NIST CSF 2.0: awareness, training & the human layer

The NIST Cybersecurity Framework 2.0 has become the common language of cyber programmes far beyond the United States — African banks, regulators, insurers and enterprise customers use it to structure assessments, board reporting and third-party questionnaires. The framework is voluntary and there is no CSF certificate, but that makes the evidence question sharper, not softer: when someone asks "where are you against the CSF?", you need measured outcomes, not adjectives. This page maps the framework's human-layer outcomes to the records AfriPhish produces.

What CSF 2.0 expects on awareness and human risk

GOVERN — roles and policy. The new GOVERN function makes the organisational side explicit. Under GV.RR, cybersecurity roles, responsibilities and authorities must be established and communicated — which means people can actually state what is expected of them, not that an org chart exists somewhere. Under GV.PO, organisational cybersecurity policy must be established, communicated and enforced. A policy nobody has read has not been communicated, and one nobody has acknowledged is hard to enforce.

PROTECT — the PR.AT Awareness and Training category. The framework dedicates a category to your people. PR.AT-01 expects personnel to be provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind. PR.AT-02 extends this to individuals in specialized roles — administrators, developers, finance teams handling payments, executives — who need training matched to the risks of their function, not the generic all-staff module.

DETECT and RESPOND — behaviours, not just tooling. Detection and response outcomes quietly depend on humans: adverse events have to be noticed and reported before anything downstream can happen. An employee who recognises a phishing message and reports it through a known channel is a detection source; one who deletes it silently is a blind spot. A CSF-aligned programme therefore has to build — and measure — reporting behaviour, not only click avoidance.

Tiers and profiles — the framework's maturity language. CSF 2.0 describes implementation tiers from Partial to Adaptive, and Organizational Profiles that compare your current state against a target. Human-layer outcomes belong in that profile like any technical outcome: to place yourself honestly on a tier, you need measurements — completion rates, simulation results, reporting trends — rather than an optimistic self-rating.

The outcomes AfriPhish helps you evidence

CSF 2.0 outcomeAfriPhish moduleEvidence produced
GV.PO — policy communicated and enforcedPolicy management with e-signature attestationVersioned, timestamped acknowledgement registers per employee
GV.RR — roles and responsibilities communicatedRole-aware training assignmentsRecords of who was trained on what, mapped to their role
PR.AT-01 — general workforce awarenessAwareness training (EN/FR/AR) plus real-time coachingPer-user completion logs, quiz scores, coaching interactions
PR.AT-02 — specialized-role trainingDedicated IT/SecOps training trackTrack-level completion and score records for technical staff
DETECT/RESPOND — event reporting behaviourPhishing simulations with report trackingReport rates and time-to-report per campaign
Tier and profile measurementHuman risk scoring, analytics and reportsTrend data for current-versus-target profile reviews

Because simulations, training and attestations share one data model, your profile is grounded in observation: you can show that reporting rates climbed and click rates fell across successive campaigns — the behavioural change the framework's outcomes actually describe.

What assessors typically ask for

CSF assessments — internal reviews, third-party maturity assessments, regulator-mapped questionnaires or cyber-insurance underwriting — converge on the same requests:

  • A documented awareness and training programme mapped to PR.AT, with owners and a schedule.
  • Completion records for the general workforce (PR.AT-01) and for specialized roles (PR.AT-02), separately.
  • Policy communication evidence for GV.PO — who acknowledged which version, and when.
  • Simulation and testing results — proof the PR.AT outcomes are achieved in behaviour, not just planned on paper.
  • Reporting metrics — evidence that employees feed your detection and response processes in practice.
  • Trend data supporting your tier claim — a Repeatable or Adaptive rating implies measurement and improvement you can show.

All of the above export directly from AfriPhish, scoped to the assessment period.

See where your organisation stands

The CSF's tiers-and-profile logic is exactly how our free 4-minute Human Risk Maturity Assessment works: it benchmarks your current human-layer practices, shows the gap to a defensible target profile, and highlights what an assessor would flag under GV.PO and PR.AT.

Building or refreshing a CSF-aligned programme? Book a demo and we will show you the exact reports that slot into a current-versus-target profile review.