NIST CSF Mapper

Browse NIST CSF 2.0 by function and map every subcategory to CIS Controls v8, ISO 27001:2022 and SOC 2 criteria. Search both ways, export CSV free.

Advertisement

NIST CSF 2.0 Control Mapper: CIS Controls v8, ISO 27001:2022 and SOC 2

This mapper turns the NIST Cybersecurity Framework 2.0 into something you can actually work from. Browse the Core by Function and Category, search across control identifiers, names, and descriptions, and see for each subcategory which CIS Controls v8 safeguards, which ISO/IEC 27001:2022 Annex A controls, and which SOC 2 Trust Services Criteria address the same outcome. The mapping also works in reverse: pick a CIS safeguard, an ISO control, or a SOC 2 criterion and see every CSF subcategory it supports. Export the whole cross-reference as CSV in one click.

It exists for the recurring problem of doing the same control work three times. An organisation adopts CSF for its risk conversations, gets audited against SOC 2, and is asked by a customer for ISO 27001 certification. The underlying controls are largely the same controls. This tool makes the overlap explicit so one piece of evidence can serve several frameworks.

The CSF 2.0 Structure

CSF 2.0 was published in February 2024 and made the framework’s first structural change since 2014: it added a sixth Function, Govern, alongside the original five. The full Core is six Functions containing 22 Categories and 106 Subcategories.

FunctionIDOutcome it describes
GovernGVThe cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.
IdentifyIDThe organisation’s current cybersecurity risks are understood — assets, suppliers, and risk assessment.
ProtectPRSafeguards to manage those risks are used — identity, access, data security, platform security, resilience.
DetectDEPossible attacks and compromises are found and analysed.
RespondRSActions regarding a detected incident are taken — management, analysis, communication, mitigation.
RecoverRCAssets and operations affected by an incident are restored, and recovery is communicated.

Govern is not a sixth silo bolted onto the side. It is deliberately placed first and cuts across the other five: organisational context (GV.OC), risk management strategy (GV.RM), roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management (GV.SC). Supply chain risk in particular was promoted out of Identify, where it lived as ID.SC in version 1.1, and given its own Category under Govern — a reasonable reading of what changed in the threat landscape between 2018 and 2024.

Identifiers follow a consistent pattern. PR.AA-01 reads as Function PR (Protect), Category AA (Identity Management, Authentication, and Access Control), Subcategory 01. If you are migrating from CSF 1.1, expect the identifiers to have moved: numbering was reset and several subcategories were merged or relocated, so a 1.1 crosswalk is not a rename exercise.

Two other pieces of CSF sit outside the Core and are worth knowing even though they are not in this tool. Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorously an organisation manages cyber risk — they are not maturity levels and Tier 4 is not automatically the goal. Organizational Profiles capture a Current Profile and a Target Profile, and the gap between them is the improvement plan.

What This Tool Covers

The mapper carries a curated subset of the Core: 48 subcategories across 19 categories, spanning all six Functions, chosen as the ones most commonly cited in audits and customer security questionnaires. Each carries its official identifier, its name, a plain description of the outcome, and its mappings.

  • CIS Controls v8 — referenced as safeguard numbers such as CIS 5.3 or CIS 12.1. CIS is the prescriptive layer: it tells you what to implement, which is what CSF deliberately does not do.
  • ISO/IEC 27001:2022 Annex A — the 93 controls of the 2022 revision, in the A.5 to A.8 numbering (organisational, people, physical, technological). Note that this is the 2022 scheme, not the 114 controls of the 2013 version.
  • SOC 2 Trust Services Criteria — the CC common criteria series plus the additional categories, which is what a service auditor tests against.

The subset is a working cross-reference, not a substitute for the published framework. For a formal gap assessment or a certification scope, work from the NIST Core and the official ISO and AICPA documents; use this to orient yourself and to find the overlap quickly.

How to Use It

  1. Start on the NIST CSF tab and expand a Function to see its Categories, then a Category to see its Subcategories.
  2. Filter by Function when you are working a single area — all six are in the dropdown, or choose All Functions to search everything.
  3. Search across everything. The search box matches control identifiers, names, descriptions, and the mapped control references. Typing A.8.16 or CC7.2 finds the CSF subcategories that map to it.
  4. Click a control for the detail panel: full description and every mapped CIS, ISO, and SOC 2 reference in one place.
  5. Switch to a framework tab — CIS Controls v8, ISO 27001:2022, or SOC 2 TSC — to browse from that side instead. This is the reverse index, and it is the fast way to answer “we already do this for SOC 2; what does it buy us in CSF?”
  6. Export CSV to get the entire cross-reference as a spreadsheet with one row per subcategory and columns for each framework — the practical starting point for a control matrix.

A Worked Example

Take PR.AA-03, “users, services, and hardware are authenticated”. On its own that is an outcome statement with no implementation guidance, which is by design — CSF describes what good looks like and leaves the how to the organisation.

The mappings supply the how. The CIS safeguards under Control 6 (Access Control Management) tell you to require MFA for externally exposed applications, for remote access, and for administrative accounts. ISO 27001:2022 A.5.17 covers authentication information and A.8.5 covers secure authentication. SOC 2 CC6.1 is where an auditor tests logical access controls.

So one project — enforcing MFA across your identity provider — produces evidence for a CSF subcategory, a CIS safeguard, two ISO Annex A controls, and a SOC 2 criterion. Recognising that before you start is the difference between three compliance programmes and one security programme with three reports coming out of it.

Which Framework Do You Actually Need?

FrameworkWhat it isCertifiable?
NIST CSF 2.0A voluntary outcome-based structure for describing and communicating cyber risk. Free to use.No formal certification
CIS Controls v8A prioritised, prescriptive list of safeguards, grouped into Implementation Groups by organisation size and risk.No, but directly actionable
ISO/IEC 27001:2022A management-system standard: you build an ISMS, and Annex A is the control reference.Yes, by an accredited body
SOC 2An attestation report produced by a CPA firm against the Trust Services Criteria, usually for customers.Report, not certificate

A common and sensible pattern for a mid-sized organisation: use CSF as the internal language for risk and board reporting, implement CIS Controls because they are concrete, and produce a SOC 2 Type II or an ISO 27001 certificate when customers demand external assurance. The mapper is the connective tissue between those.

Related Tools

Pair the mapper with the cybersecurity maturity assessment to score where you currently stand, the compliance checklist to track evidence collection, and the risk matrix calculator for the likelihood-and-impact scoring that feeds the Govern and Identify functions. When the result is a funding request, the security business case builder turns it into an ROI narrative.

Frequently Asked Questions

What are the six NIST CSF 2.0 Functions?

Govern, Identify, Protect, Detect, Respond, and Recover. Govern was added in CSF 2.0, published in February 2024; the previous version had the other five.

Why was Govern added?

To make explicit that cybersecurity is an enterprise risk management concern rather than a technical one. It covers organisational context, risk management strategy, roles and responsibilities, policy, oversight, and supply chain risk — the decisions that determine whether the other five Functions are resourced and prioritised sensibly.

How many Categories and Subcategories does CSF 2.0 have?

Twenty-two Categories and 106 Subcategories across the six Functions. This tool includes a curated subset of 48 subcategories across 19 categories, covering all six Functions.

Can I map my CSF 1.1 work straight across?

Not by renaming. Identifiers were renumbered, some subcategories were merged, and content moved between Functions — supply chain risk, for instance, moved from ID.SC in 1.1 to GV.SC under Govern. Treat it as a re-mapping exercise and check each control’s new home.

Are these mappings official?

No. They are a practitioner cross-reference intended to speed up gap analysis. NIST publishes informative references and CIS publishes its own mappings; for anything going in front of an auditor or certification body, confirm against those authoritative sources.

Which ISO 27001 version is used?

ISO/IEC 27001:2022, whose Annex A has 93 controls in four themes numbered A.5 through A.8. If your documentation still uses the 2013 numbering with 114 controls, the references will not line up.

What are Implementation Tiers, and should we aim for Tier 4?

Tiers — Partial, Risk Informed, Repeatable, Adaptive — describe how rigorously and consistently you manage cyber risk. They are context, not a maturity ladder, and NIST is explicit that Tier 4 is not a universal target. Choose the tier that matches your risk, your obligations, and your resources.

Is CSF 2.0 something you can be certified against?

No. There is no CSF certification. Organisations self-assess using Organizational Profiles, and if they need third-party assurance they obtain it through ISO 27001 certification or a SOC 2 attestation — which is exactly why a cross-reference between the three is useful.

Does CSF apply to small organisations?

Yes, and NIST publishes small-business material specifically for it. The Core is scalable because it describes outcomes rather than mandating controls. In practice small teams often get further faster by starting with CIS Implementation Group 1 and mapping that work back into CSF for reporting.

What does the CSV export contain?

One row per included subcategory, with the CSF identifier, name, and description, plus comma-separated columns for the mapped CIS Controls v8 safeguards, ISO 27001:2022 Annex A controls, and SOC 2 Trust Services Criteria — ready to paste into a control matrix.

What Is the NIST Cybersecurity Framework

The NIST Cybersecurity Framework (CSF) is a voluntary framework developed by the National Institute of Standards and Technology that provides organizations with a structured approach to managing cybersecurity risk. Originally published in 2014 and updated to CSF 2.0 in 2024, the framework is used by organizations of all sizes across all industries — though it was originally developed for critical infrastructure sectors.

The framework's strength is its flexibility: it does not prescribe specific technologies or controls. Instead, it organizes cybersecurity activities into six core functions that provide a high-level strategic view of an organization's security lifecycle. This tool maps your existing security controls to the NIST CSF functions and categories, identifying gaps and priorities.

NIST CSF 2.0 Core Functions

FunctionPurposeKey Activities
Govern (GV)Establish and monitor cybersecurity risk management strategyRisk management strategy, roles and responsibilities, policies, oversight
Identify (ID)Understand your cybersecurity risk contextAsset management, risk assessment, supply chain risk management
Protect (PR)Implement safeguards to manage riskAccess control, awareness training, data security, platform security
Detect (DE)Find cybersecurity events when they occurContinuous monitoring, adverse event analysis
Respond (RS)Take action when incidents are detectedIncident management, analysis, mitigation, reporting
Recover (RC)Restore operations after incidentsRecovery planning, execution, communication

Framework Tiers (Maturity Levels)

TierNameDescription
1PartialAd hoc, reactive; limited awareness of cybersecurity risk
2Risk InformedRisk awareness exists but not formalized organization-wide
3RepeatableFormal policies and processes; regularly updated based on risk
4AdaptiveContinuous improvement; real-time risk response; lessons learned integrated

Common Use Cases

  • Security program assessment: Map your current security controls to CSF functions and categories to identify gaps and prioritize improvements
  • Compliance alignment: Use CSF as a common framework to demonstrate alignment with multiple regulatory requirements (HIPAA, PCI DSS, CMMC share many CSF mappings)
  • Board reporting: Communicate security posture to executives and boards using the CSF's clear function-based structure and tier system
  • Vendor evaluation: Assess third-party security maturity by requesting their CSF self-assessment or mapping their controls to CSF categories
  • Incident response maturity: Evaluate your Detect, Respond, and Recover capabilities against CSF requirements and identify improvement areas

Best Practices

  1. Start with Identify and Govern — You cannot protect what you do not know about. Complete asset inventory and governance before investing in advanced Protect and Detect capabilities.
  2. Use CSF Profiles — Create Current and Target profiles to visualize gaps. A Current profile documents existing capabilities; a Target profile defines desired outcomes based on business requirements.
  3. Map to Implementation Tiers realistically — Self-assessing at Tier 4 when you are actually Tier 2 prevents improvement. Honest assessment drives meaningful progress.
  4. Cross-reference with NIST 800-53 — CSF provides strategic guidance. NIST SP 800-53 provides specific controls. Map CSF categories to 800-53 controls for actionable implementation steps.
  5. Review after every significant incident — Post-incident reviews should update your CSF mapping to reflect lessons learned and identify functions that need strengthening.

Frequently Asked Questions

What is the NIST Cybersecurity Framework 2.0?+

NIST CSF 2.0 is a voluntary framework developed by the National Institute of Standards and Technology that provides organizations with guidance for managing cybersecurity risk. It organizes cybersecurity activities into six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Version 2.0, released in 2024, added the Govern function and expanded applicability beyond critical infrastructure.

Which frameworks does this tool map NIST CSF controls to?+

This tool maps NIST CSF 2.0 controls to three major compliance frameworks: CIS Controls v8, ISO 27001:2022, and SOC 2 Trust Services Criteria. This cross-mapping helps organizations understand how implementing NIST CSF controls can simultaneously satisfy requirements from multiple standards, reducing compliance overhead.

What are the six functions in NIST CSF 2.0?+

The six NIST CSF 2.0 functions are: Govern (establishing cybersecurity governance and risk management), Identify (understanding your organization and risk context), Protect (implementing safeguards), Detect (discovering cybersecurity events), Respond (taking action on detected incidents), and Recover (restoring capabilities after incidents). Each function contains categories and subcategories of specific controls.

How do I find specific controls in this tool?+

You can search for controls by typing keywords in the search box, which filters across control IDs, names, and descriptions. You can also filter by NIST CSF function using the dropdown menu, or filter by mapped framework to see only controls that map to CIS, ISO 27001, or SOC 2. Combining search and filters helps you quickly locate relevant controls.

Can I export the control mappings for documentation?+

Yes, you can export all visible controls to a CSV file by clicking the Export to CSV button. The export includes the NIST CSF control ID, function, category, subcategory name, and all corresponding mappings to CIS Controls, ISO 27001 clauses, and SOC 2 criteria. This is useful for compliance documentation and gap analysis.

What is the difference between CIS Controls and NIST CSF?+

CIS Controls v8 provides specific, prioritized security actions organized into 18 control families, while NIST CSF offers a broader risk management framework organized around functions and outcomes. CIS Controls are more prescriptive and technical, whereas NIST CSF is more flexible and outcome-focused. Many organizations use both together, with NIST CSF for strategy and CIS Controls for implementation.

How can this tool help with compliance audits?+

This tool helps you demonstrate how your NIST CSF implementation addresses requirements from other frameworks during audits. By showing the mappings between controls, you can provide auditors with evidence that implementing a NIST CSF control also satisfies corresponding ISO 27001 or SOC 2 requirements. This reduces redundant documentation and testing efforts.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.