Version 2.0

NIST CSF

NIST Cybersecurity Framework

Official Docs

A voluntary framework consisting of standards, guidelines, and best practices to manage cybersecurity risk. Version 2.0 added the Govern function to emphasize organizational governance.

All 106 CSF 2.0 Core subcategories are represented across six functions and 22 categories. Descriptions are Purposeful Security plain-English summaries, not official NIST wording. This reference is not a full CSF assessment or an official crosswalk.

Content review: September 22, 2026. Not a certification or conformity assessment.

106 subcategories · 22 categories·6 functions

How to use this reference

Open a function, then a category to explore its outcomes. Plain-English summaries are authored by Purposeful Security; use the NIST source links for the official wording.

The Core describes outcomes, not a universal implementation checklist. Numbering gaps are intentional in CSF 2.0. This covers the full Core hierarchy, not every supporting publication, Profile, Tier, or implementation example.

Our Security Checkup addresses selected outcomes only and is not a full CSF assessment. Reference coverage does not mean assessed or verified coverage.

Govern (GV)6 categories · 31 subcategories
GV.OCOrganizational Context5 subcategories
  1. GV.OC-01

    Use an understanding of the organization’s mission to guide cybersecurity risk decisions.

    NIST source · p. 16
  2. GV.OC-02

    Understand internal and external stakeholders and consider their security needs and expectations.

    NIST source · p. 16
  3. GV.OC-03

    Understand and manage relevant legal, regulatory, and contractual obligations, including privacy and civil liberties.

    NIST source · p. 16
  4. GV.OC-04

    Understand and communicate the critical services, capabilities, and objectives others rely on your organization to deliver.

    NIST source · p. 16
  5. GV.OC-05

    Understand and communicate the external outcomes, capabilities, and services your organization relies on.

    NIST source · p. 16
GV.RMRisk Management Strategy7 subcategories
  1. GV.RM-01

    Agree with stakeholders on the objectives for managing risk.

    NIST source · p. 16
  2. GV.RM-02

    Define, communicate, and keep current the types and amounts of risk the organization is willing to accept.

    NIST source · p. 16
  3. GV.RM-03

    Include cybersecurity activities and results in the organization’s broader risk management processes.

    NIST source · p. 16
  4. GV.RM-04

    Set and communicate strategic guidance on appropriate ways to respond to risk.

    NIST source · p. 16
  5. GV.RM-05

    Establish channels for communicating cybersecurity risks across the organization, including third-party risks.

    NIST source · p. 16
  6. GV.RM-06

    Agree on and communicate a consistent way to calculate, record, classify, and prioritize cybersecurity risks.

    NIST source · p. 16
  7. GV.RM-07

    Include opportunities and potential benefits, not just negative impacts, in cybersecurity risk discussions.

    NIST source · p. 16
GV.RRRoles, Responsibilities, and Authorities4 subcategories
  1. GV.RR-01

    Make leadership accountable for cybersecurity risk and for encouraging ethical, risk-aware, continuously improving practices.

    NIST source · p. 17
  2. GV.RR-02

    Define, communicate, enforce, and ensure understanding of cybersecurity responsibilities and decision-making authority.

    NIST source · p. 17
  3. GV.RR-03

    Provide resources that fit the security strategy, assigned responsibilities, and policies.

    NIST source · p. 17
  4. GV.RR-04

    Include cybersecurity in human resources practices.

    NIST source · p. 17
GV.POPolicy2 subcategories
  1. GV.PO-01

    Create, communicate, and enforce security risk policies that reflect the organization’s context, strategy, and priorities.

    NIST source · p. 17
  2. GV.PO-02

    Review, update, communicate, and enforce policies as obligations, threats, technology, and the mission change.

    NIST source · p. 17
GV.OVOversight3 subcategories
  1. GV.OV-01

    Review the results of the cybersecurity risk strategy and use them to adjust direction.

    NIST source · p. 17
  2. GV.OV-02

    Review and adjust the strategy so it addresses organizational needs and risks.

    NIST source · p. 17
  3. GV.OV-03

    Evaluate cybersecurity risk management performance and decide what needs to change.

    NIST source · p. 17
GV.SCCybersecurity Supply Chain Risk Management10 subcategories
  1. GV.SC-01

    Agree with stakeholders on a supply-chain security program, including its strategy, objectives, policies, and processes.

    NIST source · p. 17
  2. GV.SC-02

    Define and coordinate security responsibilities with suppliers, customers, and partners, internally and externally.

    NIST source · p. 17
  3. GV.SC-03

    Integrate supply-chain security into cybersecurity and enterprise risk management, assessments, and improvement.

    NIST source · p. 17
  4. GV.SC-04

    Identify suppliers and rank them by how critical they are.

    NIST source · p. 17
  5. GV.SC-05

    Define and prioritize supply-chain security expectations and include them in supplier and third-party agreements.

    NIST source · p. 18
  6. GV.SC-06

    Plan and perform due diligence to reduce risk before formalizing third-party relationships.

    NIST source · p. 18
  7. GV.SC-07

    Understand, record, prioritize, assess, address, and monitor supplier, product, service, and other third-party risks throughout the relationship.

    NIST source · p. 18
  8. GV.SC-08

    Include relevant suppliers and third parties in incident preparation, response, and recovery.

    NIST source · p. 18
  9. GV.SC-09

    Integrate supply-chain security practices into risk programs and monitor their performance throughout product and service life cycles.

    NIST source · p. 18
  10. GV.SC-10

    Plan for security activities that remain necessary after a partnership or service agreement ends.

    NIST source · p. 18
Identify (ID)3 categories · 21 subcategories
ID.AMAsset Management7 subcategories
  1. ID.AM-01

    Keep an up-to-date inventory of hardware managed by the organization.

    NIST source · p. 18
  2. ID.AM-02

    Keep inventories of the software, systems, and services the organization manages.

    NIST source · p. 18
  3. ID.AM-03

    Maintain representations of authorized network communications and internal and external data flows.

    NIST source · p. 18
  4. ID.AM-04

    Keep an inventory of services delivered by suppliers.

    NIST source · p. 18
  5. ID.AM-05

    Prioritize assets according to their classification, criticality, resources, and impact on the mission.

    NIST source · p. 18
  6. ID.AM-07

    Inventory designated types of data and their associated metadata.

    NIST source · p. 18
  7. ID.AM-08

    Manage systems, hardware, software, services, and data from introduction through retirement.

    NIST source · p. 18
ID.RARisk Assessment10 subcategories
  1. ID.RA-01

    Find, confirm, and document vulnerabilities in assets.

    NIST source · p. 18
  2. ID.RA-02

    Obtain cyber threat intelligence from relevant sources and information-sharing communities.

    NIST source · p. 19
  3. ID.RA-03

    Identify and record threats originating both inside and outside the organization.

    NIST source · p. 19
  4. ID.RA-04

    Record how likely threats are to exploit vulnerabilities and what the consequences could be.

    NIST source · p. 19
  5. ID.RA-05

    Use threats, vulnerabilities, likelihood, and impact to understand inherent risk and prioritize responses.

    NIST source · p. 19
  6. ID.RA-06

    Choose, prioritize, plan, track, and communicate responses to risk.

    NIST source · p. 19
  7. ID.RA-07

    Manage and record changes and exceptions, assess their risk impact, and track them.

    NIST source · p. 19
  8. ID.RA-08

    Establish a process to receive, analyze, and respond to vulnerability disclosures.

    NIST source · p. 19
  9. ID.RA-09

    Assess whether hardware and software are authentic and intact before acquiring or using them.

    NIST source · p. 19
  10. ID.RA-10

    Assess critical suppliers before acquisition.

    NIST source · p. 19
ID.IMImprovement4 subcategories
  1. ID.IM-01

    Use evaluations to identify improvements to cybersecurity risk management.

    NIST source · p. 19
  2. ID.IM-02

    Identify improvements through security tests and exercises, including those involving suppliers and other relevant parties.

    NIST source · p. 19
  3. ID.IM-03

    Learn where to improve from day-to-day processes, procedures, and activities.

    NIST source · p. 19
  4. ID.IM-04

    Establish, share, maintain, and improve incident response and other security plans that affect operations.

    NIST source · p. 19
Protect (PR)5 categories · 22 subcategories
PR.AAIdentity Management, Authentication, and Access Control6 subcategories
  1. PR.AA-01

    Manage identities and credentials for authorized people, services, and hardware.

    NIST source · p. 19
  2. PR.AA-02

    Verify identities and connect them to credentials in a way appropriate to the interaction.

    NIST source · p. 19
  3. PR.AA-03

    Authenticate users, services, and hardware.

    NIST source · p. 19
  4. PR.AA-04

    Protect, transmit, and verify identity assertions used to communicate authentication or identity claims.

    NIST source · p. 19
  5. PR.AA-05

    Set access rights in policy, manage and enforce them, and review them using least privilege and separation of duties.

    NIST source · p. 20
  6. PR.AA-06

    Manage, monitor, and enforce physical access to assets according to risk.

    NIST source · p. 20
PR.ATAwareness and Training2 subcategories
  1. PR.AT-01

    Give personnel the awareness, knowledge, and skills needed to consider cybersecurity risks in their everyday work.

    NIST source · p. 20
  2. PR.AT-02

    Provide role-specific awareness and training for people with specialized responsibilities.

    NIST source · p. 20
PR.DSData Security4 subcategories
  1. PR.DS-01

    Protect stored data against unauthorized disclosure, alteration, and loss of availability.

    NIST source · p. 20
  2. PR.DS-02

    Protect data being transmitted against unauthorized disclosure, alteration, and loss of availability.

    NIST source · p. 20
  3. PR.DS-10

    Protect data while it is being used or processed against unauthorized disclosure, alteration, and loss of availability.

    NIST source · p. 20
  4. PR.DS-11

    Create, safeguard, maintain, and test data backups.

    NIST source · p. 20
PR.PSPlatform Security6 subcategories
  1. PR.PS-01

    Establish and use configuration management practices.

    NIST source · p. 20
  2. PR.PS-02

    Maintain, replace, or remove software according to its risks.

    NIST source · p. 20
  3. PR.PS-03

    Maintain, replace, or remove hardware according to its risks.

    NIST source · p. 20
  4. PR.PS-04

    Generate logs and make them available to support ongoing monitoring.

    NIST source · p. 20
  5. PR.PS-05

    Prevent unauthorized software from being installed or run.

    NIST source · p. 20
  6. PR.PS-06

    Integrate secure development practices and monitor their performance throughout the software life cycle.

    NIST source · p. 20
PR.IRTechnology Infrastructure Resilience4 subcategories
  1. PR.IR-01

    Protect networks and environments against unauthorized logical access and use.

    NIST source · p. 20
  2. PR.IR-02

    Protect technology assets from environmental hazards.

    NIST source · p. 21
  3. PR.IR-03

    Implement measures that meet resilience needs during normal operations and disruptions.

    NIST source · p. 21
  4. PR.IR-04

    Maintain sufficient resource capacity to keep services available.

    NIST source · p. 21
Detect (DE)2 categories · 11 subcategories
DE.CMContinuous Monitoring5 subcategories
  1. DE.CM-01

    Monitor networks and network services for potentially harmful events.

    NIST source · p. 21
  2. DE.CM-02

    Monitor the physical environment for potentially harmful events.

    NIST source · p. 21
  3. DE.CM-03

    Monitor personnel activities and technology use for potentially harmful events.

    NIST source · p. 21
  4. DE.CM-06

    Monitor external providers’ activities and services for potentially harmful events.

    NIST source · p. 21
  5. DE.CM-09

    Monitor computing hardware, software, runtime environments, and their data for potentially harmful events.

    NIST source · p. 21
DE.AEAdverse Event Analysis6 subcategories
  1. DE.AE-02

    Analyze potentially harmful events to understand the associated activities.

    NIST source · p. 21
  2. DE.AE-03

    Connect information from multiple sources to understand events.

    NIST source · p. 21
  3. DE.AE-04

    Understand the estimated scope and impact of harmful events.

    NIST source · p. 21
  4. DE.AE-06

    Provide event information to authorized personnel and tools.

    NIST source · p. 21
  5. DE.AE-07

    Include threat intelligence and other context in event analysis.

    NIST source · p. 21
  6. DE.AE-08

    Declare an incident when events meet the organization’s defined incident criteria.

    NIST source · p. 21
Respond (RS)4 categories · 13 subcategories
RS.MAIncident Management5 subcategories
  1. RS.MA-01

    Once an incident is declared, carry out the response plan with relevant third parties.

    NIST source · p. 22
  2. RS.MA-02

    Triage incident reports and check that they are valid.

    NIST source · p. 22
  3. RS.MA-03

    Classify incidents and set their priority.

    NIST source · p. 22
  4. RS.MA-04

    Escalate incidents to the appropriate level when needed.

    NIST source · p. 22
  5. RS.MA-05

    Apply the criteria that determine when recovery should begin.

    NIST source · p. 22
RS.ANIncident Analysis4 subcategories
  1. RS.AN-03

    Determine what happened during the incident and identify its root cause.

    NIST source · p. 22
  2. RS.AN-06

    Record investigation actions and preserve the integrity and origin of those records.

    NIST source · p. 22
  3. RS.AN-07

    Collect incident data and metadata while preserving their integrity and origin.

    NIST source · p. 22
  4. RS.AN-08

    Estimate and validate the magnitude of the incident.

    NIST source · p. 22
RS.COIncident Response Reporting and Communication2 subcategories
  1. RS.CO-02

    Notify internal and external stakeholders about incidents.

    NIST source · p. 22
  2. RS.CO-03

    Share incident information with designated stakeholders inside and outside the organization.

    NIST source · p. 22
RS.MIIncident Mitigation2 subcategories
  1. RS.MI-01

    Contain incidents to limit their spread and effects.

    NIST source · p. 22
  2. RS.MI-02

    Eradicate the incident, removing the malicious presence or other causes that sustain it.

    NIST source · p. 22
Recover (RC)2 categories · 8 subcategories
RC.RPIncident Recovery Plan Execution6 subcategories
  1. RC.RP-01

    Carry out the recovery part of the incident response plan when the response process initiates it.

    NIST source · p. 22
  2. RC.RP-02

    Select recovery actions, define their scope and priority, and perform them.

    NIST source · p. 23
  3. RC.RP-03

    Check the integrity of backups and other recovery resources before using them to restore operations.

    NIST source · p. 23
  4. RC.RP-04

    Consider critical mission functions and cybersecurity risks when establishing how operations will run after the incident.

    NIST source · p. 23
  5. RC.RP-05

    Verify restored assets are intact, restore systems and services, and confirm normal operations.

    NIST source · p. 23
  6. RC.RP-06

    Use defined criteria to declare recovery complete and finish incident documentation.

    NIST source · p. 23
RC.COIncident Recovery Communication2 subcategories
  1. RC.CO-03

    Keep designated internal and external stakeholders informed about recovery work and restoration progress.

    NIST source · p. 23
  2. RC.CO-04

    Use approved channels and messaging for public updates on recovery.

    NIST source · p. 23