NIST CSF 2.0 Subcategories in Excel — all 106

Last updated:

Every subcategory of the NIST Cybersecurity Framework (CSF) 2.0 in one spreadsheet, with its function and category on each row. A last column names the toolkit document written for each category. Free, no email required.

Download the Excel file (.xlsx) — free

Need the written policies, not only the list? NIST CSF 2.0 Complete Toolkit ($79)

At a glance

NIST CSF 2.0 has 106 subcategories in 22 categories, grouped under 6 functions. Each subcategory is one outcome to work toward.

Categories and subcategories per NIST CSF 2.0 function
FunctionCategoriesSubcategories
GOVERN (GV)631
IDENTIFY (ID)321
PROTECT (PR)522
DETECT (DE)211
RESPOND (RS)413
RECOVER (RC)28
Total22106

What's in the workbook

  • One row per subcategory, 106 in all, with six columns: function, category ID, category, subcategory ID, the subcategory text, and "Covered by".
  • NIST's own wording. The function, category and subcategory text is copied from the framework without change.
  • "Covered by" names the document in the NIST CSF 2.0 Complete Toolkit that is written for the row's category.
  • An About sheet with the source, how to use the list, and what it is not.

There are no status or priority columns. Add your own, or see the toolkit section at the end of this page.

How to use it

  1. Filter the Function or Category column to work through one area at a time.
  2. Add your own columns for where you are today, where you want to be, who owns each outcome, and where the evidence lives.
  3. Use the "Covered by" column to find the policy or plan to read or write next.
  4. Review the list again when your systems, suppliers or risks change.

All 106 subcategories

Jump to: GOVERN · IDENTIFY · PROTECT · DETECT · RESPOND · RECOVER

GOVERN (GV): 6 categories, 31 subcategories

Organizational Context (GV.OC) · Covered by: Cybersecurity Governance Policy
IDSubcategory
GV.OC-01The organizational mission is understood and informs cybersecurity risk management
GV.OC-02Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
GV.OC-03Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
GV.OC-04Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
GV.OC-05Outcomes, capabilities, and services that the organization depends on are understood and communicated
Risk Management Strategy (GV.RM) · Covered by: Cyber Risk Management Strategy and Procedure
IDSubcategory
GV.RM-01Risk management objectives are established and agreed to by organizational stakeholders
GV.RM-02Risk appetite and risk tolerance statements are established, communicated, and maintained
GV.RM-03Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
GV.RM-04Strategic direction that describes appropriate risk response options is established and communicated
GV.RM-05Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
GV.RM-06A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
GV.RM-07Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
Roles, Responsibilities, and Authorities (GV.RR) · Covered by: Cybersecurity Roles and Responsibilities
IDSubcategory
GV.RR-01Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
GV.RR-02Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
GV.RR-03Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
GV.RR-04Cybersecurity is included in human resources practices
Policy (GV.PO) · Covered by: Cybersecurity Governance Policy
IDSubcategory
GV.PO-01Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
GV.PO-02Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
Oversight (GV.OV) · Covered by: Cybersecurity Governance Policy
IDSubcategory
GV.OV-01Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
GV.OV-02The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
GV.OV-03Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
Cybersecurity Supply Chain Risk Management (GV.SC) · Covered by: Cybersecurity Supply Chain Risk Management Policy
IDSubcategory
GV.SC-01A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
GV.SC-02Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
GV.SC-03Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
GV.SC-04Suppliers are known and prioritized by criticality
GV.SC-05Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
GV.SC-06Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
GV.SC-07The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
GV.SC-08Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
GV.SC-09Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
GV.SC-10Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

IDENTIFY (ID): 3 categories, 21 subcategories

Asset Management (ID.AM) · Covered by: Asset Management Policy
IDSubcategory
ID.AM-01Inventories of hardware managed by the organization are maintained
ID.AM-02Inventories of software, services, and systems managed by the organization are maintained
ID.AM-03Representations of the organization's authorized network communication and internal and external network data flows are maintained
ID.AM-04Inventories of services provided by suppliers are maintained
ID.AM-05Assets are prioritized based on classification, criticality, resources, and impact on the mission
ID.AM-07Inventories of data and corresponding metadata for designated data types are maintained
ID.AM-08Systems, hardware, software, services, and data are managed throughout their life cycles
Risk Assessment (ID.RA) · Covered by: Cyber Risk Management Strategy and Procedure
IDSubcategory
ID.RA-01Vulnerabilities in assets are identified, validated, and recorded
ID.RA-02Cyber threat intelligence is received from information sharing forums and sources
ID.RA-03Internal and external threats to the organization are identified and recorded
ID.RA-04Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
ID.RA-05Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
ID.RA-06Risk responses are chosen, prioritized, planned, tracked, and communicated
ID.RA-07Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
ID.RA-08Processes for receiving, analyzing, and responding to vulnerability disclosures are established
ID.RA-09The authenticity and integrity of hardware and software are assessed prior to acquisition and use
ID.RA-10Critical suppliers are assessed prior to acquisition
Improvement (ID.IM) · Covered by: Cybersecurity Improvement Procedure
IDSubcategory
ID.IM-01Improvements are identified from evaluations
ID.IM-02Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
ID.IM-03Improvements are identified from execution of operational processes, procedures, and activities
ID.IM-04Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

PROTECT (PR): 5 categories, 22 subcategories

Identity Management, Authentication, and Access Control (PR.AA) · Covered by: Identity and Access Management Policy
IDSubcategory
PR.AA-01Identities and credentials for authorized users, services, and hardware are managed by the organization
PR.AA-02Identities are proofed and bound to credentials based on the context of interactions
PR.AA-03Users, services, and hardware are authenticated
PR.AA-04Identity assertions are protected, conveyed, and verified
PR.AA-05Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
PR.AA-06Physical access to assets is managed, monitored, and enforced commensurate with risk
Awareness and Training (PR.AT) · Covered by: Security Awareness and Training Procedure
IDSubcategory
PR.AT-01Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
PR.AT-02Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
Data Security (PR.DS) · Covered by: Data Security Policy
IDSubcategory
PR.DS-01The confidentiality, integrity, and availability of data-at-rest are protected
PR.DS-02The confidentiality, integrity, and availability of data-in-transit are protected
PR.DS-10The confidentiality, integrity, and availability of data-in-use are protected
PR.DS-11Backups of data are created, protected, maintained, and tested
Platform Security (PR.PS) · Covered by: Platform and Application Security Policy
IDSubcategory
PR.PS-01Configuration management practices are established and applied
PR.PS-02Software is maintained, replaced, and removed commensurate with risk
PR.PS-03Hardware is maintained, replaced, and removed commensurate with risk
PR.PS-04Log records are generated and made available for continuous monitoring
PR.PS-05Installation and execution of unauthorized software are prevented
PR.PS-06Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
Technology Infrastructure Resilience (PR.IR) · Covered by: Technology Infrastructure Resilience Policy
IDSubcategory
PR.IR-01Networks and environments are protected from unauthorized logical access and usage
PR.IR-02The organization's technology assets are protected from environmental threats
PR.IR-03Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
PR.IR-04Adequate resource capacity to ensure availability is maintained

DETECT (DE): 2 categories, 11 subcategories

Continuous Monitoring (DE.CM) · Covered by: Continuous Monitoring Policy
IDSubcategory
DE.CM-01Networks and network services are monitored to find potentially adverse events
DE.CM-02The physical environment is monitored to find potentially adverse events
DE.CM-03Personnel activity and technology usage are monitored to find potentially adverse events
DE.CM-06External service provider activities and services are monitored to find potentially adverse events
DE.CM-09Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Adverse Event Analysis (DE.AE) · Covered by: Adverse Event Analysis Procedure
IDSubcategory
DE.AE-02Potentially adverse events are analyzed to better understand associated activities
DE.AE-03Information is correlated from multiple sources
DE.AE-04The estimated impact and scope of adverse events are understood
DE.AE-06Information on adverse events is provided to authorized staff and tools
DE.AE-07Cyber threat intelligence and other contextual information are integrated into the analysis
DE.AE-08Incidents are declared when adverse events meet the defined incident criteria

RESPOND (RS): 4 categories, 13 subcategories

Incident Management (RS.MA) · Covered by: Incident Response Plan
IDSubcategory
RS.MA-01The incident response plan is executed in coordination with relevant third parties once an incident is declared
RS.MA-02Incident reports are triaged and validated
RS.MA-03Incidents are categorized and prioritized
RS.MA-04Incidents are escalated or elevated as needed
RS.MA-05The criteria for initiating incident recovery are applied
Incident Analysis (RS.AN) · Covered by: Incident Response Plan
IDSubcategory
RS.AN-03Analysis is performed to establish what has taken place during an incident and the root cause of the incident
RS.AN-06Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
RS.AN-07Incident data and metadata are collected, and their integrity and provenance are preserved
RS.AN-08An incident's magnitude is estimated and validated
Incident Response Reporting and Communication (RS.CO) · Covered by: Incident Response Plan
IDSubcategory
RS.CO-02Internal and external stakeholders are notified of incidents
RS.CO-03Information is shared with designated internal and external stakeholders
Incident Mitigation (RS.MI) · Covered by: Incident Response Plan
IDSubcategory
RS.MI-01Incidents are contained
RS.MI-02Incidents are eradicated

RECOVER (RC): 2 categories, 8 subcategories

Incident Recovery Plan Execution (RC.RP) · Covered by: Incident Recovery Plan
IDSubcategory
RC.RP-01The recovery portion of the incident response plan is executed once initiated from the incident response process
RC.RP-02Recovery actions are selected, scoped, prioritized, and performed
RC.RP-03The integrity of backups and other restoration assets is verified before using them for restoration
RC.RP-04Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
RC.RP-05The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
RC.RP-06The end of incident recovery is declared based on criteria, and incident-related documentation is completed
Incident Recovery Communication (RC.CO) · Covered by: Incident Recovery Plan
IDSubcategory
RC.CO-03Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
RC.CO-04Public updates on incident recovery are shared using approved methods and messaging

Questions about the list

Why do some subcategory numbers skip?
Because NIST withdrew or moved some version 1.1 subcategories in CSF 2.0 and did not renumber the rest. For example, ID.AM-06 was incorporated into GV.RR-02 and GV.SC-02, and PR.DS-04 moved to PR.IR-04. This list holds only the 106 current subcategories.
Does NIST publish its own spreadsheet?
Yes. NIST's CSF 2.0 Reference Tool exports the Core as Excel and JSON. In its Excel export, downloaded on October 6, 2026, the rows are nested under function and category headings, the 79 withdrawn subcategories are still listed, and NIST's implementation examples are included. This list has one row per current subcategory, so it sorts and filters as a flat table, and it adds the toolkit document for each category.

What it is, and what it isn't

The function, category and subcategory text is NIST's. It comes from NIST CSWP 29, "The NIST Cybersecurity Framework (CSF) 2.0", published February 26, 2024. We transcribed it from NIST's machine-readable export of the CSF 2.0 Core (the Cybersecurity and Privacy Reference Tool, CPRT) and checked it against that export word for word on October 6, 2026. As a work of the US Government, it is in the public domain.

The "Covered by" column is our mapping, and it is made by category: each of the 22 categories is assigned to one of the toolkit's 15 documents. It shows where to look. A document does not achieve an outcome by itself.

NIST CSF 2.0 is voluntary, and there is no NIST CSF certification. Filling in this list, or using any template, does not make an organization compliant. Results come from operating the practices the framework describes. This is not legal advice.

Get new templates and guides by email

An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.

If you need the documents as well as the list

This list tells you what the framework asks for. The NIST CSF 2.0 Complete Toolkit is the editable set of 15 policies, procedures and plans named in the "Covered by" column. It also includes a Profile & Assessment workbook with priority, implementation status and target-date columns for the same 106 subcategories. The NIST CSF 2.0 guide explains the framework in plain English, and NIST CSF 2.0 explained covers the six functions and where a small organization can start. Questions: support@compliancedocshq.com.

← All free compliance resources

Professional editable templates — general information only, not legal, audit, tax, or certification advice, and no professional or advisory relationship is created. No purchase makes an organization compliant or certified. Review each document with qualified counsel, your compliance professional, or your auditor before relying on it. ISO, IEC, SOC 2, AICPA, HIPAA, NIST, GDPR, the EU AI Act, IRS and FTC are referenced descriptively only; ComplianceDocs (ExpertEngine LLC) is independent and is not affiliated with, endorsed by, or certified by any standards body, regulator, or audit firm.