The initial public draft of NIST Special Publication 1353, "NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting," published by the National Institute of Standards and Technology on August 19, 2026 under DOI 10.6028/NIST.SP.1353.ipd. Comments are due to csf@nist.gov by October 15, 2026 (Source: csrc.nist.gov). The nine-page draft is the most recent entry in the CSF 2.0 quick-start guide series and is accompanied by four supplemental archives carrying the full prompts and simulated source documents.
The direction of the instrument is worth stating plainly, since it inverts the more usual pairing: this is guidance on using AI to do cybersecurity framework work, not guidance on securing AI or on applying the framework to AI systems. NIST is explicit that writing AI best practices or cybersecurity guidelines for AI was not the focus.
Purpose and scope
The stated premise is that organizations "are increasingly leveraging Artificial Intelligence (AI) systems to better understand, assess, prioritize, and communicate their cybersecurity efforts in alignment with CSF 2.0," with AI helping in "analyzing, planning, implementing, and monitoring the organization's progress toward achieving the outcomes of the CSF 2.0." The guide supplies three notional use cases and example prompts for structuring natural-language inputs to produce specified CSF 2.0 outputs from a generative AI model. NIST states the examples "are notional" and illustrate "some ways that an organization might use AI." Precautions are marked in the document by orange exclamation triangles.
The three use cases
- Use Case 1 — Review organizational policies and strategy to align with CSF governance. AI-assisted review evaluating cybersecurity policy, strategy and risk governance against the CSF 2.0 GOVERN function, with emphasis on accountability, oversight and risk decision-making. Inputs are governance artifacts, risk governance context, organizational strategy documents, organizational context, and supply chain and third-party risk context. The sample prompt's Style field specifies "evidence-based; no inference beyond provided artifacts; no maturity scoring; no benchmarking unless explicitly provided," and outputs are scored per GOVERN category as Aligned / Partial / Misaligned / Not addressed.
- Use Case 2 — Current State Profile development from organizational artifacts. Mapping existing practices to CSF Core Subcategories to draft an Organization Current State Profile, populating template columns for current policies and current practices, citing the requirement or risk response driving each outcome. The prompt requires source-grounded, traceable output with no fabrication, plain statement where an outcome is unaddressed, and a closing "Assumptions & Evidence Gaps" note listing outcomes where sources were silent or thin and places where a column rests on documented process rather than observed practice.
- Use Case 3 — Target State Profile development from organizational artifacts. Drawing on internal and industry references to draft a target-state profile describing desired outcomes against mission objectives, stakeholder expectations, the risk landscape and requirements. Inputs include published Community Profiles, risk governance artifacts, strategy documents and industry standards of good practice. Its Assumptions and Evidence Gaps note is required to flag outcomes where no explicit target existed and best practice was applied, targets implying new tooling, budget or staffing not confirmed in the sources, and dependencies or sequencing to validate before roadmapping.
The CO-STAR prompt structure
All sample prompts use the CO-STAR format, which the guide sets out as Context, Objective, Style, Tone, Audience, and Response. Context supplies the specific scenario affecting the desired CSF outcomes; Objective describes the purpose of the CSF activity; Style specifies technical, managerial or audit-based framing; Tone sets objectivity or authority for the target audience; Audience sets level of abstraction, precision of terms and response structure; Response specifies format and structure. NIST states that CO-STAR is used for this guide but that "organizations may want or need to use an alternative prompt format."
Stated cautions
The guide's recurring cautions are consistent across sections: review an AI tool's privacy and security settings, including data retention, training, access privileges and confidentiality terms, and follow company data policy before inputting sensitive information; AI-generated content "should always be reviewed by qualified personnel before being used in organizational decision-making," with users responsible for validating applicability, scope, inputs, assumptions and outputs; and consider using multiple AI tools and comparing results when validating output. On reference data, AI-assisted mappings or crosswalks "should retain identifiers, source context, provenance, and statuses to avoid unsupported mappings being used without appropriate review or context by a subject-matter expert," and reference data should be confirmed as the most current published version before use.
The glossary defines hallucination as "plausible but inaccurate AI output; requires expert review before use," prompt engineering as iteratively refining prompts to obtain reliable output, and proposed / derived mapping as status labels for AI-assisted mappings pending expert validation.
Supplemental materials
Appendix A describes the accompanying portfolio: an "Organizational Documents" folder of simulated records for a fictitious company, Halverston Community Bank — bank security requirements, staff interview notes, a security policy handbook, a risk register and an Organizational Profile template — created with generative AI for illustration and explicitly not to be used as templates for actual use; and a folder per use case containing the abbreviated sample prompt and an expanded version. NIST notes the CO-STAR prompts "deliberately reflect stylistic differences (e.g., tone, voice) to provide variety," and that all individuals, organizations and records in the guide and supplements "are products of fiction for illustrative purposes." The workflow in Appendix A is: choose an authorized AI tool, upload the organizational documents, paste the CO-STAR prompt, generate and review, with a note that content generated "reflects a point-in-time output" and results can change or vary.
The guide points readers to the Cybersecurity and Privacy Reference Tool, the CSF 2.0 Reference Tool and the Online Informative References Program for exportable structured reference data, and to AI at NIST, the NIST AI Resource Center, the AI Risk Management Framework and the Cyber AI Profile.
Provenance
Fetched in full from nvlpubs.nist.gov, NIST's own publication server, at the DOI-backed path, nine pages. The document is a slide-format guide; multi-column extraction interleaves some lines. The four supplemental ZIP archives under csrc.nist.gov, which carry the expanded prompts and the simulated Halverston Community Bank documents, are not captured — the abbreviated prompts printed on pages 4 to 6 are the only prompt text held here.
Coverage of the draft appeared on August 21, 2026, and the wiki previously carried that as the publication date. NIST's own record gives August 19, 2026, and the earlier date is corrected here and on National Institute of Standards and Technology (NIST).
Relationships
- related: National Institute of Standards and Technology (NIST) — the issuing body.
- related: NIST AI Risk Management Framework 1.0 — a sibling NIST instrument; this guide applies AI to framework work rather than governing AI systems, and the guide points to the AI RMF as a companion resource.
- related: AI and Cybersecurity, Enterprise AI Deployment Gap.