NIST drafts first CSF 2.0 profile for federal Open RAN
The profile operationalizes CSF 2.0's supply-chain risk management language against an architecture deliberately designed to multiply vendors rather than consolidate them.
TL;DR
NIST released draft IR 8623, a CSF 2.0 community profile for federal agencies deploying Open Radio Access Network infrastructure. The profile maps disaggregated RAN components to CSF 2.0 outcomes and references O-RAN Alliance security specifications. It adds new columns for O-RAN risk scores and technical reports, a structural departure from earlier CSF community profiles. Comments close November 2. It's the first profile built for an architecture whose defining feature is multiplying vendors, making it an operational test of the supply-chain risk management language CSF 2.0 added in its Govern function.

NIST published draft IR 8623 on September 17, the first CSF 2.0 community profile built for a deliberately disaggregated telecom architecture. Federal agencies planning Open RAN deployments now have a document that maps the O-RAN Alliance's security specifications to CSF 2.0 outcomes. More significantly, it operationalizes the supply-chain risk management language CSF 2.0 introduced in its Govern function against an architecture whose whole premise is multiplying component vendors rather than consolidating them.
Open RAN breaks the traditional single-vendor radio access network into separate components (Radio Unit, Distributed Unit, and Central Unit) connected by standardized open interfaces. The O-RAN Alliance, of which NIST is a member, develops the security specifications for those interfaces. The pitch has always been reduced vendor lock-in. The security corollary is an expanded attack surface across every new interface and every new supplier. This profile confronts that corollary directly.
The profile differs structurally from earlier CSF 2.0 community profiles. It adds columns for the O-RAN Alliance Risk Score and for relevant O-RAN Alliance specifications or technical reports alongside each CSF subcategory. Another new column maps each subcategory to other federal guidance, including NIST publications. The draft also acknowledges a baseline truth other profiles don't have to state: "There will never be an agency that solely operates a RAN for its own sake, but as part of larger agency infrastructure." The profile is a bridge document: it points cybersecurity managers toward information they need to fold an Open RAN deployment into existing security plans and organizational CSF profiles.
CSF 2.0's Govern function, added in the 2024 update, made cybersecurity supply chain risk management (C-SCRM) an explicit organizational governance concern rather than a subcategory under Identify. This profile is the first to take that elevated C-SCRM language and apply it to an infrastructure model where the core architectural decision to disaggregate components across open interfaces and multiple vendors makes supply-chain governance both more necessary and harder. The profile doesn't resolve that tension; it documents it, subcategory by subcategory, O-RAN specification by O-RAN specification.
Comments are due November 2 to oran-cybersecurity@nist.gov. For federal cybersecurity managers, the comment period is the window to shape whether the final profile hardens into procurement language. The draft is silent on that question. The architecture it profiles isn't.
Published ·Deep Fathom