Cloud Security Stack
Compliance and governance

Compliance

NIST CSF 2.0 mapped to Microsoft capabilities

The framework everyone claims to follow. What each function means in a Microsoft estate, including the one added in 2.0 that most organisations have not addressed.

13 min read · Reviewed 22 August 2026 · Written against NIST CSF 2.0 and Microsoft's published capabilities.

CSF is a language, not a checklist

NIST Cybersecurity Framework 2.0 gives you a vocabulary for describing where your capability is strong and where it is thin. It is not certifiable, nobody audits you against it, and that is the point: it is for organising a conversation, particularly with a board.

Version 2.0 added Govern alongside the original five functions, and that addition is the part most organisations have not done anything about, because it is the only one you cannot buy.

The six functions in a Microsoft estate
Where it lives
GovernPolicy, roles, risk appetite. Not a product
IdentifyPurview data discovery, asset inventory in Intune and Defender
ProtectEntra ID, Conditional Access, Intune, Purview DLP
DetectDefender XDR, Microsoft Sentinel
RespondSentinel automation, Defender response actions, your runbook
RecoverBackup, tested restore, and the communications plan

A tool can support a function. It cannot satisfy one, particularly Govern.

Where Microsoft estates are typically strongest and weakest

Our assessment of the usual shape, offered as an argument rather than as survey data.

  • Protect35
  • Detect26
  • Recover22
  • Govern17

Relative maturity in our view, not measured data.

The two functions worth your attention

Recover, because almost every organisation has backups and almost none have tested a restore under time pressure. An untested restore is a belief, not a capability.

Govern, because it is new, it is unglamorous, and it is the function that determines whether the other five get funded. It is also the only one where the answer is a document rather than a licence, which is precisely why it gets skipped.

The verdict

Our pick

Use CSF to structure the board conversation, not to buy products

Its value is a shared vocabulary for describing capability and gaps to people who do not read security tooling documentation.

Who should skip

Do not use a vendor CSF mapping as evidence of maturity. Those documents describe what a product could support, not what you have configured.

Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.