PR 22 subcategories · 5 categories

NIST CSF 2.0 Protect (PR)

Protect covers identity and access management, awareness and training, data security, platform security and technology infrastructure resilience. This is where most existing security spend already sits, so the usual gap is not a missing control but incomplete coverage — the control exists, and it covers the systems that were straightforward to onboard.

PR.AA — Identity Management, Authentication, and Access Control

PR.AA-01 Identity and credential management
Identities and credentials for authorized users, services, and hardware are managed by the organization.
PR.AA-02 Identity proofing
Identities are proofed and bound to credentials based on the context of interactions.
PR.AA-03 Authentication of users, services and hardware
Users, services, and hardware are authenticated.
PR.AA-04 Identity assertion protection
Identity assertions are protected, conveyed, and verified.
PR.AA-05 Access authorization and least privilege
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.
PR.AA-06 Physical access management
Physical access to assets is managed, monitored, and enforced commensurate with risk.

PR.AT — Awareness and Training

PR.AT-01 General awareness and training
Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.
PR.AT-02 Specialized role training
Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind.

PR.DS — Data Security

PR.DS-01 Data-at-rest protection
The confidentiality, integrity, and availability of data-at-rest are protected.
PR.DS-02 Data-in-transit protection
The confidentiality, integrity, and availability of data-in-transit are protected.
PR.DS-10 Data-in-use protection
The confidentiality, integrity, and availability of data-in-use are protected.
PR.DS-11 Backups created and tested
Backups of data are created, protected, maintained, and tested.

PR.PS — Platform Security

PR.PS-01 Configuration management
Configuration management practices are established and applied.
PR.PS-02 Software maintenance and patching
Software is maintained, replaced, and removed commensurate with risk.
PR.PS-03 Hardware maintenance and replacement
Hardware is maintained, replaced, and removed commensurate with risk.
PR.PS-04 Log generation for monitoring
Log records are generated and made available for continuous monitoring.
PR.PS-05 Unauthorized software prevention
Installation and execution of unauthorized software are prevented.
PR.PS-06 Secure software development
Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle.

PR.IR — Technology Infrastructure Resilience

PR.IR-01 Network protection from unauthorized access
Networks and environments are protected from unauthorized logical access and usage.
PR.IR-02 Protection from environmental threats
The organization's technology assets are protected from environmental threats.
PR.IR-03 Resilience mechanisms
Mechanisms are implemented to achieve resilience requirements in normal and adverse situations.
PR.IR-04 Adequate resource capacity
Adequate resource capacity to ensure availability is maintained.

Other CSF 2.0 functions

GV ID DE RS RC
Crosswalk to ISO 27001 & SOC 2 →
Map these outcomes across frameworks in the Control Mapper.
Search all 106 subcategories →
Filter the CSF 2.0 Core by keyword, function or category.

Frequently asked questions

How many subcategories are in the NIST CSF Protect function?

Protect (PR) contains 22 subcategories across 5 categories. CSF 2.0 defines 106 subcategories in total across six functions: Govern, Identify, Protect, Detect, Respond and Recover.

Is the Protect function mandatory?

No. CSF 2.0 is a voluntary framework of outcomes and there is no certification against it. Its outcomes become binding only through a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

What changed in the Protect function in CSF 2.0?

CSF 2.0 restructured the Core and renumbered subcategories, so PR identifiers do not map one-to-one to CSF 1.1. If you are transitioning a profile, re-assess against the 2.0 Core rather than renaming your existing entries.