Browse NIST CSF 2.0 by function and map every subcategory to CIS Controls v8, ISO 27001:2022 and SOC 2 criteria. Search both ways, export CSV free.
This mapper turns the NIST Cybersecurity Framework 2.0 into something you can actually work from. Browse the Core by Function and Category, search across control identifiers, names, and descriptions, and see for each subcategory which CIS Controls v8 safeguards, which ISO/IEC 27001:2022 Annex A controls, and which SOC 2 Trust Services Criteria address the same outcome. The mapping also works in reverse: pick a CIS safeguard, an ISO control, or a SOC 2 criterion and see every CSF subcategory it supports. Export the whole cross-reference as CSV in one click.
It exists for the recurring problem of doing the same control work three times. An organisation adopts CSF for its risk conversations, gets audited against SOC 2, and is asked by a customer for ISO 27001 certification. The underlying controls are largely the same controls. This tool makes the overlap explicit so one piece of evidence can serve several frameworks.
CSF 2.0 was published in February 2024 and made the framework’s first structural change since 2014: it added a sixth Function, Govern, alongside the original five. The full Core is six Functions containing 22 Categories and 106 Subcategories.
| Function | ID | Outcome it describes |
|---|---|---|
| Govern | GV | The cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored. |
| Identify | ID | The organisation’s current cybersecurity risks are understood — assets, suppliers, and risk assessment. |
| Protect | PR | Safeguards to manage those risks are used — identity, access, data security, platform security, resilience. |
| Detect | DE | Possible attacks and compromises are found and analysed. |
| Respond | RS | Actions regarding a detected incident are taken — management, analysis, communication, mitigation. |
| Recover | RC | Assets and operations affected by an incident are restored, and recovery is communicated. |
Govern is not a sixth silo bolted onto the side. It is deliberately placed first and cuts across the other five: organisational context (GV.OC), risk management strategy (GV.RM), roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management (GV.SC). Supply chain risk in particular was promoted out of Identify, where it lived as ID.SC in version 1.1, and given its own Category under Govern — a reasonable reading of what changed in the threat landscape between 2018 and 2024.
Identifiers follow a consistent pattern. PR.AA-01 reads as Function PR (Protect), Category AA (Identity Management, Authentication, and Access Control), Subcategory 01. If you are migrating from CSF 1.1, expect the identifiers to have moved: numbering was reset and several subcategories were merged or relocated, so a 1.1 crosswalk is not a rename exercise.
Two other pieces of CSF sit outside the Core and are worth knowing even though they are not in this tool. Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorously an organisation manages cyber risk — they are not maturity levels and Tier 4 is not automatically the goal. Organizational Profiles capture a Current Profile and a Target Profile, and the gap between them is the improvement plan.
The mapper carries a curated subset of the Core: 48 subcategories across 19 categories, spanning all six Functions, chosen as the ones most commonly cited in audits and customer security questionnaires. Each carries its official identifier, its name, a plain description of the outcome, and its mappings.
CIS 5.3 or CIS 12.1. CIS is the prescriptive layer: it tells you what to implement, which is what CSF deliberately does not do.A.5 to A.8 numbering (organisational, people, physical, technological). Note that this is the 2022 scheme, not the 114 controls of the 2013 version.CC common criteria series plus the additional categories, which is what a service auditor tests against.The subset is a working cross-reference, not a substitute for the published framework. For a formal gap assessment or a certification scope, work from the NIST Core and the official ISO and AICPA documents; use this to orient yourself and to find the overlap quickly.
A.8.16 or CC7.2 finds the CSF subcategories that map to it.Take PR.AA-03, “users, services, and hardware are authenticated”. On its own that is an outcome statement with no implementation guidance, which is by design — CSF describes what good looks like and leaves the how to the organisation.
The mappings supply the how. The CIS safeguards under Control 6 (Access Control Management) tell you to require MFA for externally exposed applications, for remote access, and for administrative accounts. ISO 27001:2022 A.5.17 covers authentication information and A.8.5 covers secure authentication. SOC 2 CC6.1 is where an auditor tests logical access controls.
So one project — enforcing MFA across your identity provider — produces evidence for a CSF subcategory, a CIS safeguard, two ISO Annex A controls, and a SOC 2 criterion. Recognising that before you start is the difference between three compliance programmes and one security programme with three reports coming out of it.
| Framework | What it is | Certifiable? |
|---|---|---|
| NIST CSF 2.0 | A voluntary outcome-based structure for describing and communicating cyber risk. Free to use. | No formal certification |
| CIS Controls v8 | A prioritised, prescriptive list of safeguards, grouped into Implementation Groups by organisation size and risk. | No, but directly actionable |
| ISO/IEC 27001:2022 | A management-system standard: you build an ISMS, and Annex A is the control reference. | Yes, by an accredited body |
| SOC 2 | An attestation report produced by a CPA firm against the Trust Services Criteria, usually for customers. | Report, not certificate |
A common and sensible pattern for a mid-sized organisation: use CSF as the internal language for risk and board reporting, implement CIS Controls because they are concrete, and produce a SOC 2 Type II or an ISO 27001 certificate when customers demand external assurance. The mapper is the connective tissue between those.
Pair the mapper with the cybersecurity maturity assessment to score where you currently stand, the compliance checklist to track evidence collection, and the risk matrix calculator for the likelihood-and-impact scoring that feeds the Govern and Identify functions. When the result is a funding request, the security business case builder turns it into an ROI narrative.
Govern, Identify, Protect, Detect, Respond, and Recover. Govern was added in CSF 2.0, published in February 2024; the previous version had the other five.
To make explicit that cybersecurity is an enterprise risk management concern rather than a technical one. It covers organisational context, risk management strategy, roles and responsibilities, policy, oversight, and supply chain risk — the decisions that determine whether the other five Functions are resourced and prioritised sensibly.
Twenty-two Categories and 106 Subcategories across the six Functions. This tool includes a curated subset of 48 subcategories across 19 categories, covering all six Functions.
Not by renaming. Identifiers were renumbered, some subcategories were merged, and content moved between Functions — supply chain risk, for instance, moved from ID.SC in 1.1 to GV.SC under Govern. Treat it as a re-mapping exercise and check each control’s new home.
No. They are a practitioner cross-reference intended to speed up gap analysis. NIST publishes informative references and CIS publishes its own mappings; for anything going in front of an auditor or certification body, confirm against those authoritative sources.
ISO/IEC 27001:2022, whose Annex A has 93 controls in four themes numbered A.5 through A.8. If your documentation still uses the 2013 numbering with 114 controls, the references will not line up.
Tiers — Partial, Risk Informed, Repeatable, Adaptive — describe how rigorously and consistently you manage cyber risk. They are context, not a maturity ladder, and NIST is explicit that Tier 4 is not a universal target. Choose the tier that matches your risk, your obligations, and your resources.
No. There is no CSF certification. Organisations self-assess using Organizational Profiles, and if they need third-party assurance they obtain it through ISO 27001 certification or a SOC 2 attestation — which is exactly why a cross-reference between the three is useful.
Yes, and NIST publishes small-business material specifically for it. The Core is scalable because it describes outcomes rather than mandating controls. In practice small teams often get further faster by starting with CIS Implementation Group 1 and mapping that work back into CSF for reporting.
One row per included subcategory, with the CSF identifier, name, and description, plus comma-separated columns for the mapped CIS Controls v8 safeguards, ISO 27001:2022 Annex A controls, and SOC 2 Trust Services Criteria — ready to paste into a control matrix.
The NIST Cybersecurity Framework (CSF) is a voluntary framework developed by the National Institute of Standards and Technology that provides organizations with a structured approach to managing cybersecurity risk. Originally published in 2014 and updated to CSF 2.0 in 2024, the framework is used by organizations of all sizes across all industries — though it was originally developed for critical infrastructure sectors.
The framework's strength is its flexibility: it does not prescribe specific technologies or controls. Instead, it organizes cybersecurity activities into six core functions that provide a high-level strategic view of an organization's security lifecycle. This tool maps your existing security controls to the NIST CSF functions and categories, identifying gaps and priorities.
| Function | Purpose | Key Activities |
|---|---|---|
| Govern (GV) | Establish and monitor cybersecurity risk management strategy | Risk management strategy, roles and responsibilities, policies, oversight |
| Identify (ID) | Understand your cybersecurity risk context | Asset management, risk assessment, supply chain risk management |
| Protect (PR) | Implement safeguards to manage risk | Access control, awareness training, data security, platform security |
| Detect (DE) | Find cybersecurity events when they occur | Continuous monitoring, adverse event analysis |
| Respond (RS) | Take action when incidents are detected | Incident management, analysis, mitigation, reporting |
| Recover (RC) | Restore operations after incidents | Recovery planning, execution, communication |
| Tier | Name | Description |
|---|---|---|
| 1 | Partial | Ad hoc, reactive; limited awareness of cybersecurity risk |
| 2 | Risk Informed | Risk awareness exists but not formalized organization-wide |
| 3 | Repeatable | Formal policies and processes; regularly updated based on risk |
| 4 | Adaptive | Continuous improvement; real-time risk response; lessons learned integrated |
NIST CSF 2.0 is a voluntary framework developed by the National Institute of Standards and Technology that provides organizations with guidance for managing cybersecurity risk. It organizes cybersecurity activities into six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Version 2.0, released in 2024, added the Govern function and expanded applicability beyond critical infrastructure.
This tool maps NIST CSF 2.0 controls to three major compliance frameworks: CIS Controls v8, ISO 27001:2022, and SOC 2 Trust Services Criteria. This cross-mapping helps organizations understand how implementing NIST CSF controls can simultaneously satisfy requirements from multiple standards, reducing compliance overhead.
The six NIST CSF 2.0 functions are: Govern (establishing cybersecurity governance and risk management), Identify (understanding your organization and risk context), Protect (implementing safeguards), Detect (discovering cybersecurity events), Respond (taking action on detected incidents), and Recover (restoring capabilities after incidents). Each function contains categories and subcategories of specific controls.
You can search for controls by typing keywords in the search box, which filters across control IDs, names, and descriptions. You can also filter by NIST CSF function using the dropdown menu, or filter by mapped framework to see only controls that map to CIS, ISO 27001, or SOC 2. Combining search and filters helps you quickly locate relevant controls.
Yes, you can export all visible controls to a CSV file by clicking the Export to CSV button. The export includes the NIST CSF control ID, function, category, subcategory name, and all corresponding mappings to CIS Controls, ISO 27001 clauses, and SOC 2 criteria. This is useful for compliance documentation and gap analysis.
CIS Controls v8 provides specific, prioritized security actions organized into 18 control families, while NIST CSF offers a broader risk management framework organized around functions and outcomes. CIS Controls are more prescriptive and technical, whereas NIST CSF is more flexible and outcome-focused. Many organizations use both together, with NIST CSF for strategy and CIS Controls for implementation.
This tool helps you demonstrate how your NIST CSF implementation addresses requirements from other frameworks during audits. By showing the mappings between controls, you can provide auditors with evidence that implementing a NIST CSF control also satisfies corresponding ISO 27001 or SOC 2 requirements. This reduces redundant documentation and testing efforts.