RS 13 subcategories · 4 categories

NIST CSF 2.0 Respond (RS)

Respond covers incident management, analysis, reporting and communication, and mitigation. Response capability is hard to evidence without incidents, so exercises and tabletop records carry the weight — they are what demonstrates the capability exists before it is needed rather than after.

RS.MA — Incident Management

RS.MA-01 Response plan execution
The incident response plan is executed in coordination with relevant third parties once an incident is declared.
RS.MA-02 Incident report triage and validation
Incident reports are triaged and validated.
RS.MA-03 Incident categorization and prioritization
Incidents are categorized and prioritized.
RS.MA-04 Incident escalation
Incidents are escalated or elevated as needed.
RS.MA-05 Recovery initiation criteria
The criteria for initiating incident recovery are applied.

RS.AN — Incident Analysis

RS.AN-03 Root cause and incident analysis
Analysis is performed to establish what has taken place during an incident and the root cause of the incident.
RS.AN-06 Investigation actions recorded
Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved.
RS.AN-07 Incident data and metadata preserved
Incident data and metadata are collected, and their integrity and provenance are preserved.
RS.AN-08 Incident magnitude estimated and validated
An incident's magnitude is estimated and validated.

RS.CO — Incident Response Reporting and Communication

RS.CO-02 Stakeholder notification of incidents
Internal and external stakeholders are notified of incidents.
RS.CO-03 Information sharing with stakeholders
Information is shared with designated internal and external stakeholders.

RS.MI — Incident Mitigation

RS.MI-01 Incident containment
Incidents are contained.
RS.MI-02 Incident eradication
Incidents are eradicated.

Other CSF 2.0 functions

GV ID PR DE RC
Crosswalk to ISO 27001 & SOC 2 →
Map these outcomes across frameworks in the Control Mapper.
Search all 106 subcategories →
Filter the CSF 2.0 Core by keyword, function or category.

Frequently asked questions

How many subcategories are in the NIST CSF Respond function?

Respond (RS) contains 13 subcategories across 4 categories. CSF 2.0 defines 106 subcategories in total across six functions: Govern, Identify, Protect, Detect, Respond and Recover.

Is the Respond function mandatory?

No. CSF 2.0 is a voluntary framework of outcomes and there is no certification against it. Its outcomes become binding only through a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

What changed in the Respond function in CSF 2.0?

CSF 2.0 restructured the Core and renumbered subcategories, so RS identifiers do not map one-to-one to CSF 1.1. If you are transitioning a profile, re-assess against the 2.0 Core rather than renaming your existing entries.