Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

NIST CSF Toolkit – 164 Cybersecurity Framework 2.0 Templates

The NIST CSF Toolkit is 164 editable documents covering all 106 Subcategories of the NIST Cybersecurity Framework 2.0 — 118 Word policies and procedures plus 46 Excel workbooks, including a scored assessment and maturity tool, Current and Target Profiles, a two-axis Implementation Tier self-assessment, and crosswalks to SP 800-53 Rev 5, ISO/IEC 27001, SP 800-171 Rev 3 and CIS Controls. Every document names the Framework outcomes it answers, with NIST’s own wording reproduced in full.

$99.00

✓ In stock — instant download after checkout

Instant downloadYour files are available immediately after checkout
Fully editableNative Microsoft Word & Excel templates
30-day money-back guaranteeNot satisfied? Request a refund within 30 days
🔒Secure checkoutEncrypted payment powered by Stripe

Description

About the NIST CSF Toolkit

The NIST CSF Toolkit is a complete implementation and assessment pack for the NIST Cybersecurity Framework 2.0. It is 164 editable documents — 118 Word policies, procedures and guides, and 46 Excel workbooks — covering all 106 Subcategories of the Framework Core.

Fourteen of the workbooks ship pre-loaded with every one of the 106 outcomes, so the assessment starts the moment you open the file rather than after a week of typing.

First, the thing our competitors will not tell you

There is no certification against the NIST Cybersecurity Framework. No accreditation body, no certificate, no auditor who can issue one. Nobody is “CSF certified” and nobody is “CSF compliant” — the correct phrase is aligned to CSF 2.0, and anyone selling you certification is not selling what they say.

Implementation Tiers are not a certification either, and they are not maturity levels. NIST presents them as a notional illustration.

We say this first because it is true, because it is what an assessor will say, and because a toolkit that lets you believe otherwise has sold you a problem.

What you can do is run the Framework properly, assess yourself honestly against all 106 outcomes, and hold evidence a customer or regulator will accept. That is what this pack is for.

The assessment tool is the product

Most CSF packs are a policy library with a maturity spreadsheet bolted on. This one is built the other way round.

GDL-CSF-PRF-006, the CSF 2.0 Assessment and Maturity Tool, carries all 106 Subcategories with NIST’s own outcome wording, a five-point scoring scale, an evidence reference against every score, a target score, a calculated gap, and automatic roll-ups by Function and by Category. It is an Excel file. It opens, it works, and it does not need a login.

Around it sit six more pre-loaded workbooks: Current Profile, Target Profile, Profile Gap Analysis, Action Plan and Improvement Roadmap, Executive Reporting Dashboard, and the CSF 2.0 Core Reference with NIST’s Implementation Examples and Informative References in full.

Implementation Tiers, scored the way NIST actually defines them

This is the detail nearly every Tier assessment on the market gets wrong.

CSWP 29 Table 2 scores Tiers across two separate axes: cybersecurity risk governance (the GOVERN Function) and cybersecurity risk management (IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER). An organisation can sit at Tier 3 on management and Tier 1 on governance — capable operational practice with no organisational risk strategy behind it. That is a real and common result, and a single overall Tier number erases it.

GDL-CSF-PRF-008 scores both axes separately, with NIST’s own characterisation of each Tier on each axis, an evidence column, and a selection sheet that records current Tier, target Tier and the reasoning.

Why the count is 106 and not 185

If you download NIST’s own CSF 2.0 reference file and count the Subcategory rows, you get 185. You will then wonder why this toolkit claims 106.

The reference file carries 79 withdrawn CSF 1.1 entries, marked [Withdrawn: ...], alongside the live Core. 106 + 79 = 185. The correct count of current outcomes is 106, in 22 Categories and 6 Functions.

Every one of the 79 withdrawn identifiers is listed in the Core Reference with the CSF 2.0 outcome NIST says it was incorporated into or moved to, and mapped again in the Transition Map. If you are carrying a CSF 1.1 programme across, that mapping is the first thing you need.

GOVERN is new, and it is the largest Function

Function Categories Subcategories
GOVERN (GV) 6 31
IDENTIFY (ID) 3 21
PROTECT (PR) 5 22
DETECT (DE) 2 11
RESPOND (RS) 4 13
RECOVER (RC) 2 8
Total 22 106

Thirty-one of the 106 outcomes sit under GOVERN — more than under PROTECT. Ten of those are supply chain alone. In CSF 1.1, governance was four Subcategories buried inside IDENTIFY, so an organisation moving across from 1.1 has almost nothing to show here. That is why Section 01 of this toolkit is 32 documents.

Sixteen of the 106 Subcategories have no CSF 1.1 ancestor at all. They are listed by identifier and outcome in the Transition Guide, so you know exactly where you will be starting from zero.

The Framework text ships inside the documents — lawfully

Every one of our ISO toolkits has to paraphrase, because ISO requirement wording is copyright. This one does not.

NIST Technical Series publications are works of the United States Government. Works authored by NIST employees are subject to 17 U.S.C. 105 and are not subject to copyright protection within the United States, and NIST grants a royalty-free right to reprint them and to prepare derivative works, conditioned on attribution.

So each of the 118 Word documents opens with a Framework outcomes addressed table carrying the Subcategory identifier, its Category, and the outcome text in full. You can hand any single document to an assessor and they can see exactly which outcomes it is evidence for, without holding the Framework open beside it.

The same permission is why the Core Reference workbook carries NIST’s Implementation Examples in full — not summarised, not paraphrased.

Crosswalks, with their coverage stated on the face of them

Six crosswalk workbooks, built from NIST’s own published Informative References:

Crosswalk Coverage of the 106
NIST SP 800-53 Rev 5 106 / 106
ISO/IEC 27001:2022 106 / 106
NIST SP 800-171 Rev 3 89 / 106
CIS Controls v8.1 48 / 106
NIST Privacy Framework 1.1 structured worksheet — see below
CSF 1.1 to CSF 2.0 79 withdrawn identifiers mapped

NIST publishes no CSF-to-Privacy-Framework mapping, so that workbook is not a populated crosswalk and we do not pretend otherwise. It ships as a structured worksheet carrying all 106 outcomes with relationship and shared-evidence columns ready to complete — the mirror image of the workbook in our Privacy Framework pack, which is blank for the same reason.

CIS Controls reaches 48 of the 106, and we say so on the workbook itself. CIS is a prioritised set of technical safeguards; it does not set out to cover organisational risk governance, so most of GOVERN has no CIS equivalent. The empty rows are the finding. A crosswalk that hides them is worse than one that shows them.

Two constraints we hold to. Third-party frameworks are cited by identifier and our own short description only — ISO requirement wording is not ours to republish, and the identifier is there so you can look it up in your own licensed copy. And every crosswalk carries a guide stating plainly that a mapping is not a claim of equivalence and must never be offered to an assessor as evidence that a control operates.

A note on SP 800-171 and CMMC

NIST publishes a CSF 2.0 mapping to SP 800-171 Revision 3 only. There is no Revision 2 mapping in NIST’s reference data, so ours is a Rev 3 crosswalk.

CMMC assessments remain anchored to SP 800-171 Rev 2. That crosswalk is not a CMMC coverage claim and the workbook says so. We would rather tell you that than sell you a mapping you cannot use.

NIST CSF Toolkit structure

# Section Documents
00 Programme Foundation 8
01 GOVERN (GV) 32
02 IDENTIFY (ID) 27
03 PROTECT (PR) 33
04 DETECT (DE) 13
05 RESPOND (RS) 15
06 RECOVER (RC) 10
07 Organizational Profiles and Implementation Tiers 10
08 Crosswalks 7
09 Assurance and Audit 9
Total 164

The NIST CSF Toolkit is 118 Word documents and 46 Excel workbooks. Sections 01 to 06 are the Framework’s six Functions, in NIST’s own order, so the pack is laid out the way an assessor reads it.

Fourteen workbooks ship already filled in

They are not blank templates. Fourteen of the 46 workbooks ship pre-loaded with all 106 Subcategories — Function, Category, identifier and the outcome text in full:

Workbook What it does
CSF 2.0 Core Reference The whole Core, plus NIST’s Implementation Examples, the 79 withdrawn identifiers and the 16 outcomes new in 2.0
Current Profile Status, extent and evidence per outcome, with an audit-tested column
Target Profile Is-a-target, priority, the driver behind it, and the rationale
Profile Gap Analysis The gap, the risk left open, the action, the evidence of closure
Action Plan and Improvement Roadmap Dated actions with owners, and a column for what was prioritised but not funded
CSF 2.0 Assessment and Maturity Tool Scored assessment with roll-ups by Function and Category
Executive Reporting Dashboard Board-level position and movement
CSF 2.0 Audit Checklist Audit question, method, sample, evidence examined and limitation per outcome
Evidence Register Every outcome pointed at the artefact that evidences it
Crosswalk to NIST SP 800-53 Rev 5 106 / 106
Crosswalk to ISO/IEC 27001:2022 106 / 106, identifiers only
Crosswalk to NIST SP 800-171 Rev 3 89 / 106
Crosswalk to CIS Controls v8.1 48 / 106, coverage stated
CSF 1.1 to CSF 2.0 Transition Map All 79 withdrawn identifiers with successors

All fourteen are generated from one Subcategory set, so they cannot drift apart from each other or from the documents.

Every document names the outcomes it answers

All 106 Subcategories are covered, and the build fails if any one of them is left without a document — a check we run, not a claim we make. The same check rejects any document that cites an identifier which is not in the live Core.

That matters more here than it sounds. CSF 2.0 numbering is deliberately not contiguous: ID.AM runs 01–05, 07, 08 with no ID.AM-06; PR.DS is 01, 02, 10, 11; DE.CM is 01, 02, 03, 06, 09. The gaps are where CSF 1.1 outcomes were withdrawn. A pack that quietly fills a gap to tidy a sequence is citing an outcome that does not exist.

What you get

  • 164 documents: 118 in Word, 46 in Excel. No PDFs you cannot edit.
  • All 106 Subcategories covered, with NIST’s outcome text reproduced in full.
  • British spelling throughout; a find-and-replace to US spelling is safe and

affects no identifier.

  • 12 months of free updates.
  • A single-organisation perpetual licence — edit it, rebrand it, use it

indefinitely.

List of Documentation Toolkit:

00 — Programme Foundation (8 documents)

  1. Toolkit Guide and Document Index.docx
  2. Cybersecurity Framework Implementation Roadmap.docx
  3. CSF Scope and Boundary Statement.docx
  4. Cybersecurity Programme Charter.docx
  5. Cybersecurity Terms and Definitions Glossary.docx
  6. CSF 2.0 Core Reference.xlsx
  7. CSF 1.1 to CSF 2.0 Transition Guide.docx
  8. Document Control and Version Register.xlsx

01 — GOVERN (GV) (32 documents)

  1. Organizational Context Statement.docx
  2. Mission and Stakeholder Expectations Analysis.docx
  3. Legal Regulatory and Contractual Requirements Register.xlsx
  4. Critical Objectives and Services Register.xlsx
  5. Dependencies and Critical Services Analysis.docx
  6. Cybersecurity Risk Management Strategy.docx
  7. Risk Appetite and Risk Tolerance Statement.docx
  8. Enterprise Risk Integration Procedure.docx
  9. Risk Response Strategy and Options.docx
  10. Risk Communication Line of Sight Procedure.docx
  11. Risk Prioritisation and Resource Allocation Procedure.docx
  12. Positive Risk and Opportunity Register.xlsx
  13. Cybersecurity Roles Responsibilities and Authorities.docx
  14. Leadership Accountability Statement.docx
  15. Cybersecurity Resource Allocation Plan.docx
  16. Human Resources Cybersecurity Practices Procedure.docx
  17. Cybersecurity Policy.docx
  18. Policy Review and Maintenance Procedure.docx
  19. Cybersecurity Oversight and Governance Review Procedure.docx
  20. Risk Management Strategy Performance Review Report.docx
  21. Programme Coverage and Adjustment Review.docx
  22. Cyber Supply Chain Risk Management Programme.docx
  23. Supplier Roles and Responsibilities Statement.docx
  24. C-SCRM Integration into Enterprise Risk Procedure.docx
  25. Supplier Identification and Prioritisation Procedure.docx
  26. Supplier Register.xlsx
  27. Supplier Contract Cybersecurity Requirements.docx
  28. Supplier Due Diligence Procedure.docx
  29. Supplier Risk Monitoring Procedure.docx
  30. Supply Chain Incident Response and Recovery Planning.docx
  31. Supply Chain Practices Through the Technology Lifecycle.docx
  32. Supplier Termination and Exit Procedure.docx

02 — IDENTIFY (ID) (27 documents)

  1. Asset Management Policy.docx
  2. Hardware Asset Inventory.xlsx
  3. Software Services and Systems Inventory.xlsx
  4. Network and Data Flow Documentation Procedure.docx
  5. Network Diagram and Data Flow Register.xlsx
  6. Supplier-Provided Services Inventory.xlsx
  7. Asset Criticality and Prioritisation Procedure.docx
  8. Data Inventory and Classification Register.xlsx
  9. Asset Lifecycle and Secure Disposal Procedure.docx
  10. Cybersecurity Risk Assessment Methodology.docx
  11. Vulnerability Identification and Management Procedure.docx
  12. Vulnerability Register.xlsx
  13. Threat Intelligence Procedure.docx
  14. Threat Register.xlsx
  15. Cybersecurity Risk Register.xlsx
  16. Risk Response Plan.docx
  17. Risk Response Tracking Register.xlsx
  18. Exception and Risk Acceptance Procedure.docx
  19. Change and Risk Impact Assessment Procedure.docx
  20. Vulnerability Disclosure Policy.docx
  21. Third-Party Hardware and Software Integrity Procedure.docx
  22. Critical Supplier Assessment Procedure.docx
  23. Continual Improvement Procedure.docx
  24. Lessons Learned and Post-Incident Review Procedure.docx
  25. Security Test and Exercise Programme.docx
  26. Cybersecurity Improvement Plan.docx
  27. Improvement Register.xlsx

03 — PROTECT (PR) (33 documents)

  1. Identity and Access Management Policy.docx
  2. Identity Lifecycle Procedure.docx
  3. Authentication and Credential Management Procedure.docx
  4. Identity Assertion Protection Standard.docx
  5. Access Control and Authorisation Procedure.docx
  6. Access Review Register.xlsx
  7. Physical Access Control Policy.docx
  8. Visitor and Physical Access Log.xlsx
  9. Security Awareness and Training Policy.docx
  10. Awareness and Training Plan.docx
  11. Specialised Role Training Procedure.docx
  12. Training Records Register.xlsx
  13. Data Security Policy.docx
  14. Cryptographic Controls Policy.docx
  15. Data at Rest Protection Standard.docx
  16. Data in Transit Protection Standard.docx
  17. Data in Use Protection Standard.docx
  18. Backup and Restoration Procedure.docx
  19. Backup Test Register.xlsx
  20. Platform Security Policy.docx
  21. Configuration Management Procedure.docx
  22. Secure Configuration Baseline Register.xlsx
  23. Patch and Maintenance Procedure.docx
  24. Hardware and Software Lifecycle Register.xlsx
  25. Change Management Procedure.docx
  26. Log Management and Retention Procedure.docx
  27. Malware Prevention Procedure.docx
  28. Secure Software Development Policy.docx
  29. Technology Infrastructure Resilience Policy.docx
  30. Network Security Standard.docx
  31. Physical and Environmental Protection Procedure.docx
  32. Resilience and Redundancy Architecture Statement.docx
  33. Capacity and Availability Management Procedure.docx

04 — DETECT (DE) (13 documents)

  1. Continuous Monitoring Policy.docx
  2. Network Monitoring Procedure.docx
  3. Physical Environment Monitoring Procedure.docx
  4. Personnel Activity and Technology Usage Monitoring Procedure.docx
  5. External Service Provider Monitoring Procedure.docx
  6. Computing Hardware and Software Monitoring Procedure.docx
  7. Monitoring Coverage Register.xlsx
  8. Adverse Event Analysis Procedure.docx
  9. Event Correlation and Log Review Standard.docx
  10. Event Impact and Scope Assessment Procedure.docx
  11. Incident Declaration Criteria.docx
  12. Threat Intelligence Integration into Analysis Procedure.docx
  13. Event and Alert Register.xlsx

05 — RESPOND (RS) (15 documents)

  1. Incident Response Plan.docx
  2. Incident Response Policy.docx
  3. Incident Triage and Categorisation Procedure.docx
  4. Incident Escalation and Elevation Procedure.docx
  5. Incident Closure Procedure.docx
  6. Incident Register.xlsx
  7. Forensic Investigation and Evidence Handling Procedure.docx
  8. Incident Analysis Record.docx
  9. Evidence and Chain of Custody Register.xlsx
  10. Incident Magnitude Estimation Procedure.docx
  11. Internal Incident Communication Procedure.docx
  12. External Incident Notification and Regulatory Reporting Procedure.docx
  13. Stakeholder Notification Register.xlsx
  14. Incident Containment Procedure.docx
  15. Incident Eradication Procedure.docx

06 — RECOVER (RC) (10 documents)

  1. Incident Recovery Plan.docx
  2. Recovery Execution Procedure.docx
  3. Recovery Prioritisation and Scope Procedure.docx
  4. Backup Integrity Verification Procedure.docx
  5. Recovery Completion and Normal Operations Declaration.docx
  6. Post-Recovery Asset Integrity Verification Procedure.docx
  7. Recovery Test and Exercise Register.xlsx
  8. Recovery Communication Procedure.docx
  9. Public and Stakeholder Communication Templates.docx
  10. Recovery Status Reporting Register.xlsx

07 — Organizational Profiles and Implementation Tiers (10 documents)

  1. Organizational Profile Guide.docx
  2. Current Profile.xlsx
  3. Target Profile.xlsx
  4. Profile Gap Analysis.xlsx
  5. Action Plan and Improvement Roadmap.xlsx
  6. CSF 2.0 Assessment and Maturity Tool.xlsx
  7. Implementation Tiers Guide.docx
  8. Implementation Tier Self-Assessment.xlsx
  9. Community Profile Selection Guide.docx
  10. Executive Reporting Dashboard.xlsx

08 — Crosswalks (7 documents)

  1. Crosswalk Guide.docx
  2. Crosswalk to NIST SP 800-53 Rev 5.xlsx
  3. Crosswalk to ISO IEC 27001 2022.xlsx
  4. Crosswalk to NIST SP 800-171 Rev 3.xlsx
  5. Crosswalk to CIS Controls v8.1.xlsx
  6. Crosswalk to NIST Privacy Framework 1.1.xlsx
  7. CSF 1.1 to CSF 2.0 Transition Map.xlsx

09 — Assurance and Audit (9 documents)

  1. Internal Audit Programme.docx
  2. CSF 2.0 Audit Checklist.xlsx
  3. Evidence Register.xlsx
  4. Management Review Procedure.docx
  5. Management Review Minutes Template.docx
  6. Cybersecurity Metrics and KPI Register.xlsx
  7. Nonconformity and Corrective Action Procedure.docx
  8. Corrective Action Register.xlsx
  9. Third-Party Assessment Readiness Guide.docx

Frequently Asked Questions (FAQ)

What is the NIST CSF Toolkit?

The NIST CSF Toolkit is 164 editable documents implementing the NIST Cybersecurity Framework 2.0: 118 Word policies, procedures and guides across the six Functions, and 46 Excel workbooks including a scored assessment and maturity tool, Current and Target Profiles, a gap analysis, an action plan, an audit checklist and six crosswalks. All 106 Subcategories of the Framework are covered.

Can this make us NIST CSF certified?

No, and nothing can. There is no certification scheme for the NIST Cybersecurity Framework, no accreditation body and no certificate. CSF 2.0 is voluntary guidance. What this toolkit does is let you assess yourself against all 106 outcomes, close the gaps deliberately, and hold evidence a customer or regulator will accept. The correct way to describe the result is aligned to NIST CSF 2.0.

Do I need to buy the Framework itself?

No. NIST CSF 2.0 is free. We link to it and we encourage you to read it. The Core’s outcome text and NIST’s Implementation Examples are also reproduced in full inside this toolkit, which we may lawfully do because NIST Technical Series publications are US Government works.

We already run ISO 27001. Is this duplication?

Partly, and the crosswalk shows you exactly where. NIST’s own Informative References map all 106 CSF outcomes to ISO/IEC 27001, so you can see which evidence you already hold. What ISO 27001 will not give you is the CSF’s Organizational Profiles, its Implementation Tiers, or the GOVERN Function’s supply chain depth. And the mapping is orientation, not coverage — it says the two frameworks address a related concern, not that they demand the same thing.

How is this different from your NIST Cyber Risk Management Toolkit?

They answer different questions. The NIST Cyber Risk Management Toolkit is built on SP 800-30 and is for running a risk assessment — risk registers, risk matrices, treatment plans. This toolkit is built on the CSF 2.0 Core and is for running and evidencing a framework programme: 106 outcomes, Profiles, Tiers, gap analysis, crosswalks. Organisations that need both usually buy both; if you only want one, buy the one that matches the question you are being asked.

We are on CSF 1.1. How much work is the move?

More than a relabel, and the toolkit tells you exactly how much. 79 Subcategories were withdrawn and 12 whole Categories disappeared. 16 outcomes are genuinely new with no 1.1 ancestor. And GOVERN went from four Subcategories inside IDENTIFY to a Function of 31. The Transition Guide and Transition Map carry NIST’s own successor mapping for every withdrawn identifier, so the re-mapping is mechanical — the real work is GOVERN.

What formats are the documents in?

Microsoft Word (.docx) and Microsoft Excel (.xlsx). Everything is editable. There are no locked PDFs and no macros.

The documents use British spelling. Can I change it?

Yes. A find-and-replace is safe. Every CSF identifier, Function name and Subcategory outcome is reproduced in NIST’s own spelling and casing and is not affected.

How long does it take to deploy?

The assessment can start the day you open the file — the workbooks are pre-loaded. A first full cycle, from scoping to an approved action plan, is typically planned as an eight-week exercise for a single scope; the Implementation Roadmap sets out the week-by-week sequence. Adopting all 164 documents at once does not work, and the Roadmap says so and gives you the order instead.

What happens if NIST revises the CSF?

You get the updated toolkit free for 12 months from purchase. CSF 2.0 was published on 26 February 2024, is final, and NIST has published no revision and announced none. The only related work in progress is a supplementary quick-start guide on using AI for CSF analysis, which is not a change to the Framework.

Moving from CertiKit? CertiKit closes on 18 December 2026 and its NIST Cybersecurity Framework toolkit, which sold for £595, is no longer being updated. This one is $99 with twelve months of free updates. See how the two compare on CSF 2.0.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.

Reviews

There are no reviews yet

Add a review
Currently, we are not accepting new reviews