NIST CSF 2.0 Controls List: The Real Structure (and Why It Isn't a Control List)
Here is the answer that clears up most of the confusion up front: NIST CSF 2.0 is not a controls list. It is a hierarchy of outcomes — 6 Functions, 22 Categories, and 106 Subcategories — that describe what good cybersecurity looks like, not the specific technical controls you deploy. When people search for a "NIST CSF 2.0 controls list PDF download" or a "controls spreadsheet," what they actually want is the Subcategory list (the closest thing CSF has to individual requirements) plus the Informative References that map each one to real control catalogs like NIST SP 800-53 and the CIS Controls. This post gives you the structure, the counts, and how to turn it into something you can act on.
The CSF 2.0 structure: 6 Functions, 22 Categories, 106 Subcategories
NIST released CSF 2.0 in February 2024, and the headline change was adding Govern (GV) as a sixth Function alongside the original five — Identify, Protect, Detect, Respond and Recover. That was the first structural change since the 2014 original, and it matters: Govern pulls risk strategy, roles, policy, and supply chain oversight out of "Identify" and gives them their own top-level home. If you are a CISO, Govern is now the Function where board reporting and risk appetite live.
The six Functions break down like this:
- Govern (GV) — Organizational Context, Risk Management Strategy, Roles/Responsibilities/Authorities, Policy, Oversight, Cybersecurity Supply Chain Risk Management.
- Identify (ID) — Asset Management, Risk Assessment, Improvement.
- Protect (PR) — Identity Management & Access Control, Awareness & Training, Data Security, Platform Security, Technology Infrastructure Resilience.
- Detect (DE) — Continuous Monitoring, Adverse Event Analysis.
- Respond (RS) — Incident Management, Incident Analysis, Incident Response Reporting & Communication, Incident Mitigation.
- Recover (RC) — Incident Recovery Plan Execution, Incident Recovery Communication.
Those 22 Categories then decompose into 106 Subcategories — outcome statements written in plain language, each with an identifier like PR.AA-01 ("Identities and credentials for authorized users, services, and hardware are managed by the organization"). The Subcategory list is the artifact people mean when they ask for the CSF 2.0 "controls" in a PDF or spreadsheet.
How many NIST controls are there, really?
This is where searches collide. There are two very different "NIST" things:
- NIST CSF 2.0 — 106 Subcategories (outcomes). Voluntary, framework-level, sector-agnostic.
- NIST SP 800-53 Rev. 5 — roughly 1,000+ individual controls organized into 20 control families (AC Access Control, AU Audit & Accountability, CM Configuration Management, IR Incident Response, and so on). These are the prescriptive, testable controls federal systems must implement, and they're the "20 control families" people search for.
The relationship is the useful part: every CSF Subcategory carries Informative References mapping it to specific 800-53 controls. So PR.AA-01 maps to 800-53 controls in the IA (Identification and Authentication) and AC (Access Control) families. That mapping is how you go from a strategic outcome to the concrete control an auditor will actually check. Don't treat CSF and 800-53 as competitors — CSF is the map, 800-53 is the terrain.
The other lists people confuse with CSF: CIS Controls and "cyber essentials"
Two more items show up in the same searches, and they're worth distinguishing so you don't reinvent them:
- The "SANS Top 20" is now the CIS Controls v8 — 18 controls (it was 20 under the old SANS/CIS Critical Security Controls branding). These are ranked, prioritized technical safeguards: Inventory of Enterprise Assets, Inventory of Software Assets, Data Protection, Secure Configuration, Account Management, Access Control Management, Continuous Vulnerability Management, Audit Log Management, and so on. If someone hands you a CSF Subcategory and asks "what do we actually deploy?", CIS Controls are frequently the crisp answer.
- The "5 cyber essential controls" refers to the UK Cyber Essentials scheme's five technical controls: firewalls, secure configuration, user access control, malware protection, and security update management (patching). These are a floor, not a framework — the minimum baseline for basic hygiene, useful for small organizations that find full CSF or 800-53 overwhelming.
Practical stack for most teams: use CSF 2.0 to organize governance and communicate risk to leadership, CIS Controls v8 to prioritize what to build first, and 800-53 when you need audit-grade control language.
Turning the Subcategory list into a working spreadsheet
The reason people want a "CSF 2.0 controls spreadsheet" is to run a gap assessment. Here's a column layout that actually works instead of a static PDF:
- Subcategory ID (e.g., GV.RM-01)
- Outcome statement (copied verbatim from the CSF Core)
- Current Tier — 1 Partial, 2 Risk Informed, 3 Repeatable, 4 Adaptive
- Target Tier — where you need to be given your risk appetite
- Evidence — the policy, ticket, or config that proves it
- Owner and Gap / next action
The Tier columns are what make CSF actionable. You don't have to be Tier 4 everywhere — that's expensive and rarely justified. A payments company might target Tier 4 on Data Security (PR.DS) and Continuous Monitoring (DE.CM) but accept Tier 2 on some Recover Subcategories. Documenting that deliberate difference is exactly the kind of risk-informed decision Govern was created to capture.
A worked prioritization example
Say your assessment shows these three gaps: ID.AM-01 (hardware inventory) at Tier 1, PR.AA-05 (access permissions/least privilege) at Tier 2, and RC.RP-01 (recovery plan execution) at Tier 1. Which do you fix first?
Sequence by dependency, not by score. You can't enforce least privilege (PR.AA-05) reliably without knowing what assets and identities exist — so ID.AM-01 comes first because half a dozen Protect and Detect Subcategories depend on a trustworthy inventory. This is also why CIS Control 1 (asset inventory) sits at the top of that list. Recovery plan execution matters, but a documented, untested plan (raising RC.RP-01 to Tier 2) is a fast, cheap win you can do in parallel. The point: the CSF Subcategory list becomes a prioritization engine only when you overlay dependencies and business impact — not just count red cells.
Where to get the authoritative source
Skip third-party "CSF 2.0 PDF" reposts of unknown vintage. NIST publishes the CSF 2.0 Core, the full Subcategory list, and machine-readable exports (including the Informative Reference mappings to 800-53 and CIS) directly on its site
Ready to practise the decisions these articles describe?
Run a free War Room →