NIST’s New Guide for AI and CSF 2.0
NIST recently released a new draft, SP 1353, that acts as a practical guide for using AI alongside the Cybersecurity Framework 2.0. Instead of being a dry rulebook, this document focuses on how security teams can actually use generative AI to help with the heavy lifting of analysis and reporting. The guide shares specific prompt strategies to help you plan or monitor CSF outcomes, and while it is not an AI security policy, it sprinkles in important precautions to help you keep things secure while you work.
Real-World Scenarios and Next Steps
To show how this works in the real world, the guide includes three specific scenarios featuring a fictional company. It walks you through using AI to review your internal policies, map out your current cybersecurity posture, and draft target profiles that align with your mission objectives. Beyond practical scenarios, the update establishes clear prompt engineering standards built around structured frameworks like CO-STAR to turn raw organizational documents into formatted CSF deliverables. It also introduces crucial security parameters, explicitly cautioning teams to validate all model outputs manually and safeguard internal data against potential exposure when feeding artifacts into AI tools. It is essentially a toolkit designed to help speed up the documentation process. NIST is looking for public feedback on these prompt ideas until October 15, 2026, so it is a good time to test it out if you are looking for ways to streamline your workflow.
Author Notes
National Institute of Standards and Technology. (2026, August 19). NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting (NIST Special Publication 1353 Initial Public Draft). U.S. Department of Commerce. https://csrc.nist.gov/pubs/sp/1353/ipd
About the Author
Carmen Estela is a Cybersecurity Research Analyst at Cyber Defense Magazine and a Women in Cybersecurity Award Candidate. She recently graduated with a Master of Science degree from the University of Central Florida and holds a Bachelor’s degree in Criminology from the University of Florida with certifications in Data Analytics and AI Fundamentals. She frequently speaks and volunteers at well-known industry gatherings, such as BSides Orlando and BSides Jax, where she offers her perspectives on emerging cyber trends. Carmen is committed to advancing the standards of governance, risk, and compliance within cybersecurity. She has also served as an adult protective investigator, police dispatcher, and legal intern, applying investigative skills across law enforcement, academic, and public service settings.
Reach her online at [email protected].

