NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Consumer Privacy and Marketing
Honor consumer privacy rights + consent + marketing + loyalty data obligations per applicable jurisdiction privacy law + sectoral marketing law. Privacy rights must (a) honor data subject access + deletion + correction + portability + opt-out of sale or sharing + opt-out of targeted advertising + limit use of sensitive personal information + non-discrimination per CCPA + CPRA + similar state laws, (b) provide privacy notice at collection with content per applicable law, (c) honor Global Privacy Control signal + Universal Opt-Out Mechanism where applicable, (d) age-gate children data per COPPA + state child privacy laws + sensitive flag transgender/non-binary data per state-specific provisions. Consent must (a) obtain opt-in consent where required (sensitive data + marketing email/SMS per CAN-SPAM/TCPA + cross-border transfers per GDPR + EU consumer products per ePrivacy), (b) distinguish
- per-state privacy rights handling (access + deletion + correction + portability + opt-out + sensitive data limit)
- consent management platform + consent receipts + revocation handling + audit trail
- marketing preference center + CAN-SPAM + TCPA + DNC compliance evidence
- Global Privacy Control + UOOM honor evidence where applicable
- loyalty data uses unmapped producing consent gaps
- consent banners present but consent management infrastructure absent
- TCPA prior express written consent not maintained for SMS marketing
Detection, IR, Breach, Fraud
Operate detection + logging + IR + breach notification + fraud detection per NRF framework + NIST SP 800-61 + state breach notification laws + PCI DSS incident response + brand operating rules. Logging and detection must (a) collect logs from POS + e-commerce + payment processing + IAM + endpoint + network + cloud + mobile app + in-store IoT + loyalty + customer service applications with retail-aware correlation rules, (b) deploy detection rules covering retail-specific patterns (skimming + form-jacking + account takeover + credential stuffing + return fraud + chargeback abuse + gift card fraud + insider misuse + ransomware staging), (c) integrate threat intelligence from R-CISC / RH-ISAC + payment brand fraud feeds + commercial threat intelligence. Incident response must (a) maintain IR plan covering retail scenarios with cross-functional team (cyber + privacy + payments + legal + comms
- log collection across POS + e-commerce + payment + IAM + endpoint + network + cloud + mobile + store IoT with retail correlation rules
- IR plan with retail scenarios + cross-functional team + payment brand coordination + PFI readiness
- state breach notification matrix actionable at incident time + GDPR + sectoral coverage
- fraud detection across digital + physical channels + integration with cybersecurity
- state breach notification matrix absent producing late notifications
- PCI Forensic Investigator (PFI) relationship not pre-established
- fraud + cybersecurity siloed missing compromise-enabled-fraud signals
E-Commerce, Mobile, Store, IoT
Secure e-commerce + mobile + in-store technology + IoT per NRF framework and OWASP + vendor-specific guidance. E-commerce security must (a) protect against OWASP Top 10 + API Top 10 vulnerabilities + skimming + form-jacking via subresource integrity + Content Security Policy + script monitoring + behavioural analytics, (b) implement bot management against credential stuffing + scraping + scalping + inventory hoarding + fake review generation, (c) protect checkout via PCI-compliant payment integration + 3D Secure / 3DS2 + tokenisation + risk-based authentication, (d) maintain WAF + DDoS protection + traffic anomaly detection. Mobile and in-store app security must (a) protect against mobile-specific threats per OWASP Mobile Top 10 + MASVS + MASTG verification, (b) implement secure mobile payment per PCI Mobile Payment Acceptance + Apple Pay + Google Pay + secure element + tokenisation, (c)
- e-commerce security evidence (OWASP + CSP + SRI + script monitoring + bot management + WAF + DDoS)
- mobile app security evidence (MASVS + secure mobile payment + tokenisation)
- store technology and IoT inventory + segmentation + patching + monitoring
- subresource integrity + third-party script monitoring for skimming protection
- third-party scripts on checkout without CSP or SRI producing skimming exposure
- store IoT not segmented from POS network
- mobile app penetration testing not performed before release
IAM, Workforce, Training
Operate IAM + workforce security + training across the retail enterprise per NRF framework. IAM must (a) implement multi-factor authentication for all employees + contractors + service accounts where feasible + with priority for privileged access + remote access + admin consoles + e-commerce backend + payment processing + finance systems + HR systems + customer database access, (b) implement least privilege + separation of duties + role engineering for retail roles (store associate + manager + loss prevention + corporate office + IT + cybersecurity + finance + HR + supplier + contractor), (c) operate the joiner-mover-leaver lifecycle with documented SLA for new-hire access provisioning + role change + termination access revocation (target maximum hours for termination), (d) implement privileged access management with credential vaulting + session recording + JIT approval + emergency-acce
- MFA coverage report + role-based access + privileged access management + termination SLA tracking
- seasonal hiring security onboarding evidence
- training records by role + phishing simulation results + retail-specific scenarios
- loss prevention access governance + contractor access management
- seasonal employees onboarded without security training
- termination access revocation SLA missed routinely
- training not tailored to retail roles
Payment Card Protection and PCI DSS
Operate payment card data protection per the NRF framework + PCI DSS v4.0.1 + card brand operating rules (Visa + Mastercard + American Express + Discover + JCB + UnionPay + regional schemes). PCI DSS scope management must (a) accurately scope the Cardholder Data Environment (CDE) including all systems that store + process + transmit cardholder data + connected systems + security systems + service providers + merchant-of-record relationships, (b) implement scope-reduction strategies (point-to-point encryption + tokenisation + outsourced payment processing + e-commerce iframe / redirect to PSP-hosted payment pages + EMV chip + contactless) with documented residual scope, (c) achieve and maintain PCI DSS compliance per applicable merchant level (Level 1 over 6M card transactions + Level 2 1M-6M + Level 3 20K-1M e-commerce + Level 4 below) + Self-Assessment Questionnaire type + or Report on
- accurate CDE scoping with all in-scope systems including connected + security systems + service providers
- PCI DSS compliance per merchant level + SAQ type or RoC + remediation closure
- scope-reduction implementation evidence (P2PE + tokenisation + iframe + EMV + contactless)
- PCI v4.0 Future-dated Requirement transition plan
- scope under-defined missing connected systems or service providers
- PCI v4.0 Future-dated Requirement transition not planned or budgeted
- tokenisation deployed but original CHD still flowing through scope
Retail Cyber Governance
Establish cybersecurity governance and policy structures appropriate to retail industry characteristics per the NRF Cybersecurity and Data Privacy Framework guidance and supporting NIST CSF alignment. Governance must (a) name accountable executives (CISO + Chief Privacy Officer + Chief Risk Officer + Chief Operating Officer + Chief Marketing Officer + Chief Digital Officer where applicable) with documented decision authority, (b) maintain cyber and privacy policies covering acceptable use + access control + data classification + incident response + breach notification + third-party risk + PCI DSS scope + e-commerce + mobile + in-store technology + supply chain + retail-specific peak-season operations + fraud prevention, (c) align to NIST Cybersecurity Framework 2.0 functions (Govern + Identify + Protect + Detect + Respond + Recover) with retail-specific implementation tier targets, (d) r
- named cyber + privacy + risk executive accountability with retail-specific decision authority
- cyber and privacy policies covering retail-specific scope
- regulatory inventory + change-monitoring service + cross-functional change committee
- alignment to NIST CSF 2.0 with retail implementation tier targets
- regulatory inventory incomplete missing state-specific + international
- policy generic not retail-specific
- no cross-functional change committee producing surprise exposures
Risk Assessment and Data Inventory
Conduct retail-tailored risk assessment + customer data inventory + classification per the NRF framework + NIST SP 800-30 Rev 1 + adaptation to retail threat model. Customer data inventory must enumerate (a) data types collected (loyalty + transaction + browsing + clickstream + mobile location + in-store sensor + camera + payment + employee + supplier + business operations data), (b) sources (POS + e-commerce site + mobile app + email signup + in-store kiosk + loyalty programme + customer service interaction + supplier portal + third-party data brokers + warranty / registration data + market research), (c) processing locations (data centres + cloud + retail stores + warehouses + distribution centres + supplier facilities + third-party processors + cross-border transfers), (d) retention periods + deletion procedures + data subject rights compliance per applicable jurisdiction. Classificat
- retail risk assessment with retail threat model + impact analysis
- customer data inventory covering all retail data sources + locations + retention + rights compliance
- data discovery exercise output reconciled against inventory
- loyalty + clickstream data under-inventoried
- retail threat model generic IT not retail-specific
- data inventory not refreshed after new digital channel launches
Third-Party, Resilience, Metrics
Operate third-party risk + supply chain + resilience + metrics + continuous improvement per NRF framework. Third-party risk must (a) maintain vendor inventory categorised by data access + critical service + payment processing + e-commerce platform + cloud service + IT outsourcer + marketing service + analytics service + supplier-of-merchandise, (b) tier vendors by risk + apply due diligence at acquisition + contract requirements (cybersecurity + privacy + breach notification + audit rights + flow-down to subcontractors + insurance + indemnification) + ongoing monitoring (SOC 2 + ISO 27001 + ASV scans + sanction screening + financial health), (c) operate vendor breach response coordination protocols. Supply chain security must address (a) merchandise supply chain (counterfeit + diversion + theft + customs + traceability), (b) IT and technology supply chain (SaaS + cloud + hardware + firmw
- vendor inventory tiered by risk + contract requirements + ongoing monitoring + breach response coordination
- merchandise + IT + physical supply chain security evidence
- peak-season readiness plan + capacity testing + change freeze + heightened monitoring + IR capacity
- metrics dashboard + executive + board reporting + peer benchmarking
- vendor inventory incomplete missing analytics + marketing service providers
- no change freeze during peak shopping periods producing avoidable incidents
- metrics measured but not reported to executive or board
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NRF Cybersecurity and Data Privacy Framework (National Retail Federation) framework page.