NIST CSF 2.0 · 106 subcategories · Client-side

NIST CSF 2.0 Reference

Search all 106 subcategories of the NIST Cybersecurity Framework 2.0 with official Core text, evidence examples, and ISO 27001 mapping. Covers all six functions — Govern, Identify, Protect, Detect, Respond, Recover. Built for security teams building profiles and gap assessments.

All 106 NIST CSF 2.0 subcategories

Open any subcategory for its Core text, evidence examples, and its ISO 27001:2022 mapping.

GV — Govern (31)

GV.OC-01 Organizational mission GV.OC-02 Internal and external stakeholders GV.OC-03 Legal, regulatory and contractual requirements GV.OC-04 Critical objectives, capabilities and services GV.OC-05 Dependencies on external resources GV.RM-01 Risk management objectives GV.RM-02 Risk appetite and tolerance GV.RM-03 Cyber risk in enterprise risk management GV.RM-04 Risk response direction GV.RM-05 Risk communication lines GV.RM-06 Standardized risk measurement GV.RM-07 Strategic opportunities GV.RR-01 Leadership accountability GV.RR-02 Roles, responsibilities and authorities GV.RR-03 Adequate resources GV.RR-04 Cybersecurity in HR practices GV.PO-01 Policy established and communicated GV.PO-02 Policy reviewed and updated GV.OV-01 Strategy outcomes reviewed GV.OV-02 Strategy reviewed and adjusted for coverage GV.OV-03 Risk management performance measured GV.SC-01 Supply chain risk management program GV.SC-02 Supplier roles and responsibilities GV.SC-03 Supply chain risk in ERM GV.SC-04 Suppliers prioritized by criticality GV.SC-05 Supply chain requirements in contracts GV.SC-06 Due diligence before supplier relationships GV.SC-07 Ongoing supplier risk monitoring GV.SC-08 Suppliers in incident planning GV.SC-09 Supply chain security throughout lifecycle GV.SC-10 Post-relationship supply chain plans

ID — Identify (21)

ID.AM-01 Hardware inventory ID.AM-02 Software and service inventory ID.AM-03 Network communication and data flows ID.AM-04 Supplier-provided asset inventory ID.AM-05 Asset prioritization ID.AM-07 Data inventory and classification ID.AM-08 Asset lifecycle management ID.RA-01 Vulnerability identification ID.RA-02 Threat intelligence received ID.RA-03 Internal and external threats identified ID.RA-04 Threat impact and likelihood ID.RA-05 Risk prioritization from threats, vulnerabilities, impacts ID.RA-06 Risk responses chosen and tracked ID.RA-07 Changes and exceptions risk-assessed ID.RA-08 Vulnerability disclosure handling ID.RA-09 Hardware and software integrity verified pre-use ID.RA-10 Critical supplier assessment ID.IM-01 Improvements from evaluations ID.IM-02 Improvements from tests and exercises ID.IM-03 Improvements from operations ID.IM-04 Plans established and maintained

PR — Protect (22)

PR.AA-01 Identity and credential management PR.AA-02 Identity proofing PR.AA-03 Authentication of users, services and hardware PR.AA-04 Identity assertion protection PR.AA-05 Access authorization and least privilege PR.AA-06 Physical access management PR.AT-01 General awareness and training PR.AT-02 Specialized role training PR.DS-01 Data-at-rest protection PR.DS-02 Data-in-transit protection PR.DS-10 Data-in-use protection PR.DS-11 Backups created and tested PR.PS-01 Configuration management PR.PS-02 Software maintenance and patching PR.PS-03 Hardware maintenance and replacement PR.PS-04 Log generation for monitoring PR.PS-05 Unauthorized software prevention PR.PS-06 Secure software development PR.IR-01 Network protection from unauthorized access PR.IR-02 Protection from environmental threats PR.IR-03 Resilience mechanisms PR.IR-04 Adequate resource capacity

DE — Detect (11)

DE.CM-01 Network monitoring DE.CM-02 Physical environment monitoring DE.CM-03 Personnel activity and technology usage monitoring DE.CM-06 External provider activity monitoring DE.CM-09 Computing hardware, software and services monitoring DE.AE-02 Event analysis for indicators DE.AE-03 Event correlation across sources DE.AE-04 Event impact and scope estimation DE.AE-06 Event information provided to stakeholders DE.AE-07 Threat intel enrichment of analysis DE.AE-08 Incident declaration criteria

RS — Respond (13)

RS.MA-01 Response plan execution RS.MA-02 Incident report triage and validation RS.MA-03 Incident categorization and prioritization RS.MA-04 Incident escalation RS.MA-05 Recovery initiation criteria RS.AN-03 Root cause and incident analysis RS.AN-06 Investigation actions recorded RS.AN-07 Incident data and metadata preserved RS.AN-08 Incident magnitude estimated and validated RS.CO-02 Stakeholder notification of incidents RS.CO-03 Information sharing with stakeholders RS.MI-01 Incident containment RS.MI-02 Incident eradication

RC — Recover (8)

RC.RP-01 Recovery plan execution RC.RP-02 Recovery actions selected and prioritized RC.RP-03 Backup and asset integrity verified before restore RC.RP-04 Post-incident operational norms restored RC.RP-05 Asset integrity confirmed and services restored RC.RP-06 Recovery completion declared RC.CO-03 Recovery communication to stakeholders RC.CO-04 Public recovery updates

Frequently asked questions

How many subcategories are in NIST CSF 2.0?

NIST CSF 2.0 (CSWP 29, February 2024) defines 106 subcategories organised into 22 categories and 6 functions: Govern (31), Identify (21), Protect (22), Detect (11), Respond (13) and Recover (8). This tool lets you search and browse all 106, each with evidence examples.

What changed between NIST CSF 1.1 and 2.0?

CSF 2.0 added a sixth function — Govern — covering strategy, policy, roles, oversight and supply chain risk management, expanded the framework beyond critical infrastructure to all organisations, and reorganised the Core from 108 subcategories (1.1) to 106. It also introduced Organizational Profiles and Tiers guidance for implementation.

Is this NIST CSF tool free and private?

Yes. The reference is 100% free and runs entirely in your browser — no account, no sign-up, and nothing is sent to a server. You can also map CSF 2.0 to ISO 27001 and SOC 2 with the Control Mapper.

Does NIST CSF map to ISO 27001?

Yes — most CSF 2.0 subcategories have equivalent ISO 27001:2022 Annex A controls, and NIST publishes informative references between the frameworks. Each subcategory page in this tool shows its ISO 27001 mapping, and the Control Mapper provides the full three-framework crosswalk with a maturity gap assessment.