What this Preview includes
- Preview Function, Category, and Subcategory catalog
- Preliminary shared-control mappings
- Likely evidence examples
- Current and Target Profile planning concepts
- Open questions for product feedback
NIST CSF 2.0 PLANNING PREVIEW
PreviewReview preliminary Function and Subcategory mappings, shared controls, likely evidence, and open questions. Active NIST CSF programs are not yet available.
Shared work
Preview mappings show possible relationships to controls already supporting SOC 2 or ISO 27001. A relationship is a planning aid, not proof that a NIST CSF outcome has been achieved.
Governance policies may support outcomes for organizational context, strategy, roles, oversight, and supply chain risk.
Asset inventories and risk records may support outcomes for understanding systems, threats, vulnerabilities, and improvement priorities.
Identity, awareness, data-security, and resilience controls may support outcomes intended to reduce cybersecurity risk.
Monitoring observations may support outcomes for continuous monitoring and adverse-event analysis.
Incident procedures may support outcomes for management, analysis, reporting, communication, and mitigation.
Recovery plans and test records may support outcomes for restoration and recovery communication.
NIST-specific planning
Current and Target Profiles organize cybersecurity outcomes around the organization's risk context. The Preview helps structure that planning without making an implementation or assessment claim.
Document mission, stakeholders, requirements, risk appetite, and the systems that matter to the business.
Identify the Functions, Categories, and Subcategories that fit the organization and its risk context.
Record which applicable outcomes appear to be in place, incomplete, or still unverified.
Choose the outcome state the organization wants to reach and the priorities that shape it.
Compare Current and Target Profiles using risk, business impact, and dependencies.
Connect priority gaps to an owner, related control, improvement action, and expected review.
The NIST Cybersecurity Framework is a risk-based framework for describing and improving cybersecurity outcomes. Version 2.0 organizes those outcomes into six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. It can be used by organizations of any size or sector without prescribing one technology stack.
The Core contains Categories and Subcategories that describe outcomes a security program should achieve. Organizations can use Profiles to describe their current and target posture, then prioritize work based on business context and risk. The framework supports communication and improvement, but it is not an audit report or certification.
Implementation Tiers characterize the rigor of cybersecurity risk governance and management practices. Informative References connect CSF outcomes to other standards and guidance. Neither concept is a certification level or a substitute for an organization-specific Profile.
The catalog has 106 active Subcategories represented in preliminary Preview mappings. Shared-control relationships can help teams reuse work from SOC 2 and ISO 27001 while preserving the distinct language and risk-based purpose of NIST CSF.
106 active Subcategories are represented in preliminary Preview mappings across the six Functions.
Context, strategy, policy, oversight, roles, and supply chain risk
Assets, risk assessment, and improvement
Access, awareness, data security, resilience, and platform security
Continuous monitoring and adverse-event analysis
Incident management, analysis, reporting, and mitigation
Recovery execution, restoration, and communication
Quick answers about the product, frameworks, and getting started.
No. NIST CSF is a voluntary risk-based cybersecurity framework. Organizations use it to understand, communicate, and improve cybersecurity outcomes. vCISO.ai does not issue a NIST certification or independent assessment.
Version 2.0 adds Govern as a top-level Function and broadens the framework's language for organizations of every size and sector. The Core is organized across Govern, Identify, Protect, Detect, Respond, and Recover.
Often, yes. Many implemented controls and reviewed evidence records can support outcomes in more than one framework. The mappings are planning aids, and each framework's requirements and review purpose remain distinct.
The requirement view and mappings are currently Preview. Active readiness programs, commercial availability, and assurance should not be inferred from the Preview workspace.
Did not find what you were looking for? Talk to us.
Preview access
Tell us what your team needs. Active readiness remains limited to SOC 2 and ISO 27001 today.