Search all 106 subcategories of the NIST Cybersecurity Framework 2.0 with official Core text, evidence examples, and ISO 27001 mapping. Covers all six functions — Govern, Identify, Protect, Detect, Respond, Recover. Built for security teams building profiles and gap assessments.
Open any subcategory for its Core text, evidence examples, and its ISO 27001:2022 mapping.
NIST CSF 2.0 (CSWP 29, February 2024) defines 106 subcategories organised into 22 categories and 6 functions: Govern (31), Identify (21), Protect (22), Detect (11), Respond (13) and Recover (8). This tool lets you search and browse all 106, each with evidence examples.
CSF 2.0 added a sixth function — Govern — covering strategy, policy, roles, oversight and supply chain risk management, expanded the framework beyond critical infrastructure to all organisations, and reorganised the Core from 108 subcategories (1.1) to 106. It also introduced Organizational Profiles and Tiers guidance for implementation.
Yes. The reference is 100% free and runs entirely in your browser — no account, no sign-up, and nothing is sent to a server. You can also map CSF 2.0 to ISO 27001 and SOC 2 with the Control Mapper.
Yes — most CSF 2.0 subcategories have equivalent ISO 27001:2022 Annex A controls, and NIST publishes informative references between the frameworks. Each subcategory page in this tool shows its ISO 27001 mapping, and the Control Mapper provides the full three-framework crosswalk with a maturity gap assessment.