Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST Privacy Framework checklist infographic

NIST Privacy Framework Checklist: The Essential 2026 Guide to a 10-Step Rollout

A NIST Privacy Framework checklist gives a privacy team something it rarely has: a neutral, sequenced way to decide what to do first. The framework is voluntary, it is not tied to a single law, and it does not produce a certificate. That flexibility is its strength, but it also leaves many teams unsure where to start and how to show progress.

This guide turns the framework into ten practical steps, each with the evidence you should keep. It assumes you are building or maturing a privacy program and want to map it to NIST, to GDPR or to US state privacy laws. Timelines and effort vary by organization, so treat every range here as typical rather than guaranteed.

Free gap assessment

Is your privacy work built on the 2025 edition?

Score the standalone privacy management system, free, with privacy risk measured as risk to the individual rather than to you.

Run the free ISO 27701 gap assessment →  or  View premium report sample

What the framework is and what it is not

The NIST Privacy Framework is a voluntary tool published by the US National Institute of Standards and Technology to help organizations manage privacy risk. Version 1.0 appeared in January 2020, and NIST has been developing a version 1.1 that keeps the core structure while aligning more closely with the Cybersecurity Framework 2.0 and addressing AI. Check the NIST Privacy Framework page for the current published version before you fix your mapping.

The framework is organized around five functions: Identify-P, Govern-P, Control-P, Communicate-P and Protect-P. Each function contains categories and subcategories that describe outcomes, not specific controls. You decide how to achieve an outcome. That is why a NIST Privacy Framework checklist must be built from your own context rather than copied from a template.

It is not a law and there is no certification. For how it compares with other frameworks, see NIST Privacy Framework vs GDPR and NIST Privacy Framework vs ISO 27701.

The 10-step NIST Privacy Framework checklist

Work through the steps in order. Steps one to three set context, four to eight build the core capabilities, and nine and ten make the program repeatable.

  • Step 1: Define scope, business goals and the legal requirements that apply
  • Step 2: Inventory personal data and map data flows
  • Step 3: Assess privacy risk, including problematic data actions
  • Step 4: Assign governance roles and approve policies
  • Step 5: Build processes for individual requests, consent and retention
  • Step 6: Publish and maintain clear privacy notices
  • Step 7: Align security safeguards with privacy needs
  • Step 8: Manage third parties and data sharing
  • Step 9: Create a current and a target profile and plan the gap closure
  • Step 10: Monitor, review and report to leadership

Steps 1 to 3: scope, inventory and risk in your NIST Privacy Framework checklist

Start with scope. List the products, teams and jurisdictions in play, and note which laws apply. Then build the data inventory: what personal data you process, why, where it lives, who can access it and where it goes. Our guide on the NIST Privacy Framework data map shows a workable format.

Risk comes next. The framework focuses on problematic data actions, meaning processing that could cause adverse effects on individuals, such as unanticipated revelation or surveillance. Privacy risk is about harm to people, not just harm to the organization, and that is what separates it from security risk. Read problematic data actions and privacy risk vs cybersecurity risk before you score anything.

FunctionPurposeExample evidence to keep
Identify-PUnderstand data processing and related privacy risksData inventory, data maps, risk assessments
Govern-PSet policies, roles and oversightPrivacy policy, governance charter, training records
Control-PManage data processing and individual choicesConsent and request procedures, retention schedule
Communicate-PMake processing transparent to individualsPrivacy notices, communication logs
Protect-PSafeguard data and manage incidentsSecurity controls, incident response plan, test records

Steps 4 to 6: governance, individual rights and transparency

Governance is where many programs stall. Assign an accountable executive, name a privacy lead, define decision rights and approve policies. Evidence includes the governance charter, meeting minutes and training records. The Govern-P function explains the outcomes in more detail.

Then build the processes individuals touch: handling access, deletion and correction requests, recording consent where you rely on it, and setting retention periods with deletion routines. Finish with notices that match what you actually do. A notice that promises what your systems cannot deliver is a liability, so test your notice against your data map.

Steps 7 to 8: safeguards and third parties

Privacy and security overlap but do not match. Security protects data from unauthorized access; privacy also asks whether you should be collecting, using or sharing it at all. Map your existing security controls to the Protect-P outcomes, then look for privacy-specific gaps such as purpose limitation or minimization.

For third parties, keep a register of processors and recipients, confirm contracts carry the obligations you need and record assessments. If you already run a security framework, align with it; our notes on the NIST Privacy Framework cover the crosswalks.

Steps 9 to 10: profiles, tiers and monitoring

A profile is a snapshot of which outcomes you achieve now and which you want to achieve next. Build a current profile, define a target profile, compare them and turn the differences into a prioritized plan with owners and dates. See NIST Privacy Framework profiles for the method.

Tiers describe how rigorous your risk management practices are, from partial to adaptive. They are not a score to maximize; they help you decide what is appropriate. The page on implementation tiers explains how to choose. Finally, report progress to leadership on a fixed cycle, using your target profile as the yardstick.

Using templates to work through the checklist

Most of the ten steps produce documents: policies, registers, assessments, procedures and plans. The NIST Privacy Framework Toolkit provides editable templates that follow the framework’s structure, so you fill in your facts instead of inventing formats.

Templates are a starting point. Reviewers and regulators look for evidence that the program is real: dated records, approvals, training logs and examples of requests handled. Keep those records alongside the documents and review them on a schedule.

How long each step of the NIST Privacy Framework checklist takes

Effort depends on how much already exists. A company with a recent data inventory and a working security program may complete the scoping, governance and notice steps in a few weeks. A company starting from nothing often needs the first quarter just to find out where personal data lives, because marketing tools, support platforms, analytics scripts and spreadsheets all hold it. Plan the inventory as a cross-functional project with named owners in engineering, HR, marketing and customer support, not as a task for the privacy lead alone.

Risk assessment and profile building are the next largest efforts, because they require judgment and workshops rather than data entry. Policies and procedures are usually the fastest part when you start from templates. These durations are illustrative, so validate them against your own headcount and number of systems before you commit dates to leadership.

Free privacy risk assessment

Which privacy risks would hurt the people whose data you hold?

List your personal data and processing, pick from 38 privacy risk scenarios, rate them for the people concerned and for you, and plan treatment with ISO 27701 controls. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free privacy risk assessment →  or  View premium report sample

Evidence reviewers expect to see

Whether the reviewer is a customer, an auditor or a regulator, the questions are similar. Who is accountable for privacy? Where is the list of systems that hold personal data, and when was it last updated? How do you decide whether a new use of data is acceptable? What happened the last time someone asked to delete their data, and how long did it take? Prepare a short evidence binder that answers those questions with dated documents, and assign someone to refresh it every quarter.

Examples of strong evidence include an approved data inventory with version history, a completed risk assessment with named approvers, records of individual requests with response dates, vendor assessments and a training log. Weak evidence includes undated policies, screenshots with no context and claims that cannot be tied to a system or a person. Anything that cannot be reproduced on request will not be persuasive, so keep originals in a controlled location.

Keeping the checklist alive after rollout

A NIST Privacy Framework checklist only helps if it changes when your business changes. Tie it to events that already happen: a new product launch, a new vendor, a new data source, a merger or a change in the law. Each event should trigger a short review of the inventory, the risk assessment and the target profile, with the result recorded. Add a standing agenda item to a quarterly meeting so the work never depends on one person remembering, and record decisions so that the next reviewer can see why a choice was made.

Common mistakes with a NIST Privacy Framework checklist

Teams often treat the checklist as a one-time exercise and never update the data inventory. They copy another organization’s profile instead of writing their own. They confuse privacy with security and leave the harm-to-individuals analysis out. They also skip the target profile, so nobody can say what good looks like.

A final mistake is over-scoping. Begin with one product or business unit, prove the approach and then expand. A small, evidenced program beats a broad, paper-only one.

NIST Privacy Framework Checklist FAQ

Is the NIST Privacy Framework mandatory?

No. It is voluntary. Organizations use it to structure privacy risk management and to map to laws such as GDPR and US state privacy statutes.

Can I get certified to the NIST Privacy Framework?

No. There is no official certification. You can document your profiles and use internal or third-party reviews as evidence of alignment.

How long does a rollout take?

Typical programs take several months to a year depending on size and starting maturity. Scope one business unit first to shorten the cycle.

Does the framework replace GDPR compliance work?

No. It helps you organize the work, but you still must meet each applicable law’s specific obligations, such as lawful basis and breach notification.

What evidence should I keep?

Keep dated records: the data inventory, risk assessments, approvals, training logs, request handling records and monitoring reports.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.