NIST framework reference

NIST framework reference

The NIST Cybersecurity Framework 2.0 and AI Risk Management Framework 1.0, searchable, in NIST's own words.

The framework text comes from NIST's own exports, downloaded on 6 October 2026: the CSF 2.0 Core with its implementation examples, without the CSF 1.1 legacy elements, and the AI RMF 1.0 with the AI RMF Playbook. See the sources and counts.

Spelling: American spellings in the NIST Cybersecurity Framework (CSF) 2.0 and AI RMF 1.0 text have been changed to British English, for example organisation, authorise and behaviour. The National Institute of Standards and Technology name, function names, tier names and identifiers are unchanged.

NIST AI Risk Management Framework (AI RMF 1.0)

Open a function, then select a category to see its subcategories and the AI RMF Playbook's suggested actions.

Return to menu

Sources and counts

The text of every element shown is NIST's own, taken from the exports listed below. Only American spellings have been changed to British English, by a fixed word table, and the CSF 1.1 legacy elements in the CSF 2.0 export are left out. Times are Europe/London.

Sources

Counts

FrameworkFunctionsCategoriesSubcategoriesExamplesNotes
CSF 2.0622106363 implementation examples91 CSF 1.1 legacy elements removed from the NIST export (12 categories, 79 subcategories marked withdrawn, moved or incorporated into CSF 2.0 elements).
AI RMF 1.041972462 Playbook suggested actionsFirst level actions only; nested points are listed under the action they belong to.

Return to menu