NIST CSF 2.0 Multi-Framework Crosswalk

Map all 106 NIST CSF 2.0 Subcategories to controls in NIST 800-53, 800-171, ISO 27001, CIS v8, and SCF. See what your existing security program already covers before doing any new work.

What’s Inside

  • 106 Subcategories Across 6 Functions and 22 Categories: Every CSF 2.0 Subcategory listed with its ID, parent Category, parent Function, and a plain-language description of the security outcome it addresses — Govern (31), Identify (21), Protect (22), Detect (11), Respond (13), and Recover (8).
  • Five-Framework Control Mappings Per Subcategory: Each row maps to specific control IDs in NIST SP 800-53 Rev 5, NIST SP 800-171 Rev 3, ISO 27001:2022, CIS Controls v8, and the Secure Controls Framework (SCF). Mappings are at the individual control level (e.g., AC-6, A.8.3, CIS 6.1) — not framework families or general references.
  • Coverage Summary + Filterable Views: A pre-built Coverage Summary tab shows how many subcategories in each Function have mappings in your framework at a glance. The full crosswalk is filterable by Function and Category to focus on specific areas without scrolling through all 106 rows.

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

The InfoSec GRC Brief
Join 1,500+ security and compliance professionals who get monthly regulatory updates, GRC strategies, and threat intel with actionable next steps.
Let’s Chat
See the GRC Assessment Platform in action
Book a Demo