls, and be honest about which functions are strong and which are thin.
  • Treat Respond and Recover as first-class, with tested procedures for the specific failure modes of digital assets (key compromise, signer loss, inaccessible wallet), not just generic IT disaster recovery.
  • Ensure the recovery plan addresses the assets, not only the infrastructure.
  • Use the framework to demonstrate coverage in diligence and to align with binding regimes such as DORA and NYDFS Part 500.

How does keyless recovery, set up in advance, map to NIST CSF 2.0?

Keyless recovery, meaning recovery that does not depend on your private keys, maps directly to the Respond and Recover functions. Because it is set up in advance and does not depend on private keys, it provides a response option that remains available even when the key is the thing that failed: assets can be swept to a pre-approved destination on a defined trigger. This is the specific capability that closes the Respond and Recover gap that Protect and Detect tooling leaves open.

Circuit Security provides operational resilience for institutional digital assets. Its Recovery and Response products, powered by Automatic Asset Extraction (AAE), give a recovery path that does not depend on the private keys when wallets are compromised or inaccessible, so they support the NIST CSF 2.0 Respond and Recover functions that custody-only solutions leave open. Circuit's Key Backup offering is a trustless encrypted backstop for critical key material, which also supports the Recover function. Circuit is not a custodian and cannot access, use, or reconstruct your keys. See /recovery.

Honest limits

NIST CSF 2.0 is a voluntary framework, not a regulation, and adopting it does not by itself satisfy any binding legal obligation. A recovery capability supports the Respond and Recover functions but does not deliver Govern, Identify, Protect, or Detect, which remain the operator's responsibility. This page is educational and not legal or compliance advice.

Frequently asked questions

What are the six functions of NIST CSF 2.0?
Govern, Identify, Protect, Detect, Respond, and Recover. Govern was added in version 2.0 and sits across the other five.

Is NIST CSF mandatory?
No. NIST CSF 2.0 is a voluntary framework. It is widely adopted as a control baseline and often referenced in contracts, insurance, and diligence, which makes it a practical requirement for many institutional operators even though it is not law.

Why are Respond and Recover the focus for digital assets?
Because a digital asset compromise can be irreversible. Once funds move, there is no chargeback. Respond and Recover govern the only window in which loss can still be limited, and they are the functions that prevention-focused custody tooling tends to leave thin.

Does NIST CSF 2.0 apply to crypto and digital asset firms?
It applies to any organisation that chooses to adopt it. Version 2.0 explicitly broadened scope beyond critical infrastructure, and its function model maps cleanly onto digital asset operations.

Want to keep up to date with Circuit? Sign up below

Success! Speak soon.
Oops! Something went wrong while submitting the form.

Related Posts

Discover more key terms relevant to Circuit

Learn

NYDFS Part 500 for Virtual Currency Firms

Read More
Learn

MiCA and DORA: EU Operational Resilience Requirements for CASPs

Read More
Learn

Operational Resilience Requirements for Digital Asset Firms

Read More

Built by experts who’ve made digital assets safer, and now, recoverable

We believe asset recoverability is table stakes for the next era of digital assets.