NIST drafts AI guide for monitoring CSF 2.0 progress
The draft guide marks NIST's first formal treatment of AI as a compliance tool rather than a compliance target, providing CO-STAR prompt templates for three self-assessment use cases.
TL;DR
NIST released a draft quick-start guide on using AI to monitor progress toward CSF 2.0 outcomes, with comments due October 15. The guide walks through three use cases (policy and governance review, current-state profiling, and target-state profiling) using the CO-STAR prompt engineering framework to show how organizations can prompt AI systems for each task. Supplemental prompt materials accompany each use case in the release package.
NIST has spent years telling organizations how to secure AI systems. Now it's telling them how to use those same systems to prove they're secure.
The draft quick-start guide, published this week, represents NIST's first formal guidance on using AI as a compliance tool rather than a compliance target. It's aimed at organizations implementing CSF 2.0 (the 2024 refresh of the Cybersecurity Framework) and provides concrete examples of how to prompt AI systems for compliance monitoring, from policy evaluation through current-state and target-state profiling.
The guide applies the CO-STAR prompt engineering framework (Context, Objective, Style, Tone, Audience, Response) to structure example prompts for each use case. CO-STAR is widely used in prompt engineering, and the examples give practitioners something to adapt directly. NIST also published supplemental materials with additional prompts.
The three use cases span the full compliance monitoring workflow. First, an AI-assisted review of cybersecurity policy, strategy, and risk governance against CSF 2.0 outcomes. Second, mapping a current-state profile from artifacts and interview notes. Third, developing a target-state profile using international and industry references to meet mission objectives and regulatory requirements. Each use case includes example source material inputs, so organizations can see what the AI is working from, not just what it produces.
It's a draft. Comments close October 15. But the signal is clear: NIST sees AI-assisted compliance monitoring as a practice worth standardizing, not an edge case to tolerate. For the practitioner who's been quietly using AI to help with framework self-assessment, that's a meaningful shift, the guidance is catching up to the practice.
Published ·Updated ·Deep Fathom