Description
About the NIST CSF Toolkit
The NIST CSF Toolkit is a complete implementation and assessment pack for the NIST Cybersecurity Framework 2.0. It is 164 editable documents — 118 Word policies, procedures and guides, and 46 Excel workbooks — covering all 106 Subcategories of the Framework Core.
Fourteen of the workbooks ship pre-loaded with every one of the 106 outcomes, so the assessment starts the moment you open the file rather than after a week of typing.
First, the thing our competitors will not tell you
There is no certification against the NIST Cybersecurity Framework. No accreditation body, no certificate, no auditor who can issue one. Nobody is “CSF certified” and nobody is “CSF compliant” — the correct phrase is aligned to CSF 2.0, and anyone selling you certification is not selling what they say.
Implementation Tiers are not a certification either, and they are not maturity levels. NIST presents them as a notional illustration.
We say this first because it is true, because it is what an assessor will say, and because a toolkit that lets you believe otherwise has sold you a problem.
What you can do is run the Framework properly, assess yourself honestly against all 106 outcomes, and hold evidence a customer or regulator will accept. That is what this pack is for.
The assessment tool is the product
Most CSF packs are a policy library with a maturity spreadsheet bolted on. This one is built the other way round.
GDL-CSF-PRF-006, the CSF 2.0 Assessment and Maturity Tool, carries all 106 Subcategories with NIST’s own outcome wording, a five-point scoring scale, an evidence reference against every score, a target score, a calculated gap, and automatic roll-ups by Function and by Category. It is an Excel file. It opens, it works, and it does not need a login.
Around it sit six more pre-loaded workbooks: Current Profile, Target Profile, Profile Gap Analysis, Action Plan and Improvement Roadmap, Executive Reporting Dashboard, and the CSF 2.0 Core Reference with NIST’s Implementation Examples and Informative References in full.
Implementation Tiers, scored the way NIST actually defines them
This is the detail nearly every Tier assessment on the market gets wrong.
CSWP 29 Table 2 scores Tiers across two separate axes: cybersecurity risk governance (the GOVERN Function) and cybersecurity risk management (IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER). An organisation can sit at Tier 3 on management and Tier 1 on governance — capable operational practice with no organisational risk strategy behind it. That is a real and common result, and a single overall Tier number erases it.
GDL-CSF-PRF-008 scores both axes separately, with NIST’s own characterisation of each Tier on each axis, an evidence column, and a selection sheet that records current Tier, target Tier and the reasoning.
Why the count is 106 and not 185
If you download NIST’s own CSF 2.0 reference file and count the Subcategory rows, you get 185. You will then wonder why this toolkit claims 106.
The reference file carries 79 withdrawn CSF 1.1 entries, marked [Withdrawn: ...], alongside the live Core. 106 + 79 = 185. The correct count of current outcomes is 106, in 22 Categories and 6 Functions.
Every one of the 79 withdrawn identifiers is listed in the Core Reference with the CSF 2.0 outcome NIST says it was incorporated into or moved to, and mapped again in the Transition Map. If you are carrying a CSF 1.1 programme across, that mapping is the first thing you need.
GOVERN is new, and it is the largest Function
| Function | Categories | Subcategories |
|---|---|---|
| GOVERN (GV) | 6 | 31 |
| IDENTIFY (ID) | 3 | 21 |
| PROTECT (PR) | 5 | 22 |
| DETECT (DE) | 2 | 11 |
| RESPOND (RS) | 4 | 13 |
| RECOVER (RC) | 2 | 8 |
| Total | 22 | 106 |
Thirty-one of the 106 outcomes sit under GOVERN — more than under PROTECT. Ten of those are supply chain alone. In CSF 1.1, governance was four Subcategories buried inside IDENTIFY, so an organisation moving across from 1.1 has almost nothing to show here. That is why Section 01 of this toolkit is 32 documents.
Sixteen of the 106 Subcategories have no CSF 1.1 ancestor at all. They are listed by identifier and outcome in the Transition Guide, so you know exactly where you will be starting from zero.
The Framework text ships inside the documents — lawfully
Every one of our ISO toolkits has to paraphrase, because ISO requirement wording is copyright. This one does not.
NIST Technical Series publications are works of the United States Government. Works authored by NIST employees are subject to 17 U.S.C. 105 and are not subject to copyright protection within the United States, and NIST grants a royalty-free right to reprint them and to prepare derivative works, conditioned on attribution.
So each of the 118 Word documents opens with a Framework outcomes addressed table carrying the Subcategory identifier, its Category, and the outcome text in full. You can hand any single document to an assessor and they can see exactly which outcomes it is evidence for, without holding the Framework open beside it.
The same permission is why the Core Reference workbook carries NIST’s Implementation Examples in full — not summarised, not paraphrased.
Crosswalks, with their coverage stated on the face of them
Six crosswalk workbooks, built from NIST’s own published Informative References:
| Crosswalk | Coverage of the 106 |
|---|---|
| NIST SP 800-53 Rev 5 | 106 / 106 |
| ISO/IEC 27001:2022 | 106 / 106 |
| NIST SP 800-171 Rev 3 | 89 / 106 |
| CIS Controls v8.1 | 48 / 106 |
| NIST Privacy Framework 1.1 | structured worksheet — see below |
| CSF 1.1 to CSF 2.0 | 79 withdrawn identifiers mapped |
NIST publishes no CSF-to-Privacy-Framework mapping, so that workbook is not a populated crosswalk and we do not pretend otherwise. It ships as a structured worksheet carrying all 106 outcomes with relationship and shared-evidence columns ready to complete — the mirror image of the workbook in our Privacy Framework pack, which is blank for the same reason.
CIS Controls reaches 48 of the 106, and we say so on the workbook itself. CIS is a prioritised set of technical safeguards; it does not set out to cover organisational risk governance, so most of GOVERN has no CIS equivalent. The empty rows are the finding. A crosswalk that hides them is worse than one that shows them.
Two constraints we hold to. Third-party frameworks are cited by identifier and our own short description only — ISO requirement wording is not ours to republish, and the identifier is there so you can look it up in your own licensed copy. And every crosswalk carries a guide stating plainly that a mapping is not a claim of equivalence and must never be offered to an assessor as evidence that a control operates.
A note on SP 800-171 and CMMC
NIST publishes a CSF 2.0 mapping to SP 800-171 Revision 3 only. There is no Revision 2 mapping in NIST’s reference data, so ours is a Rev 3 crosswalk.
CMMC assessments remain anchored to SP 800-171 Rev 2. That crosswalk is not a CMMC coverage claim and the workbook says so. We would rather tell you that than sell you a mapping you cannot use.
NIST CSF Toolkit structure
| # | Section | Documents |
|---|---|---|
| 00 | Programme Foundation | 8 |
| 01 | GOVERN (GV) | 32 |
| 02 | IDENTIFY (ID) | 27 |
| 03 | PROTECT (PR) | 33 |
| 04 | DETECT (DE) | 13 |
| 05 | RESPOND (RS) | 15 |
| 06 | RECOVER (RC) | 10 |
| 07 | Organizational Profiles and Implementation Tiers | 10 |
| 08 | Crosswalks | 7 |
| 09 | Assurance and Audit | 9 |
| Total | 164 |
The NIST CSF Toolkit is 118 Word documents and 46 Excel workbooks. Sections 01 to 06 are the Framework’s six Functions, in NIST’s own order, so the pack is laid out the way an assessor reads it.
Fourteen workbooks ship already filled in
They are not blank templates. Fourteen of the 46 workbooks ship pre-loaded with all 106 Subcategories — Function, Category, identifier and the outcome text in full:
| Workbook | What it does |
|---|---|
| CSF 2.0 Core Reference | The whole Core, plus NIST’s Implementation Examples, the 79 withdrawn identifiers and the 16 outcomes new in 2.0 |
| Current Profile | Status, extent and evidence per outcome, with an audit-tested column |
| Target Profile | Is-a-target, priority, the driver behind it, and the rationale |
| Profile Gap Analysis | The gap, the risk left open, the action, the evidence of closure |
| Action Plan and Improvement Roadmap | Dated actions with owners, and a column for what was prioritised but not funded |
| CSF 2.0 Assessment and Maturity Tool | Scored assessment with roll-ups by Function and Category |
| Executive Reporting Dashboard | Board-level position and movement |
| CSF 2.0 Audit Checklist | Audit question, method, sample, evidence examined and limitation per outcome |
| Evidence Register | Every outcome pointed at the artefact that evidences it |
| Crosswalk to NIST SP 800-53 Rev 5 | 106 / 106 |
| Crosswalk to ISO/IEC 27001:2022 | 106 / 106, identifiers only |
| Crosswalk to NIST SP 800-171 Rev 3 | 89 / 106 |
| Crosswalk to CIS Controls v8.1 | 48 / 106, coverage stated |
| CSF 1.1 to CSF 2.0 Transition Map | All 79 withdrawn identifiers with successors |
All fourteen are generated from one Subcategory set, so they cannot drift apart from each other or from the documents.
Every document names the outcomes it answers
All 106 Subcategories are covered, and the build fails if any one of them is left without a document — a check we run, not a claim we make. The same check rejects any document that cites an identifier which is not in the live Core.
That matters more here than it sounds. CSF 2.0 numbering is deliberately not contiguous: ID.AM runs 01–05, 07, 08 with no ID.AM-06; PR.DS is 01, 02, 10, 11; DE.CM is 01, 02, 03, 06, 09. The gaps are where CSF 1.1 outcomes were withdrawn. A pack that quietly fills a gap to tidy a sequence is citing an outcome that does not exist.
What you get
- 164 documents: 118 in Word, 46 in Excel. No PDFs you cannot edit.
- All 106 Subcategories covered, with NIST’s outcome text reproduced in full.
- British spelling throughout; a find-and-replace to US spelling is safe and
affects no identifier.
- 12 months of free updates.
- A single-organisation perpetual licence — edit it, rebrand it, use it
indefinitely.
List of Documentation Toolkit:
00 — Programme Foundation (8 documents)
- Toolkit Guide and Document Index.docx
- Cybersecurity Framework Implementation Roadmap.docx
- CSF Scope and Boundary Statement.docx
- Cybersecurity Programme Charter.docx
- Cybersecurity Terms and Definitions Glossary.docx
- CSF 2.0 Core Reference.xlsx
- CSF 1.1 to CSF 2.0 Transition Guide.docx
- Document Control and Version Register.xlsx
01 — GOVERN (GV) (32 documents)
- Organizational Context Statement.docx
- Mission and Stakeholder Expectations Analysis.docx
- Legal Regulatory and Contractual Requirements Register.xlsx
- Critical Objectives and Services Register.xlsx
- Dependencies and Critical Services Analysis.docx
- Cybersecurity Risk Management Strategy.docx
- Risk Appetite and Risk Tolerance Statement.docx
- Enterprise Risk Integration Procedure.docx
- Risk Response Strategy and Options.docx
- Risk Communication Line of Sight Procedure.docx
- Risk Prioritisation and Resource Allocation Procedure.docx
- Positive Risk and Opportunity Register.xlsx
- Cybersecurity Roles Responsibilities and Authorities.docx
- Leadership Accountability Statement.docx
- Cybersecurity Resource Allocation Plan.docx
- Human Resources Cybersecurity Practices Procedure.docx
- Cybersecurity Policy.docx
- Policy Review and Maintenance Procedure.docx
- Cybersecurity Oversight and Governance Review Procedure.docx
- Risk Management Strategy Performance Review Report.docx
- Programme Coverage and Adjustment Review.docx
- Cyber Supply Chain Risk Management Programme.docx
- Supplier Roles and Responsibilities Statement.docx
- C-SCRM Integration into Enterprise Risk Procedure.docx
- Supplier Identification and Prioritisation Procedure.docx
- Supplier Register.xlsx
- Supplier Contract Cybersecurity Requirements.docx
- Supplier Due Diligence Procedure.docx
- Supplier Risk Monitoring Procedure.docx
- Supply Chain Incident Response and Recovery Planning.docx
- Supply Chain Practices Through the Technology Lifecycle.docx
- Supplier Termination and Exit Procedure.docx
02 — IDENTIFY (ID) (27 documents)
- Asset Management Policy.docx
- Hardware Asset Inventory.xlsx
- Software Services and Systems Inventory.xlsx
- Network and Data Flow Documentation Procedure.docx
- Network Diagram and Data Flow Register.xlsx
- Supplier-Provided Services Inventory.xlsx
- Asset Criticality and Prioritisation Procedure.docx
- Data Inventory and Classification Register.xlsx
- Asset Lifecycle and Secure Disposal Procedure.docx
- Cybersecurity Risk Assessment Methodology.docx
- Vulnerability Identification and Management Procedure.docx
- Vulnerability Register.xlsx
- Threat Intelligence Procedure.docx
- Threat Register.xlsx
- Cybersecurity Risk Register.xlsx
- Risk Response Plan.docx
- Risk Response Tracking Register.xlsx
- Exception and Risk Acceptance Procedure.docx
- Change and Risk Impact Assessment Procedure.docx
- Vulnerability Disclosure Policy.docx
- Third-Party Hardware and Software Integrity Procedure.docx
- Critical Supplier Assessment Procedure.docx
- Continual Improvement Procedure.docx
- Lessons Learned and Post-Incident Review Procedure.docx
- Security Test and Exercise Programme.docx
- Cybersecurity Improvement Plan.docx
- Improvement Register.xlsx
03 — PROTECT (PR) (33 documents)
- Identity and Access Management Policy.docx
- Identity Lifecycle Procedure.docx
- Authentication and Credential Management Procedure.docx
- Identity Assertion Protection Standard.docx
- Access Control and Authorisation Procedure.docx
- Access Review Register.xlsx
- Physical Access Control Policy.docx
- Visitor and Physical Access Log.xlsx
- Security Awareness and Training Policy.docx
- Awareness and Training Plan.docx
- Specialised Role Training Procedure.docx
- Training Records Register.xlsx
- Data Security Policy.docx
- Cryptographic Controls Policy.docx
- Data at Rest Protection Standard.docx
- Data in Transit Protection Standard.docx
- Data in Use Protection Standard.docx
- Backup and Restoration Procedure.docx
- Backup Test Register.xlsx
- Platform Security Policy.docx
- Configuration Management Procedure.docx
- Secure Configuration Baseline Register.xlsx
- Patch and Maintenance Procedure.docx
- Hardware and Software Lifecycle Register.xlsx
- Change Management Procedure.docx
- Log Management and Retention Procedure.docx
- Malware Prevention Procedure.docx
- Secure Software Development Policy.docx
- Technology Infrastructure Resilience Policy.docx
- Network Security Standard.docx
- Physical and Environmental Protection Procedure.docx
- Resilience and Redundancy Architecture Statement.docx
- Capacity and Availability Management Procedure.docx
04 — DETECT (DE) (13 documents)
- Continuous Monitoring Policy.docx
- Network Monitoring Procedure.docx
- Physical Environment Monitoring Procedure.docx
- Personnel Activity and Technology Usage Monitoring Procedure.docx
- External Service Provider Monitoring Procedure.docx
- Computing Hardware and Software Monitoring Procedure.docx
- Monitoring Coverage Register.xlsx
- Adverse Event Analysis Procedure.docx
- Event Correlation and Log Review Standard.docx
- Event Impact and Scope Assessment Procedure.docx
- Incident Declaration Criteria.docx
- Threat Intelligence Integration into Analysis Procedure.docx
- Event and Alert Register.xlsx
05 — RESPOND (RS) (15 documents)
- Incident Response Plan.docx
- Incident Response Policy.docx
- Incident Triage and Categorisation Procedure.docx
- Incident Escalation and Elevation Procedure.docx
- Incident Closure Procedure.docx
- Incident Register.xlsx
- Forensic Investigation and Evidence Handling Procedure.docx
- Incident Analysis Record.docx
- Evidence and Chain of Custody Register.xlsx
- Incident Magnitude Estimation Procedure.docx
- Internal Incident Communication Procedure.docx
- External Incident Notification and Regulatory Reporting Procedure.docx
- Stakeholder Notification Register.xlsx
- Incident Containment Procedure.docx
- Incident Eradication Procedure.docx
06 — RECOVER (RC) (10 documents)
- Incident Recovery Plan.docx
- Recovery Execution Procedure.docx
- Recovery Prioritisation and Scope Procedure.docx
- Backup Integrity Verification Procedure.docx
- Recovery Completion and Normal Operations Declaration.docx
- Post-Recovery Asset Integrity Verification Procedure.docx
- Recovery Test and Exercise Register.xlsx
- Recovery Communication Procedure.docx
- Public and Stakeholder Communication Templates.docx
- Recovery Status Reporting Register.xlsx
07 — Organizational Profiles and Implementation Tiers (10 documents)
- Organizational Profile Guide.docx
- Current Profile.xlsx
- Target Profile.xlsx
- Profile Gap Analysis.xlsx
- Action Plan and Improvement Roadmap.xlsx
- CSF 2.0 Assessment and Maturity Tool.xlsx
- Implementation Tiers Guide.docx
- Implementation Tier Self-Assessment.xlsx
- Community Profile Selection Guide.docx
- Executive Reporting Dashboard.xlsx
08 — Crosswalks (7 documents)
- Crosswalk Guide.docx
- Crosswalk to NIST SP 800-53 Rev 5.xlsx
- Crosswalk to ISO IEC 27001 2022.xlsx
- Crosswalk to NIST SP 800-171 Rev 3.xlsx
- Crosswalk to CIS Controls v8.1.xlsx
- Crosswalk to NIST Privacy Framework 1.1.xlsx
- CSF 1.1 to CSF 2.0 Transition Map.xlsx
09 — Assurance and Audit (9 documents)
- Internal Audit Programme.docx
- CSF 2.0 Audit Checklist.xlsx
- Evidence Register.xlsx
- Management Review Procedure.docx
- Management Review Minutes Template.docx
- Cybersecurity Metrics and KPI Register.xlsx
- Nonconformity and Corrective Action Procedure.docx
- Corrective Action Register.xlsx
- Third-Party Assessment Readiness Guide.docx
Frequently Asked Questions (FAQ)
What is the NIST CSF Toolkit?
The NIST CSF Toolkit is 164 editable documents implementing the NIST Cybersecurity Framework 2.0: 118 Word policies, procedures and guides across the six Functions, and 46 Excel workbooks including a scored assessment and maturity tool, Current and Target Profiles, a gap analysis, an action plan, an audit checklist and six crosswalks. All 106 Subcategories of the Framework are covered.
Can this make us NIST CSF certified?
No, and nothing can. There is no certification scheme for the NIST Cybersecurity Framework, no accreditation body and no certificate. CSF 2.0 is voluntary guidance. What this toolkit does is let you assess yourself against all 106 outcomes, close the gaps deliberately, and hold evidence a customer or regulator will accept. The correct way to describe the result is aligned to NIST CSF 2.0.
Do I need to buy the Framework itself?
No. NIST CSF 2.0 is free. We link to it and we encourage you to read it. The Core’s outcome text and NIST’s Implementation Examples are also reproduced in full inside this toolkit, which we may lawfully do because NIST Technical Series publications are US Government works.
We already run ISO 27001. Is this duplication?
Partly, and the crosswalk shows you exactly where. NIST’s own Informative References map all 106 CSF outcomes to ISO/IEC 27001, so you can see which evidence you already hold. What ISO 27001 will not give you is the CSF’s Organizational Profiles, its Implementation Tiers, or the GOVERN Function’s supply chain depth. And the mapping is orientation, not coverage — it says the two frameworks address a related concern, not that they demand the same thing.
How is this different from your NIST Cyber Risk Management Toolkit?
They answer different questions. The NIST Cyber Risk Management Toolkit is built on SP 800-30 and is for running a risk assessment — risk registers, risk matrices, treatment plans. This toolkit is built on the CSF 2.0 Core and is for running and evidencing a framework programme: 106 outcomes, Profiles, Tiers, gap analysis, crosswalks. Organisations that need both usually buy both; if you only want one, buy the one that matches the question you are being asked.
We are on CSF 1.1. How much work is the move?
More than a relabel, and the toolkit tells you exactly how much. 79 Subcategories were withdrawn and 12 whole Categories disappeared. 16 outcomes are genuinely new with no 1.1 ancestor. And GOVERN went from four Subcategories inside IDENTIFY to a Function of 31. The Transition Guide and Transition Map carry NIST’s own successor mapping for every withdrawn identifier, so the re-mapping is mechanical — the real work is GOVERN.
What formats are the documents in?
Microsoft Word (.docx) and Microsoft Excel (.xlsx). Everything is editable. There are no locked PDFs and no macros.
The documents use British spelling. Can I change it?
Yes. A find-and-replace is safe. Every CSF identifier, Function name and Subcategory outcome is reproduced in NIST’s own spelling and casing and is not affected.
How long does it take to deploy?
The assessment can start the day you open the file — the workbooks are pre-loaded. A first full cycle, from scoping to an approved action plan, is typically planned as an eight-week exercise for a single scope; the Implementation Roadmap sets out the week-by-week sequence. Adopting all 164 documents at once does not work, and the Roadmap says so and gives you the order instead.
What happens if NIST revises the CSF?
You get the updated toolkit free for 12 months from purchase. CSF 2.0 was published on 26 February 2024, is final, and NIST has published no revision and announced none. The only related work in progress is a supplementary quick-start guide on using AI for CSF analysis, which is not a change to the Framework.
Moving from CertiKit? CertiKit closes on 18 December 2026 and its NIST Cybersecurity Framework toolkit, which sold for £595, is no longer being updated. This one is $99 with twelve months of free updates. See how the two compare on CSF 2.0.
ISO 14001 Toolkit - Comprehensive 65+ Templates 




































Reviews
There are no reviews yet