GRCCopilot
Sign In
National Institute of Standards and Technology (NIST), U.S. Department of Commerce

NIST Cybersecurity Framework (NIST CSF)

The U.S. voluntary cybersecurity framework adopted globally by critical infrastructure and enterprise organisations

Start Assessment Create Free Account
7
Controls
15
Questions
Active
Status

About this Framework

The NIST Cybersecurity Framework (CSF) provides policy guidance for organisations to assess and improve their ability to prevent, detect, and respond to cyber attacks. CSF 2.0 (2024) expanded scope to all organisations and introduced a sixth function — Govern — alongside Identify, Protect, Detect, Respond and Recover. Technology-neutral and complementary to ISO 27001, PCI DSS and sector-specific regulations worldwide.

Key Control Domains

Govern (GV)
Identify (ID)
Protect (PR)
Detect (DE)
Respond (RS)
Recover (RC)

Who Needs This?

  • Critical infrastructure operators
  • U.S. federal contractors and agencies
  • Healthcare and financial services organisations
  • Any organisation seeking a flexible cyber risk management framework

Compliance Benefits

  • Flexible, risk-based cybersecurity approach
  • Widely accepted by U.S. and international regulators
  • Enables board-level cyber risk communication
  • CSF 2.0 aligned with ISO 27001 and NIST 800-53

Official Reference

NIST Cybersecurity Framework
https://www.nist.gov/cyberframework

Assessment Details

Issuer / AuthorityNational Institute of Standards and Technology (NIST), U.S. Department of Commerce
FrameworkNIST Cybersecurity Framework (NIST CSF)
Controls7
Questions15
StatusActive
Assessment Start08 May 2026

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/nist-cybersecurity-framework-nist-csf

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.