NIST CSF anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Primary documents

  • NIST Cybersecurity Framework 2.0 (February 2024). Free from NIST.
  • NIST CSF Quick-Start Guides for specific contexts (SMB, supply chain, governance).
  • NIST CSF Community Profiles for sectors.
  • NIST CSF Informative References mapping CSF to NIST 800-53, ISO 27001, CIS Controls, COBIT, ATT&CK, others.

Predecessors

  • NIST CSF 1.0 (2014)
  • NIST CSF 1.1 (2018)

Operating body

  • NIST (National Institute of Standards and Technology), US Department of Commerce.
  • NIST Cybersecurity and Privacy Resource Center (csrc.nist.gov).
  • NIST SP 800-53 Rev. 5 — controls catalog (informative reference).
  • NIST SP 800-171 Rev. 3 — CUI controls.
  • NIST SP 800-37 Rev. 2 — Risk Management Framework.
  • NIST SP 800-30 Rev. 1 — risk assessment.
  • NIST AI RMF — AI risk.
  • NIST Privacy Framework 1.1 — privacy.

Adjacent frameworks

  • ISO 27001 / 27002:2022 — international sibling.
  • CIS Controls v8 — prescriptive controls.
  • COBIT 2019 — IT governance.
  • SOC 2 — US attestation.
  • HITRUST CSF — healthcare-broadened.

Reference resources

  • nist.gov/cyberframework — CSF hub.
  • csrc.nist.gov — NIST CSRC.
  • nist.gov/csf-resources — community profiles, references.

See also