Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

NIST Privacy Framework Toolkit – 145 Privacy Templates

The NIST Privacy Framework Toolkit delivers 145 ready-to-use Microsoft Office templates for building a privacy program — 108 Word documents and 37 Excel workbooks covering every one of the 102 Subcategories in NIST Privacy Framework 1.1. Nine sections follow the Framework’s own five Functions, plus Current and Target Profile workbooks, an Implementation Tier assessment, five crosswalks and a 102-point audit checklist. Written against the Initial Public Draft (CSWP 40 ipd, 14 April 2025) — which we say plainly, because PF 1.1 is not final and nobody can be certified against it.

$99.00

✓ In stock — instant download after checkout

Instant downloadYour files are available immediately after checkout
Fully editableNative Microsoft Word & Excel templates
30-day money-back guaranteeNot satisfied? Request a refund within 30 days
🔒Secure checkoutEncrypted payment powered by Stripe

Description

About the NIST Privacy Framework Toolkit

The NIST Privacy Framework is NIST’s voluntary model for managing privacy risk, it is free to download, and it is deliberately built to sit alongside the Cybersecurity Framework rather than inside any single privacy law. What it does not come with is the documentation a privacy program has to produce against it.

The NIST Privacy Framework Toolkit is 145 editable templates written against NIST Privacy Framework 1.1, and it covers all 102 of its active Subcategories.

First, the thing our competitors will not tell you

Privacy Framework 1.1 is an Initial Public Draft. It was published on 14 April 2025 as NIST CSWP 40 ipd. The comment period closed on 13 June 2025. NIST has not announced a publication date for the final, and PF 1.0 — published 16 January 2020 — remains the only final version.

That has three consequences, and the NIST Privacy Framework Toolkit is built around them rather than hiding them:

Reality What this toolkit does
Nobody can be “compliant with” or “certified against” a draft Every document says aligned to PF 1.1 IPD. We never use the word compliant about the Framework itself
The Subcategory identifiers may change — the draft’s own Note to Reviewers asks reviewers whether NIST should renumber them in the Final Draft All 102 identifiers live in one data module, so a renumber is one edit and a rebuild, not a rewrite of 145 files
An organisation on PF 1.0 has evidence mapped to identifiers that no longer exist A PF 1.0 to PF 1.1 Transition Guide maps all 34 relocated identifiers and the 2 withdrawn ones

If you want a pack that promises certification, this is not it — and neither is anything else, because no such certification exists for the Privacy Framework in any version.

Why the count is 102 and not 138

If you open the source PDF and text-search for Subcategory identifiers you will count 138, and conclude this toolkit is missing 36 of them. It is not. That figure breaks down as:

Count
Active Subcategories in PF 1.1 IPD 102
Retired PF 1.0 identifiers, carried in Appendix A only as “Moved to” pointers 34
Withdrawn — ID.RA-P2 (artificial intelligence systems) and CM.AW-P8 2
Total identifiers appearing in the document 138

The NIST Privacy Framework Toolkit covers the 102 that exist, lists the 34 that moved, and names the 2 that were withdrawn so you do not cover them by accident. For comparison, PF 1.0 had 5 Functions, 18 Categories and 100 Subcategories.

The Framework text ships inside the documents — lawfully

Every one of our ISO toolkits has to paraphrase, because ISO requirement wording is copyright. This one does not. NIST Technical Series publications are works of the United States Government: NIST’s own statement is that works authored by NIST employees are not subject to copyright protection within the United States, and NIST grants a royalty-free right to reprint them in derivative works, subject to attribution.

So each of the 108 Word documents opens with a Framework outcomes addressed table carrying the Subcategory identifier, its Category, and the outcome text in full. You can hand any single document to an assessor and they can see exactly which outcomes it is evidence for, without holding the Framework open beside it.

The attribution NIST asks for ships in the pack, in every document and in a NIST-ATTRIBUTION.txt file. The one carve-out: the ISO/IEC 27701 crosswalk carries clause numbers and short names only, because that text is not NIST’s to license.

The idea the whole Framework rests on, and the reason an ISMS is not enough

This is the argument for buying a privacy toolkit at all when you already have information security covered.

A privacy problem can arise from data processing that is authorised, accurate and perfectly secure. No attacker. No vulnerability. No breach. No failed control. There are three regions:

Region What it is Who finds it
Cybersecurity only Compromise of systems holding no data about individuals Your security programme
Overlap Unauthorised access to data about individuals — the classic breach Both
Privacy only Over-retention, undisclosed inference, purpose drift, an automated decision with no route to challenge, a default nobody would choose Nothing but a privacy programme

A security review of anything in the third region returns “no finding”, because the access was authorised and the controls operated correctly. That is why the NIST Privacy Framework Toolkit ships a Problematic Data Action Identification Procedure as a separate step before any risk is scored, built on one question: if this works perfectly, who could still be worse off?

The pack carries this through into places most toolkits do not:

  • The incident response plan triggers on privacy events with no security failure — data

processed for an unauthorised purpose, an inference that should have been prohibited, a correction that never propagated. A security incident plan will not activate for any of them.

  • The risk method requires you to consider processing less before proposing any control.

Six minimisation questions must be answered and recorded before a protective measure is accepted, because removing the data survives a misconfiguration and a control does not.

  • The measurement set splits incidents by whether the processing was authorised, which is

the single measure that makes the third region visible. Reported as one number, it is not.

Profiles and Implementation Tiers, which is how the Framework is actually used

The Core is one of three components. A pack that ships only a control list is not a Privacy Framework toolkit.

  • Current Profile Workbook — all 102 Subcategories pre-loaded, with status, evidence,

evidence location and an audit-tested column.

  • Target Profile Workbook — because a Target Profile is chosen, not assumed to be all 102.

Deciding an outcome is not a target is a legitimate documented risk decision, and the workbook makes you record the rationale.

  • Profile Gap Analysis and Action Plan — the difference between the two, prioritised by the

risk left open rather than by ease of closure.

  • Implementation Tier Self-Assessment — Partial, Risk Informed, Repeatable and Adaptive,

assessed per dimension. The guide is explicit that Tiers are not maturity levels and Tier 4 is not the goal. Treating the Tiers as a ladder to climb is a misreading the guide addresses directly, because it produces spend disconnected from risk.

What changed from PF 1.0, and why it matters if you already have one

PF 1.1 realigns the Privacy Framework with NIST Cybersecurity Framework 2.0. The counts barely move — 100 Subcategories to 102 — which is misleading, because the structure was re-cut:

  • GOVERN-P grew from 4 Categories to 7. New: Oversight (GV.OV-P), Roles, Responsibilities and

Authorities (GV.RR-P), and Data Processing Ecosystem Risk Management (GV.DE-P), which moved wholesale out of IDENTIFY-P.

  • PROTECT-P was re-cut onto CSF 2.0 category names. PR.AC-P, PR.MA-P and PR.PT-P are gone;

PR.AA-P, PR.PS-P and PR.IR-P replace them.

  • Four Categories no longer exist, and 34 Subcategory identifiers moved.

Map your old evidence across by identifier alone and a substantial part of it lands on the wrong outcome. The Transition Guide handles this, and it is explicit that you re-run the Current Profile rather than converting the old one arithmetically — the Categories were re-cut, so the honest answer may have changed.

CT.DM-P11, the Subcategory that speaks to automated decisions

New in PF 1.1, with no counterpart in PF 1.0: stakeholder privacy preferences must be included in algorithmic design objectives, and outputs evaluated against those preferences.

The NIST Privacy Framework Toolkit ships a procedure for it that tests for proxy inference — excluding an attribute from a model’s inputs does not stop the model inferring it from correlated features — alongside an Inference Limitation Standard covering the inference surface a system could reach, not only what it currently draws.

Worth knowing: ID.RA-P2, which related to artificial intelligence systems, is withdrawn in this draft. That does not put AI outside the Framework. An AI system performing data actions is assessed like any other, and CT.DM-P11 is where its algorithmic behaviour is addressed.

NIST Privacy Framework Toolkit structure

# Section Documents
00 Programme Foundation 7
01 IDENTIFY-P 22
02 GOVERN-P 39
03 CONTROL-P 21
04 COMMUNICATE-P 11
05 PROTECT-P 23
06 Profiles and Implementation Tiers 8
07 Crosswalks 6
08 Assurance and Audit 8

The NIST Privacy Framework Toolkit is 108 Word documents and 37 Excel workbooks. Sections 01 to 05 are the Framework’s five Functions, in NIST’s own order, so the pack is laid out the way an assessor reads it.

Eleven workbooks ship already filled in

They are not blank templates. Eleven of the 37 workbooks ship pre-loaded with all 102 Subcategories — Function, Category, identifier and the outcome text in full:

Workbook What it does
Privacy Framework Core Reference The whole Core, plus the 34 moved and 2 withdrawn identifiers
Current Profile Status and evidence per outcome, with an audit-tested column
Target Profile Is-a-target, priority, rationale, and the risk or obligation driving it
Profile Gap Analysis The gap, the risk left open, the action, the evidence of closure
Privacy Framework Audit Checklist Audit question, method, evidence examined and limitation per outcome
Privacy Evidence Register Every outcome pointed at the artefact that evidences it
Crosswalk to NIST CSF 2.0 The realignment PF 1.1 was written to achieve
Crosswalk to NIST SP 800-53 Rev 5 To the privacy control baseline
Crosswalk to ISO/IEC 27701 Clause numbers and short names
Crosswalk to GDPR Article-level
Crosswalk to US state privacy law By statute and by recurring obligation theme

All eleven are generated from one Subcategory set, so they cannot drift apart from each other or from the documents. Every crosswalk carries a relationship strength and a direction, and a Crosswalk Guide that states plainly that a mapping is not a claim of equivalence and must never be used as coverage evidence.

Every document names the outcomes it answers

All 102 Subcategories are covered, and the build fails if any one of them is left without a document — a check we run, not a claim we make. The same check rejects any document that claims a withdrawn or retired identifier.

List of Documentation Toolkit:

00 — Programme Foundation (7 documents)

  1. Toolkit Guide and Document Index.docx
  2. Privacy Framework Implementation Roadmap.docx
  3. Privacy Framework Scope and Boundary Statement.docx
  4. Privacy Programme Charter.docx
  5. Privacy Terms and Definitions Glossary.docx
  6. Privacy Framework Core Reference.xlsx
  7. PF 1.0 to PF 1.1 Transition Guide.docx

01 — IDENTIFY-P (22 documents)

  1. Data Processing Inventory Policy.docx
  2. Systems Products and Services Inventory.xlsx
  3. Data Owner and Operator Register.xlsx
  4. Categories of Individuals Register.xlsx
  5. Data Actions Inventory.xlsx
  6. Processing Purposes Register.xlsx
  7. Data Elements Catalogue.xlsx
  8. Data Processing Environment Register.xlsx
  9. Data Mapping Procedure.docx
  10. Data Map Template.xlsx
  11. Data Processing Ecosystem Role Statement.docx
  12. Mission and Privacy Objectives Statement.docx
  13. Priority Systems and Key Requirements Register.xlsx
  14. Ecosystem Parties Identification and Prioritisation Procedure.docx
  15. Stakeholder Expectations Analysis.docx
  16. Organisational Dependencies Register.xlsx
  17. Contextual Factors Analysis Procedure.docx
  18. Problematic Data Action Identification Procedure.docx
  19. Privacy Risk Assessment Methodology.docx
  20. Privacy Risk Register.xlsx
  21. Privacy Risk Response Plan.docx
  22. Ecosystem Party Privacy Risk Assessment Procedure.docx

02 — GOVERN-P (39 documents)

  1. Organisational Privacy Policy.docx
  2. Data Use and Retention Conditions Standard.docx
  3. Privacy by Design Procedure.docx
  4. Privacy in the System Development Life Cycle Standard.docx
  5. Privacy Legal and Regulatory Requirements Procedure.docx
  6. Legal and Regulatory Requirements Register.xlsx
  7. Privacy in Enterprise Risk Management Statement.docx
  8. Privacy in Human Resources Procedure.docx
  9. Privacy Risk Management Strategy.docx
  10. Privacy Risk Appetite and Tolerance Statement.docx
  11. Privacy Risk Response Options Standard.docx
  12. Privacy Risk Communication Plan.docx
  13. Privacy Risk Calculation and Prioritisation Method.docx
  14. Privacy Strategic Opportunity Register.xlsx
  15. Privacy Programme Management Review Procedure.docx
  16. Privacy Strategy Review Record.docx
  17. Privacy Performance Measurement Framework.docx
  18. Privacy Metrics and KPI Workbook.xlsx
  19. Privacy Leadership Accountability Statement.docx
  20. Privacy Roles and Responsibilities Matrix.xlsx
  21. External Stakeholder Privacy Coordination Procedure.docx
  22. Privacy Resource Allocation Plan.docx
  23. Data Processing Ecosystem Risk Management Strategy.docx
  24. Privacy Contract Clauses and Data Processing Agreement.docx
  25. Interoperability and Multi-Party Framework Procedure.docx
  26. Ecosystem Party Assessment and Audit Procedure.docx
  27. Ecosystem Party Assessment Workbook.xlsx
  28. Ecosystem Risk Integration Procedure.docx
  29. Privacy Awareness and Training Programme.docx
  30. Specialised Privacy Role Training Plan.docx
  31. Privacy Training Record Log.xlsx
  32. Privacy Risk Monitoring and Re-evaluation Procedure.docx
  33. Privacy Policy and Training Review Procedure.docx
  34. Privacy Compliance Assessment Procedure.docx
  35. Privacy Risk Progress Reporting Procedure.docx
  36. Problematic Data Action Disclosure Procedure.docx
  37. Privacy Lessons Learned Procedure.docx
  38. Individual Complaints and Enquiries Procedure.docx
  39. Complaints and Enquiries Log.xlsx

03 — CONTROL-P (21 documents)

  1. Data Processing Authorisation and Consent Policy.docx
  2. Consent and Authorisation Record Log.xlsx
  3. Data Review Transfer Alteration and Deletion Procedure.docx
  4. Individual Data Preferences and Requests Procedure.docx
  5. Data Life Cycle and SDLC Alignment Standard.docx
  6. Data Access for Review Procedure.docx
  7. Data Transmission and Disclosure Procedure.docx
  8. Data Alteration and Correction Procedure.docx
  9. Data Deletion Procedure.docx
  10. Data Destruction Policy and Certificate.docx
  11. Standardised Data Transmission Format Standard.docx
  12. Processing Permission Transmission Standard.docx
  13. Privacy Logging and Data Minimisation Standard.docx
  14. Technical Privacy Control Test Plan.docx
  15. Technical Control Test Results Workbook.xlsx
  16. Algorithmic Privacy Preference Evaluation Procedure.docx
  17. Disassociated Processing Standard.docx
  18. De-identification and Tokenisation Procedure.docx
  19. Inference Limitation Standard.docx
  20. Selective Collection and Disclosure Configuration Standard.docx
  21. Attribute Substitution Procedure.docx

04 — COMMUNICATE-P (11 documents)

  1. Privacy Transparency Policy.docx
  2. Privacy Communication Roles and Responsibilities.docx
  3. Privacy Notice Template Set.docx
  4. Data Processing Practices Public Report Template.docx
  5. Individual Feedback Mechanism Procedure.docx
  6. Data Processing Visibility Design Standard.docx
  7. Data Disclosure and Sharing Register.xlsx
  8. Correction and Deletion Notification Procedure.docx
  9. Data Provenance and Lineage Standard.docx
  10. Privacy Breach Notification Procedure.docx
  11. Privacy Breach Notification Letter Templates.docx

05 — PROTECT-P (23 documents)

  1. Data Protection Improvement Procedure.docx
  2. Privacy Incident Response and Recovery Plan.docx
  3. Privacy Incident Register.xlsx
  4. Identity and Credential Management Policy.docx
  5. Identity Proofing and Binding Procedure.docx
  6. Authentication Standard.docx
  7. Identity Assertion Protection Standard.docx
  8. Access Control and Least Privilege Policy.docx
  9. Physical Access Control Procedure.docx
  10. Data at Rest Protection Standard.docx
  11. Data in Transit Protection Standard.docx
  12. System and Data Life Cycle Management Procedure.docx
  13. Hardware and Software Integrity Assessment Procedure.docx
  14. Data in Use Protection Standard.docx
  15. Backup and Restoration Procedure.docx
  16. Configuration Management Standard.docx
  17. Software Maintenance and Removal Procedure.docx
  18. Hardware Maintenance and Removal Procedure.docx
  19. Unauthorised Software Prevention Standard.docx
  20. Network and Environment Protection Standard.docx
  21. Environmental Threat Protection Procedure.docx
  22. Resilience Requirements Standard.docx
  23. Capacity Management Procedure.docx

06 — Profiles and Implementation Tiers (8 documents)

  1. Privacy Framework Profiles Guide.docx
  2. Current Profile Workbook.xlsx
  3. Target Profile Workbook.xlsx
  4. Profile Gap Analysis and Action Plan.xlsx
  5. Implementation Tiers Assessment Guide.docx
  6. Implementation Tier Self-Assessment Workbook.xlsx
  7. Privacy and Cybersecurity Risk Relationship Guide.docx
  8. Privacy Programme Roadmap and Milestone Plan.xlsx

07 — Crosswalks (6 documents)

  1. Crosswalk Guide and Methodology.docx
  2. PF 1.1 to NIST CSF 2.0 Crosswalk.xlsx
  3. PF 1.1 to NIST SP 800-53 Rev 5 Crosswalk.xlsx
  4. PF 1.1 to ISO IEC 27701 Crosswalk.xlsx
  5. PF 1.1 to GDPR Crosswalk.xlsx
  6. PF 1.1 to US State Privacy Law Crosswalk.xlsx

08 — Assurance and Audit (8 documents)

  1. Privacy Programme Internal Audit Procedure.docx
  2. Privacy Audit Programme and Schedule.xlsx
  3. Privacy Framework Audit Checklist.xlsx
  4. Privacy Audit Report Template.docx
  5. Nonconformity and Corrective Action Procedure.docx
  6. Corrective Action Log.xlsx
  7. Management Review Meeting Pack Template.docx
  8. Privacy Evidence Register.xlsx

Frequently Asked Questions (FAQ)

What is the NIST Privacy Framework Toolkit?

The NIST Privacy Framework Toolkit is a set of 145 editable Microsoft Word and Excel templates for building and running a privacy program — 108 documents and 37 workbooks across nine sections, covering all 102 Subcategories of NIST Privacy Framework 1.1, together with Current and Target Profile workbooks, an Implementation Tier assessment, five crosswalks and a 102-point internal audit checklist.

Is NIST Privacy Framework 1.1 final?

No, and this matters. PF 1.1 is an Initial Public Draft — NIST CSWP 40 ipd, published 14 April 2025, comment period closed 13 June 2025. NIST has not announced a date for the final. PF 1.0, published 16 January 2020, is still the only final version. Describe your programme as aligned to the draft, never as compliant with it. The toolkit says this on every document, not just here.

Then why buy a toolkit built on a draft?

Because PF 1.1 is where the Framework is going, and it is aligned with CSF 2.0 — so if you already run a CSF 2.0 programme, the two share a vocabulary. Building to PF 1.0 today means adopting Protect-P categories that CSF 2.0 retired. The risk is that NIST renumbers the identifiers before final — so we built the pack so that a renumber is a data-file change and a rebuild, and shipped a transition guide that handles exactly this kind of remap.

Do I need to buy the Framework itself?

No. The NIST Privacy Framework is free. Download it from nist.gov/privacy-framework and read it alongside the toolkit — we encourage it. What you are buying here is the 145 documents you would otherwise write yourself, not access to the text.

Will this make us compliant with GDPR or CCPA?

No, and no toolkit can. The Privacy Framework is a voluntary risk management tool, not a law. It gives you the operating model through which statutory obligations are managed; the obligations themselves remain separate. The toolkit keeps that distinction visible — obligations live in their own register, and the GDPR and US state law crosswalks carry an explicit warning that a mapping is not evidence of compliance.

We already have ISO 27001. Is this duplication?

Very little of it. An information security management system manages unauthorised access and compromise. It does not surface over-retention, undisclosed inference, purpose drift or an automated decision an individual cannot challenge — those arise from processing that is fully authorised and perfectly secure, and a security review of them returns no finding. The toolkit ships a crosswalk to ISO/IEC 27701 so you can reuse the evidence you already hold, and a guide setting out exactly which risks your ISMS will and will not find.

How is this different from your GDPR or ISO 27701 toolkit?

GDPR is a law and that pack is built around its obligations. ISO/IEC 27701 is a certifiable management system standard. The NIST Privacy Framework is neither: it is a voluntary risk model, structured around outcomes rather than requirements, and it is the one that works across jurisdictions because it deliberately avoids the vocabulary of any single regime. Many organisations run this as the operating model and the others as obligation sets on top.

What formats are the documents in?

Microsoft Word (.docx) and Microsoft Excel (.xlsx) — 108 and 37 respectively. Every file is fully editable, unlocked and unprotected, ready to be rebranded and populated with your own information. The workbooks carry drop-down validation, frozen headers, autofilters and worked example rows flagged for deletion.

The documents use British spelling. Can I change it?

Yes — every file is unlocked and editable. The documents use British spelling (“programme”, “minimisation”, “organisation”) as a house convention across our catalogue. NIST’s own Subcategory text is reproduced verbatim and therefore keeps US spelling, so both appear in the pack. A find-and-replace handles it if your house style requires consistency.

How long does it take to deploy?

The Implementation Roadmap sets out seven stages, and it is explicit that you should not start with Protect-P. That section most resembles an existing security programme, which makes it the most tempting starting point and the least useful one — an organisation that begins there ends up with a security programme wearing privacy labels. Start with mandate and scope, then the inventory and data map, then risk, then the Current Profile.

What happens when PF 1.1 is finalised?

Updates are free for life. When NIST publishes the final we compare it against the draft Core, reissue the pack, and you download the new version at no charge. The Transition Guide already covers the method for remapping evidence if the identifiers change.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.

Reviews

There are no reviews yet

Add a review
Currently, we are not accepting new reviews