Description
About the NIST Privacy Framework Toolkit
The NIST Privacy Framework is NIST’s voluntary model for managing privacy risk, it is free to download, and it is deliberately built to sit alongside the Cybersecurity Framework rather than inside any single privacy law. What it does not come with is the documentation a privacy program has to produce against it.
The NIST Privacy Framework Toolkit is 145 editable templates written against NIST Privacy Framework 1.1, and it covers all 102 of its active Subcategories.
First, the thing our competitors will not tell you
Privacy Framework 1.1 is an Initial Public Draft. It was published on 14 April 2025 as NIST CSWP 40 ipd. The comment period closed on 13 June 2025. NIST has not announced a publication date for the final, and PF 1.0 — published 16 January 2020 — remains the only final version.
That has three consequences, and the NIST Privacy Framework Toolkit is built around them rather than hiding them:
| Reality | What this toolkit does |
|---|---|
| Nobody can be “compliant with” or “certified against” a draft | Every document says aligned to PF 1.1 IPD. We never use the word compliant about the Framework itself |
| The Subcategory identifiers may change — the draft’s own Note to Reviewers asks reviewers whether NIST should renumber them in the Final Draft | All 102 identifiers live in one data module, so a renumber is one edit and a rebuild, not a rewrite of 145 files |
| An organisation on PF 1.0 has evidence mapped to identifiers that no longer exist | A PF 1.0 to PF 1.1 Transition Guide maps all 34 relocated identifiers and the 2 withdrawn ones |
If you want a pack that promises certification, this is not it — and neither is anything else, because no such certification exists for the Privacy Framework in any version.
Why the count is 102 and not 138
If you open the source PDF and text-search for Subcategory identifiers you will count 138, and conclude this toolkit is missing 36 of them. It is not. That figure breaks down as:
| Count | |
|---|---|
| Active Subcategories in PF 1.1 IPD | 102 |
| Retired PF 1.0 identifiers, carried in Appendix A only as “Moved to” pointers | 34 |
| Withdrawn — ID.RA-P2 (artificial intelligence systems) and CM.AW-P8 | 2 |
| Total identifiers appearing in the document | 138 |
The NIST Privacy Framework Toolkit covers the 102 that exist, lists the 34 that moved, and names the 2 that were withdrawn so you do not cover them by accident. For comparison, PF 1.0 had 5 Functions, 18 Categories and 100 Subcategories.
The Framework text ships inside the documents — lawfully
Every one of our ISO toolkits has to paraphrase, because ISO requirement wording is copyright. This one does not. NIST Technical Series publications are works of the United States Government: NIST’s own statement is that works authored by NIST employees are not subject to copyright protection within the United States, and NIST grants a royalty-free right to reprint them in derivative works, subject to attribution.
So each of the 108 Word documents opens with a Framework outcomes addressed table carrying the Subcategory identifier, its Category, and the outcome text in full. You can hand any single document to an assessor and they can see exactly which outcomes it is evidence for, without holding the Framework open beside it.
The attribution NIST asks for ships in the pack, in every document and in a NIST-ATTRIBUTION.txt file. The one carve-out: the ISO/IEC 27701 crosswalk carries clause numbers and short names only, because that text is not NIST’s to license.
The idea the whole Framework rests on, and the reason an ISMS is not enough
This is the argument for buying a privacy toolkit at all when you already have information security covered.
A privacy problem can arise from data processing that is authorised, accurate and perfectly secure. No attacker. No vulnerability. No breach. No failed control. There are three regions:
| Region | What it is | Who finds it |
|---|---|---|
| Cybersecurity only | Compromise of systems holding no data about individuals | Your security programme |
| Overlap | Unauthorised access to data about individuals — the classic breach | Both |
| Privacy only | Over-retention, undisclosed inference, purpose drift, an automated decision with no route to challenge, a default nobody would choose | Nothing but a privacy programme |
A security review of anything in the third region returns “no finding”, because the access was authorised and the controls operated correctly. That is why the NIST Privacy Framework Toolkit ships a Problematic Data Action Identification Procedure as a separate step before any risk is scored, built on one question: if this works perfectly, who could still be worse off?
The pack carries this through into places most toolkits do not:
- The incident response plan triggers on privacy events with no security failure — data
processed for an unauthorised purpose, an inference that should have been prohibited, a correction that never propagated. A security incident plan will not activate for any of them.
- The risk method requires you to consider processing less before proposing any control.
Six minimisation questions must be answered and recorded before a protective measure is accepted, because removing the data survives a misconfiguration and a control does not.
- The measurement set splits incidents by whether the processing was authorised, which is
the single measure that makes the third region visible. Reported as one number, it is not.
Profiles and Implementation Tiers, which is how the Framework is actually used
The Core is one of three components. A pack that ships only a control list is not a Privacy Framework toolkit.
- Current Profile Workbook — all 102 Subcategories pre-loaded, with status, evidence,
evidence location and an audit-tested column.
- Target Profile Workbook — because a Target Profile is chosen, not assumed to be all 102.
Deciding an outcome is not a target is a legitimate documented risk decision, and the workbook makes you record the rationale.
- Profile Gap Analysis and Action Plan — the difference between the two, prioritised by the
risk left open rather than by ease of closure.
- Implementation Tier Self-Assessment — Partial, Risk Informed, Repeatable and Adaptive,
assessed per dimension. The guide is explicit that Tiers are not maturity levels and Tier 4 is not the goal. Treating the Tiers as a ladder to climb is a misreading the guide addresses directly, because it produces spend disconnected from risk.
What changed from PF 1.0, and why it matters if you already have one
PF 1.1 realigns the Privacy Framework with NIST Cybersecurity Framework 2.0. The counts barely move — 100 Subcategories to 102 — which is misleading, because the structure was re-cut:
- GOVERN-P grew from 4 Categories to 7. New: Oversight (GV.OV-P), Roles, Responsibilities and
Authorities (GV.RR-P), and Data Processing Ecosystem Risk Management (GV.DE-P), which moved wholesale out of IDENTIFY-P.
- PROTECT-P was re-cut onto CSF 2.0 category names. PR.AC-P, PR.MA-P and PR.PT-P are gone;
PR.AA-P, PR.PS-P and PR.IR-P replace them.
- Four Categories no longer exist, and 34 Subcategory identifiers moved.
Map your old evidence across by identifier alone and a substantial part of it lands on the wrong outcome. The Transition Guide handles this, and it is explicit that you re-run the Current Profile rather than converting the old one arithmetically — the Categories were re-cut, so the honest answer may have changed.
CT.DM-P11, the Subcategory that speaks to automated decisions
New in PF 1.1, with no counterpart in PF 1.0: stakeholder privacy preferences must be included in algorithmic design objectives, and outputs evaluated against those preferences.
The NIST Privacy Framework Toolkit ships a procedure for it that tests for proxy inference — excluding an attribute from a model’s inputs does not stop the model inferring it from correlated features — alongside an Inference Limitation Standard covering the inference surface a system could reach, not only what it currently draws.
Worth knowing: ID.RA-P2, which related to artificial intelligence systems, is withdrawn in this draft. That does not put AI outside the Framework. An AI system performing data actions is assessed like any other, and CT.DM-P11 is where its algorithmic behaviour is addressed.
NIST Privacy Framework Toolkit structure
| # | Section | Documents |
|---|---|---|
| 00 | Programme Foundation | 7 |
| 01 | IDENTIFY-P | 22 |
| 02 | GOVERN-P | 39 |
| 03 | CONTROL-P | 21 |
| 04 | COMMUNICATE-P | 11 |
| 05 | PROTECT-P | 23 |
| 06 | Profiles and Implementation Tiers | 8 |
| 07 | Crosswalks | 6 |
| 08 | Assurance and Audit | 8 |
The NIST Privacy Framework Toolkit is 108 Word documents and 37 Excel workbooks. Sections 01 to 05 are the Framework’s five Functions, in NIST’s own order, so the pack is laid out the way an assessor reads it.
Eleven workbooks ship already filled in
They are not blank templates. Eleven of the 37 workbooks ship pre-loaded with all 102 Subcategories — Function, Category, identifier and the outcome text in full:
| Workbook | What it does |
|---|---|
| Privacy Framework Core Reference | The whole Core, plus the 34 moved and 2 withdrawn identifiers |
| Current Profile | Status and evidence per outcome, with an audit-tested column |
| Target Profile | Is-a-target, priority, rationale, and the risk or obligation driving it |
| Profile Gap Analysis | The gap, the risk left open, the action, the evidence of closure |
| Privacy Framework Audit Checklist | Audit question, method, evidence examined and limitation per outcome |
| Privacy Evidence Register | Every outcome pointed at the artefact that evidences it |
| Crosswalk to NIST CSF 2.0 | The realignment PF 1.1 was written to achieve |
| Crosswalk to NIST SP 800-53 Rev 5 | To the privacy control baseline |
| Crosswalk to ISO/IEC 27701 | Clause numbers and short names |
| Crosswalk to GDPR | Article-level |
| Crosswalk to US state privacy law | By statute and by recurring obligation theme |
All eleven are generated from one Subcategory set, so they cannot drift apart from each other or from the documents. Every crosswalk carries a relationship strength and a direction, and a Crosswalk Guide that states plainly that a mapping is not a claim of equivalence and must never be used as coverage evidence.
Every document names the outcomes it answers
All 102 Subcategories are covered, and the build fails if any one of them is left without a document — a check we run, not a claim we make. The same check rejects any document that claims a withdrawn or retired identifier.
List of Documentation Toolkit:
00 — Programme Foundation (7 documents)
- Toolkit Guide and Document Index.docx
- Privacy Framework Implementation Roadmap.docx
- Privacy Framework Scope and Boundary Statement.docx
- Privacy Programme Charter.docx
- Privacy Terms and Definitions Glossary.docx
- Privacy Framework Core Reference.xlsx
- PF 1.0 to PF 1.1 Transition Guide.docx
01 — IDENTIFY-P (22 documents)
- Data Processing Inventory Policy.docx
- Systems Products and Services Inventory.xlsx
- Data Owner and Operator Register.xlsx
- Categories of Individuals Register.xlsx
- Data Actions Inventory.xlsx
- Processing Purposes Register.xlsx
- Data Elements Catalogue.xlsx
- Data Processing Environment Register.xlsx
- Data Mapping Procedure.docx
- Data Map Template.xlsx
- Data Processing Ecosystem Role Statement.docx
- Mission and Privacy Objectives Statement.docx
- Priority Systems and Key Requirements Register.xlsx
- Ecosystem Parties Identification and Prioritisation Procedure.docx
- Stakeholder Expectations Analysis.docx
- Organisational Dependencies Register.xlsx
- Contextual Factors Analysis Procedure.docx
- Problematic Data Action Identification Procedure.docx
- Privacy Risk Assessment Methodology.docx
- Privacy Risk Register.xlsx
- Privacy Risk Response Plan.docx
- Ecosystem Party Privacy Risk Assessment Procedure.docx
02 — GOVERN-P (39 documents)
- Organisational Privacy Policy.docx
- Data Use and Retention Conditions Standard.docx
- Privacy by Design Procedure.docx
- Privacy in the System Development Life Cycle Standard.docx
- Privacy Legal and Regulatory Requirements Procedure.docx
- Legal and Regulatory Requirements Register.xlsx
- Privacy in Enterprise Risk Management Statement.docx
- Privacy in Human Resources Procedure.docx
- Privacy Risk Management Strategy.docx
- Privacy Risk Appetite and Tolerance Statement.docx
- Privacy Risk Response Options Standard.docx
- Privacy Risk Communication Plan.docx
- Privacy Risk Calculation and Prioritisation Method.docx
- Privacy Strategic Opportunity Register.xlsx
- Privacy Programme Management Review Procedure.docx
- Privacy Strategy Review Record.docx
- Privacy Performance Measurement Framework.docx
- Privacy Metrics and KPI Workbook.xlsx
- Privacy Leadership Accountability Statement.docx
- Privacy Roles and Responsibilities Matrix.xlsx
- External Stakeholder Privacy Coordination Procedure.docx
- Privacy Resource Allocation Plan.docx
- Data Processing Ecosystem Risk Management Strategy.docx
- Privacy Contract Clauses and Data Processing Agreement.docx
- Interoperability and Multi-Party Framework Procedure.docx
- Ecosystem Party Assessment and Audit Procedure.docx
- Ecosystem Party Assessment Workbook.xlsx
- Ecosystem Risk Integration Procedure.docx
- Privacy Awareness and Training Programme.docx
- Specialised Privacy Role Training Plan.docx
- Privacy Training Record Log.xlsx
- Privacy Risk Monitoring and Re-evaluation Procedure.docx
- Privacy Policy and Training Review Procedure.docx
- Privacy Compliance Assessment Procedure.docx
- Privacy Risk Progress Reporting Procedure.docx
- Problematic Data Action Disclosure Procedure.docx
- Privacy Lessons Learned Procedure.docx
- Individual Complaints and Enquiries Procedure.docx
- Complaints and Enquiries Log.xlsx
03 — CONTROL-P (21 documents)
- Data Processing Authorisation and Consent Policy.docx
- Consent and Authorisation Record Log.xlsx
- Data Review Transfer Alteration and Deletion Procedure.docx
- Individual Data Preferences and Requests Procedure.docx
- Data Life Cycle and SDLC Alignment Standard.docx
- Data Access for Review Procedure.docx
- Data Transmission and Disclosure Procedure.docx
- Data Alteration and Correction Procedure.docx
- Data Deletion Procedure.docx
- Data Destruction Policy and Certificate.docx
- Standardised Data Transmission Format Standard.docx
- Processing Permission Transmission Standard.docx
- Privacy Logging and Data Minimisation Standard.docx
- Technical Privacy Control Test Plan.docx
- Technical Control Test Results Workbook.xlsx
- Algorithmic Privacy Preference Evaluation Procedure.docx
- Disassociated Processing Standard.docx
- De-identification and Tokenisation Procedure.docx
- Inference Limitation Standard.docx
- Selective Collection and Disclosure Configuration Standard.docx
- Attribute Substitution Procedure.docx
04 — COMMUNICATE-P (11 documents)
- Privacy Transparency Policy.docx
- Privacy Communication Roles and Responsibilities.docx
- Privacy Notice Template Set.docx
- Data Processing Practices Public Report Template.docx
- Individual Feedback Mechanism Procedure.docx
- Data Processing Visibility Design Standard.docx
- Data Disclosure and Sharing Register.xlsx
- Correction and Deletion Notification Procedure.docx
- Data Provenance and Lineage Standard.docx
- Privacy Breach Notification Procedure.docx
- Privacy Breach Notification Letter Templates.docx
05 — PROTECT-P (23 documents)
- Data Protection Improvement Procedure.docx
- Privacy Incident Response and Recovery Plan.docx
- Privacy Incident Register.xlsx
- Identity and Credential Management Policy.docx
- Identity Proofing and Binding Procedure.docx
- Authentication Standard.docx
- Identity Assertion Protection Standard.docx
- Access Control and Least Privilege Policy.docx
- Physical Access Control Procedure.docx
- Data at Rest Protection Standard.docx
- Data in Transit Protection Standard.docx
- System and Data Life Cycle Management Procedure.docx
- Hardware and Software Integrity Assessment Procedure.docx
- Data in Use Protection Standard.docx
- Backup and Restoration Procedure.docx
- Configuration Management Standard.docx
- Software Maintenance and Removal Procedure.docx
- Hardware Maintenance and Removal Procedure.docx
- Unauthorised Software Prevention Standard.docx
- Network and Environment Protection Standard.docx
- Environmental Threat Protection Procedure.docx
- Resilience Requirements Standard.docx
- Capacity Management Procedure.docx
06 — Profiles and Implementation Tiers (8 documents)
- Privacy Framework Profiles Guide.docx
- Current Profile Workbook.xlsx
- Target Profile Workbook.xlsx
- Profile Gap Analysis and Action Plan.xlsx
- Implementation Tiers Assessment Guide.docx
- Implementation Tier Self-Assessment Workbook.xlsx
- Privacy and Cybersecurity Risk Relationship Guide.docx
- Privacy Programme Roadmap and Milestone Plan.xlsx
07 — Crosswalks (6 documents)
- Crosswalk Guide and Methodology.docx
- PF 1.1 to NIST CSF 2.0 Crosswalk.xlsx
- PF 1.1 to NIST SP 800-53 Rev 5 Crosswalk.xlsx
- PF 1.1 to ISO IEC 27701 Crosswalk.xlsx
- PF 1.1 to GDPR Crosswalk.xlsx
- PF 1.1 to US State Privacy Law Crosswalk.xlsx
08 — Assurance and Audit (8 documents)
- Privacy Programme Internal Audit Procedure.docx
- Privacy Audit Programme and Schedule.xlsx
- Privacy Framework Audit Checklist.xlsx
- Privacy Audit Report Template.docx
- Nonconformity and Corrective Action Procedure.docx
- Corrective Action Log.xlsx
- Management Review Meeting Pack Template.docx
- Privacy Evidence Register.xlsx
Frequently Asked Questions (FAQ)
What is the NIST Privacy Framework Toolkit?
The NIST Privacy Framework Toolkit is a set of 145 editable Microsoft Word and Excel templates for building and running a privacy program — 108 documents and 37 workbooks across nine sections, covering all 102 Subcategories of NIST Privacy Framework 1.1, together with Current and Target Profile workbooks, an Implementation Tier assessment, five crosswalks and a 102-point internal audit checklist.
Is NIST Privacy Framework 1.1 final?
No, and this matters. PF 1.1 is an Initial Public Draft — NIST CSWP 40 ipd, published 14 April 2025, comment period closed 13 June 2025. NIST has not announced a date for the final. PF 1.0, published 16 January 2020, is still the only final version. Describe your programme as aligned to the draft, never as compliant with it. The toolkit says this on every document, not just here.
Then why buy a toolkit built on a draft?
Because PF 1.1 is where the Framework is going, and it is aligned with CSF 2.0 — so if you already run a CSF 2.0 programme, the two share a vocabulary. Building to PF 1.0 today means adopting Protect-P categories that CSF 2.0 retired. The risk is that NIST renumbers the identifiers before final — so we built the pack so that a renumber is a data-file change and a rebuild, and shipped a transition guide that handles exactly this kind of remap.
Do I need to buy the Framework itself?
No. The NIST Privacy Framework is free. Download it from nist.gov/privacy-framework and read it alongside the toolkit — we encourage it. What you are buying here is the 145 documents you would otherwise write yourself, not access to the text.
Will this make us compliant with GDPR or CCPA?
No, and no toolkit can. The Privacy Framework is a voluntary risk management tool, not a law. It gives you the operating model through which statutory obligations are managed; the obligations themselves remain separate. The toolkit keeps that distinction visible — obligations live in their own register, and the GDPR and US state law crosswalks carry an explicit warning that a mapping is not evidence of compliance.
We already have ISO 27001. Is this duplication?
Very little of it. An information security management system manages unauthorised access and compromise. It does not surface over-retention, undisclosed inference, purpose drift or an automated decision an individual cannot challenge — those arise from processing that is fully authorised and perfectly secure, and a security review of them returns no finding. The toolkit ships a crosswalk to ISO/IEC 27701 so you can reuse the evidence you already hold, and a guide setting out exactly which risks your ISMS will and will not find.
How is this different from your GDPR or ISO 27701 toolkit?
GDPR is a law and that pack is built around its obligations. ISO/IEC 27701 is a certifiable management system standard. The NIST Privacy Framework is neither: it is a voluntary risk model, structured around outcomes rather than requirements, and it is the one that works across jurisdictions because it deliberately avoids the vocabulary of any single regime. Many organisations run this as the operating model and the others as obligation sets on top.
What formats are the documents in?
Microsoft Word (.docx) and Microsoft Excel (.xlsx) — 108 and 37 respectively. Every file is fully editable, unlocked and unprotected, ready to be rebranded and populated with your own information. The workbooks carry drop-down validation, frozen headers, autofilters and worked example rows flagged for deletion.
The documents use British spelling. Can I change it?
Yes — every file is unlocked and editable. The documents use British spelling (“programme”, “minimisation”, “organisation”) as a house convention across our catalogue. NIST’s own Subcategory text is reproduced verbatim and therefore keeps US spelling, so both appear in the pack. A find-and-replace handles it if your house style requires consistency.
How long does it take to deploy?
The Implementation Roadmap sets out seven stages, and it is explicit that you should not start with Protect-P. That section most resembles an existing security programme, which makes it the most tempting starting point and the least useful one — an organisation that begins there ends up with a security programme wearing privacy labels. Start with mandate and scope, then the inventory and data map, then risk, then the Current Profile.
What happens when PF 1.1 is finalised?
Updates are free for life. When NIST publishes the final we compare it against the draft Core, reissue the pack, and you download the new version at no charge. The Transition Guide already covers the method for remapping evidence if the identifiers change.
PCI-DSS Toolkit - Comprehensive 180+ Templates 




































Reviews
There are no reviews yet