NIST Cybersecurity Framework 2.0
What is NIST Cybersecurity Framework 2.0?
Voluntary framework for managing and reducing cybersecurity risk, organized around six core functions. It comprises 106 controls organised across 12 domains, published by NIST, and applies in the United States.
How NIST Cybersecurity Framework 2.0 maps to other frameworks
All 106 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 12 domains NIST Cybersecurity Framework 2.0 groups its controls into
Where NIST Cybersecurity Framework 2.0 overlaps with the standards you already hold
Step-by-step implementation of NIST Cybersecurity Framework 2.0
More NIST Cybersecurity Framework 2.0 comparisons
Analysis of NIST Cybersecurity Framework 2.0
Training that covers NIST Cybersecurity Framework 2.0
What NIST Cybersecurity Framework 2.0 means in your sector
What NIST Cybersecurity Framework 2.0 means for your job
Questions people ask about NIST Cybersecurity Framework 2.0
What is NIST Cybersecurity Framework 2.0?
How many controls does NIST Cybersecurity Framework 2.0 have?
Where does NIST Cybersecurity Framework 2.0 apply?
What frameworks does NIST Cybersecurity Framework 2.0 map to?
How do I get started with NIST Cybersecurity Framework 2.0 compliance?
Query NIST Cybersecurity Framework 2.0 programmatically
NIST Cybersecurity Framework 2.0, its 106 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
NIST Cybersecurity Framework 2.0 API reference and MCP config →What NIST Cybersecurity Framework 2.0 requires, control by control
Each page carries the requirement text for one NIST Cybersecurity Framework 2.0 control and what an assessor expects to see as evidence.
- NIST-CSF-DE-AE-02 Potentially adverse events are analyzed to better understand associated activities
- NIST-CSF-DE-AE-03 Information is correlated from multiple sources
- NIST-CSF-DE-AE-04 The estimated impact and scope of adverse events are understood
- NIST-CSF-DE-AE-06 Information on adverse events is provided to authorized staff and tools
- NIST-CSF-DE-AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
- NIST-CSF-DE-AE-08 Incidents are declared when adverse events meet the defined incident criteria
- NIST-CSF-DE-CM-01 Networks and network services are monitored to find potentially adverse events
- NIST-CSF-DE-CM-02 The physical environment is monitored to find potentially adverse events
- NIST-CSF-DE-CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
- NIST-CSF-DE-CM-06 External service provider activities and services are monitored to find potentially adverse events
How much of another standard NIST Cybersecurity Framework 2.0 already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- ACSC Essential Eight to NIST Cybersecurity Framework 2.0 crosswalk
- ANSSI Guide d'hygiene informatique (42 mesures, v2.0) to NIST Cybersecurity Framework 2.0 crosswalk
- APRA CPS 220 Risk Management to NIST Cybersecurity Framework 2.0 crosswalk
- APRA CPS 230 Operational Risk Management to NIST Cybersecurity Framework 2.0 crosswalk
- APRA CPS 234 to NIST Cybersecurity Framework 2.0 crosswalk
- ASD Strategies to Mitigate Cyber Security Incidents to NIST Cybersecurity Framework 2.0 crosswalk
- Australia Consumer Data Right - Banking (CDR) to NIST Cybersecurity Framework 2.0 crosswalk
- Australia My Health Records Act 2012 to NIST Cybersecurity Framework 2.0 crosswalk
How ready are you for NIST Cybersecurity Framework 2.0?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.