NIST CSF categories and subcategories, explained
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · NIST CSF
The functions are the headlines; the categories and subcategories are where the actual work lives. Understanding the structure is how you use the CSF.
The hierarchy
The CSF is organised in three levels. The six functions (Govern, Identify, Protect, Detect, Respond, Recover) are the top-level organisation. Each function contains categories — groups of related outcomes. Each category contains subcategories — the specific, granular outcomes. This nesting is how the framework goes from broad to actionable.
Subcategories are the unit of work
The subcategory is where you actually operate: each is a specific outcome statement (for example, an access-control or logging outcome) that you assess your state against in a profile. Your current and target profiles, and your gap assessment, are built at the subcategory level. The functions organise; the subcategories get assessed.
Outcomes, not controls
Crucially, subcategories describe outcomes to achieve, not prescriptive controls to implement. They say what good looks like and leave how to you — which is the source of the CSF's flexibility. The informative references then point to specific controls (in 800-53, ISO 27001, etc.) that help achieve each outcome.
Using the structure
In practice you work at the subcategory level — scoping which are relevant, assessing current state, and tracking toward target — while the functions and categories give you the organising map. SentinelPanda maps your controls to the CSF subcategories and tracks profile progress.