The National Institute of Standards and Technology (NIST), a federal standards agency, has published draft guidance showing how organizations can use generative AI to speed document-heavy Cybersecurity Framework (CSF) 2.0 analysis while keeping the work subject to approved tools, approved inputs and human review.
The initial public draft is named “NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting.”
It shows how prompts can map organizational records to CSF outcomes and generate draft cybersecurity profiles, with NIST listing “Compressing the initial drafting from weeks to hours” among example outcomes.
Generating draft profiles using structured prompts
The guide provides prompts for three uses: reviewing cybersecurity governance, building a draft Current State Profile and creating a draft Target State Profile.
The Current State Profile records how existing cybersecurity practices align with CSF outcomes, including assumptions and evidence gaps. The Target State use case draws on internal requirements, risk registers and industry references to define desired outcomes. NIST calls the examples a “possible approach,” not a prescriptive assessment or assurance methodology.
The prompts use the CO-STAR structure, which organizes instructions around context, objective, style, tone, audience and response. NIST says organizations can choose another prompt format if it better fits their use case.
The Current State Profile example shows how that document-heavy work could be automated. NIST lists policies, audit findings, penetration tests, vulnerability scans and other organizational records as possible inputs for mapping against CSF outcomes.
Maintaining security and human oversight
The same workflow comes with explicit precautions. NIST tells organizations to use an AI tool authorized by their security and privacy team, collect only records approved for use as AI inputs and review settings for data retention, training, access privileges and confidentiality before submitting sensitive information. AI-generated content should always be reviewed by qualified personnel before organizational decision-making, the guide says.
NIST is considering the same automation-versus-human-review issue elsewhere. Its request for information on modernizing the National Vulnerability Database asks which tasks are appropriate for AI-enabled automation, which should require human review and what controls and safeguards are needed around AI-generated remediations.
NIST’s separate Generative AI Profile identifies confabulation, or confidently stated false output, and data privacy risks including leakage or unauthorized disclosure of sensitive data. The guide also treats AI-assisted framework mappings as provisional: its “Proposed / Derived mapping” status covers mappings awaiting expert validation, and it says crosswalks, or mappings between frameworks, should retain identifiers, source context, provenance and status.
Separating framework analysis from AI system defense
The new guide covers a different task from NIST’s Cyber AI Profile, published as a preliminary draft in December 2025. That profile addresses securing AI system components, AI-enabled cyber defense and thwarting AI-enabled attacks. SP 1353 focuses on using AI to perform CSF analysis and reporting.
NIST separately says outsourcing cybersecurity is especially common among small businesses and lists managed service providers, managed security service providers and virtual or fractional CISOs among the options.
NIST is accepting comments on the quick-start guide and supplied prompts through Oct. 15. It is also inviting practitioners to submit additional AI-for-CSF use cases.