Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST CSF policy templates — NIST CSF Policy Templates: What All 106 Outcomes Need

NIST CSF Policy Templates: What All 106 Outcomes Need

What this guide covers

NIST CSF policy templates explained
Documentation load by Function — GOVERN carries the most

What NIST CSF policy templates have to do

NIST CSF policy templates exist to solve a problem the Framework creates deliberately: CSF 2.0 states 106 outcomes and tells you almost nothing about how to achieve them. It is a taxonomy of what should be true, not a control catalogue. That is the right design for a framework meant to work across every sector and size — and it leaves you with 106 statements and a blank page.

A good template set closes that gap without pretending to be the Framework. Each document should say which outcomes it answers, in NIST’s own words, so that anyone reading it can see exactly what it is evidence for.

Where NIST CSF policy templates carry the most weight

Not evenly. The 106 Subcategories sit across six Functions, and the documentation load follows the Function sizes rather than intuition:

Function Categories Subcategories Documentation weight
GOVERN (GV) 6 31 Heaviest — and almost entirely documents rather than technology
IDENTIFY (ID) 3 21 Inventories, risk methodology, improvement
PROTECT (PR) 5 22 Policies plus configuration standards
DETECT (DE) 2 11 Lighter; mostly procedures and coverage records
RESPOND (RS) 4 13 Plan-led
RECOVER (RC) 2 8 Smallest, but four of its outcomes are new in 2.0

GOVERN carries more outcomes than PROTECT, which is not where most documentation effort is usually planned. It is also the Function where an organisation coming from CSF 1.1 has the least existing material, because in 1.1 governance was four Subcategories inside IDENTIFY.

The documents most CSF programmes are missing

Before choosing any set of NIST CSF policy templates, it is worth knowing which outcomes are usually left uncovered.

Working through the Core, a consistent set of gaps appears — outcomes that are easy to read past and awkward to evidence.

  • A risk appetite and tolerance statement (GV.RM-02). The Framework asks for both, and they are different things. Appetite is directional and set by the board; tolerance is numeric and tells an operator when to escalate without calling a meeting. Programmes without it escalate everything or nothing.
  • An opportunity register (GV.RM-07). Positive risks are a named outcome. Almost nobody records them, and an assessment that skips the outcome is rating itself achieved on something it has never attempted.
  • Three distinct oversight artefacts (GV.OV-01, -02, -03). Direction, coverage and performance are three questions, not one. A single annual review note answers one of them.
  • A supplier exit procedure (GV.SC-10). The outcome says practices apply during and after the relationship ends. Data extraction, access revocation, federation trusts removed, and a destruction certificate that covers backups — because backups are where residual data survives an exit.
  • Recovery verification (RC.RP-03 and RC.RP-05). Verifying backup integrity before restoring, and verifying restored assets afterwards. Both are new in CSF 2.0.
  • Incident magnitude estimation (RS.AN-08). Estimated and validated. The validation step is what stops a potential-scope figure being reported as a confirmed count.

What separates useful NIST CSF policy templates from filler

Four tests, and a template set that fails any of them will cost you more time than it saves.

  1. Every document names the outcomes it answers. Not “aligned to NIST CSF” on the cover, but the specific Subcategory identifiers, with the outcome text. If you have to work out the mapping yourself, you have bought a generic policy library.
  2. The mapping runs both ways and is complete. You should be able to start from any of the 106 and find the document that answers it. Coverage claimed but not demonstrated is worth testing on a sample of five outcomes before you buy.
  3. The identifiers are CSF 2.0, not CSF 1.1 relabelled. This is the defect to check for first — see below.
  4. It is honest about certification. There is no certification against the CSF, no accreditation body and no certificate. A pack that implies otherwise has sold you a claim you cannot make to a customer.

The relabelling defect, and how to spot it in five minutes

The fault worth checking for first in any set of NIST CSF policy templates is CSF 1.1 content wearing CSF 2.0 identifiers. It happens because updating a pack by find-and-replace is fast and reading 106 outcomes is not.

Three checks will find it:

Check What you are looking for
Does GOVERN have real depth? 31 Subcategories, six Categories, ten of them supply chain. A pack with three governance documents has not been rebuilt for 2.0
Are the numbering gaps intact? ID.AM runs 01–05, 07, 08 with no ID.AM-06. PR.DS is 01, 02, 10, 11. DE.CM is 01, 02, 03, 06, 09. A tidy contiguous sequence means invented identifiers
Do the withdrawn Categories still appear? PR.AC, PR.IP, PR.PT, ID.GV, ID.BE, ID.RM, ID.SC, PR.MA, DE.DP, RS.RP, RS.IM and RC.IM do not exist in CSF 2.0. Any of them in a “2.0” pack is 1.1 residue

One further trap for anyone checking programmatically: you cannot test the version by counting digits. CSF 1.1 used one digit (ID.AM-1) and 2.0 uses two (ID.AM-01), but 1.1 identifiers numbered past ten — PR.IP-10, PR.IP-11, PR.IP-12 — also carry two. Resolve each identifier against the live list of 106 instead.

Why NIST CSF policy templates may quote the Framework in full

One genuine advantage of building on a NIST framework rather than an ISO standard: the outcome text can appear in your documents in full.

NIST Technical Series publications are works of the United States Government. Works authored by NIST employees are subject to 17 U.S.C. 105 and are not subject to copyright protection within the United States, and NIST grants a royalty-free right to reprint them and prepare derivative works, conditioned on the recommended citation and a courtesy line.

That is why good NIST CSF policy templates can open with a table carrying the Subcategory identifier, its Category and the outcome verbatim — so a document can be handed to an assessor on its own, without the Framework open beside it. The permission does not extend to anything else: ISO requirement wording in a crosswalk is not NIST’s to license, so crosswalks carry clause identifiers only.

A deployment order for NIST CSF policy templates

Adopting a full set of NIST CSF policy templates at once does not work. Sequence it so that the documents everything else depends on land first:

  1. Scope, charter, context and the top-level policy. Nothing below means anything without a stated scope and a named accountable executive.
  2. Assess before you write. Establish where you actually are across the 106 outcomes, with evidence. Writing policy before assessing produces a library nobody asked for.
  3. The risk machinery. Methodology, register, appetite and tolerance. Everything downstream routes through these.
  4. Target Profile, gap analysis, dated plan. Now you know what to write and in what order.
  5. Deploy against the gap, not alphabetically. This is where most of the policy documents land, and the plan decides the sequence.
  6. Assurance last. Audit once there is something to audit.

The step people skip is the second one. A Current Profile assembled from opinion rather than evidence sends the whole plan at the wrong problems, and the error is invisible until an assessor asks what the rating was based on.

Common questions about NIST CSF policy templates

How many documents does a CSF programme need?

There is no required number — the Framework states outcomes, not documents. What matters is that all 106 Subcategories have something behind them and that you can show which document answers which. A one-to-one mapping is neither necessary nor achievable: broad policies answer several outcomes, and some outcomes need a register rather than a policy.

Do NIST CSF policy templates make us compliant?

No, and nothing does. CSF 2.0 is voluntary guidance with no certification scheme. Templates give you the starting documents; what makes them meaningful is adopting them, operating them and holding evidence. The correct description of the result is aligned to NIST CSF 2.0.

Can we adapt ISO 27001 documentation instead of NIST CSF policy templates?

Partly. NIST maps all 106 CSF outcomes to ISO/IEC 27001, so much of PROTECT and the policy Category will have evidence you already hold. What an ISMS usually will not give you is GV.SC at ten-Subcategory depth, the three separate oversight outcomes, or the four new recovery-verification outcomes. Use the mapping for orientation, not as proof of coverage. The same caution applies to the NIST CSF to 800-53 mapping, which reaches all 106 outcomes and still proves nothing about whether a control operates.

Should NIST CSF policy templates use US or British spelling?

It makes no difference to the Framework. What matters is that a find-and-replace is safe — which it is, provided every CSF identifier, Function name and Subcategory outcome is reproduced in NIST’s own spelling and left alone.

What should a template include beyond the policy statements?

Purpose, scope, the outcomes it answers, definitions, roles and responsibilities, the body, records with retention and owners, and related documents. The records table is the one most often missing and the one an auditor reaches for first, because it is where a policy stops being a statement and starts being evidence.

NIST CSF policy templates built on the Core

Read the Framework first — it is free, and it is short: nist.gov/cyberframework. Our NIST Cybersecurity Framework overview covers the Core, Profiles and Tiers, and the GOVERN function guide covers the Function that carries most of the documentation load.

Our NIST CSF Toolkit is 164 editable documents — 118 Word policies, procedures and guides across the six Functions, plus 46 Excel workbooks. Every Word document opens with a table naming the Subcategories it answers and NIST’s outcome text in full, and the build fails if any of the 106 is left without a document. That is a check we run, not a claim we make.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.