Back to signals
NIST draft for commentGuidance and regulationPublished August 19, 2026

SP 1353, NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and ReportingInitial Public Draft

This new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing, and monitoring an organization's progress toward achieving CSF 2.0 outcomes. The document's purpose is to: Provide structured AI prompts as tools for practitioners to begin creating CSF-related artifacts in support of achieving CSF outcomes Identify current state of practice for AI prompt engineering in CSF implementation and analysis While the focus was not to write about AI best practices or to provide cybersecurity guidelines thereof, there are places where specific precautions are denoted with the /!\ notation. This guide includes three notional use cases, examples of prompts for structuring natural language inputs to produce specified CSF 2.0 outputs from a generative AI model, simulated organizational files for a fictitious company, tips for getting started, and more. USE CASE 1 illustrates the use of an AI-assisted review to evaluate organization cybersecurity policy, strategy, and risk governance in alignment with the CSF 2.0 outcomes. USE CASE 2 illustrates how to produce a draft Organization Current State Profile - mapping artifacts and personnel i…

Open the source record
Tags
NIST, draft open for comment, SP 1353
Related exam domains
CISSP 1: Security and Risk Management; CISSP 7: Security Operations; CISM 1: Information Security Governance; CISM 2: Information Security Risk Management
Source record id
https://csrc.nist.gov/pubs/sp/1353/ipd
First seen by InfoSec Signals
9/23/2026

Exam domain labels come from a keyword heuristic and are study hints, not an official mapping. The summary is the publisher's own text, shortened; the linked record is authoritative.