RC 8 subcategories · 2 categories

NIST CSF 2.0 Recover (RC)

Recover covers incident recovery plan execution and recovery communication. It is the least frequently tested function in practice and the most commonly assumed: a backup job that reports success is not recovery evidence. Restoration testing against a defined recovery time objective is what demonstrates these outcomes.

RC.RP — Incident Recovery Plan Execution

RC.RP-01 Recovery plan execution
The recovery portion of the incident response plan is executed once initiated from the incident response process.
RC.RP-02 Recovery actions selected and prioritized
Recovery actions are selected, scoped, prioritized, and performed.
RC.RP-03 Backup and asset integrity verified before restore
The integrity of backups and other restoration assets is verified before using them for restoration.
RC.RP-04 Post-incident operational norms restored
Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms.
RC.RP-05 Asset integrity confirmed and services restored
The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed.
RC.RP-06 Recovery completion declared
The end of incident recovery is declared based on criteria, and incident-related documentation is completed.

RC.CO — Incident Recovery Communication

RC.CO-03 Recovery communication to stakeholders
Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders.
RC.CO-04 Public recovery updates
Public updates on incident recovery are shared using approved methods and messaging.

Other CSF 2.0 functions

GV ID PR DE RS
Crosswalk to ISO 27001 & SOC 2 →
Map these outcomes across frameworks in the Control Mapper.
Search all 106 subcategories →
Filter the CSF 2.0 Core by keyword, function or category.

Frequently asked questions

How many subcategories are in the NIST CSF Recover function?

Recover (RC) contains 8 subcategories across 2 categories. CSF 2.0 defines 106 subcategories in total across six functions: Govern, Identify, Protect, Detect, Respond and Recover.

Is the Recover function mandatory?

No. CSF 2.0 is a voluntary framework of outcomes and there is no certification against it. Its outcomes become binding only through a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

What changed in the Recover function in CSF 2.0?

CSF 2.0 restructured the Core and renumbered subcategories, so RC identifiers do not map one-to-one to CSF 1.1. If you are transitioning a profile, re-assess against the 2.0 Core rather than renaming your existing entries.