# NIST CSF 2.0 for Procurement: A 106-Subcategory Vendor Lifecycle Mapping

> An original census of all 106 NIST CSF 2.0 subcategories and 363 official implementation examples, mapped to procurement stages and buyer evidence classes.

- Canonical page: https://mtfinstitute.com/insights/nist-csf-2-procurement-106-subcategory-mapping-august-2026/
- Content type: Article
- Editorial category: Research &amp; Reports
- Publisher: MTF Institute of Management, Technology and Finance
- Author: MTF Institute Editorial Team- Published: 2026-08-18
- Updated: 2026-08-18
- Language: English
- Topics: Procurement, Research Reports, Vendor Risk Management, NIST CSF 2.0, Cybersecurity Supply Chain

## NIST CSF 2.0 for Procurement: A 106-Subcategory Vendor Lifecycle Mapping

**MTF Research Report MTF-RR-2026-08-18-01**  
**Publication date:** 18 August 2026  
**Author:** MTF Institute Editorial Team  
**Reviewer:** [Igor Dmitriev](https://mtfinstitute.com/about/faculty/igor-dmitriev/)  
**Institution:** MTF Institute  
**DOI:** [10.5281/zenodo.21992313](https://doi.org/10.5281/zenodo.21992313)

**Research files:** [Searchable PDF](https://zenodo.org/records/21992313/files/MTF-RR-2026-08-18-01.pdf?download=1) · [Supporting data workbook](https://zenodo.org/records/21992313/files/MTF-RR-2026-08-18-01-supporting-data.xlsx?download=1)

## Abstract

Procurement security is often compressed into a pre-contract questionnaire, even though supplier exposure continues through requirements, contracting, onboarding, monitoring, incident response, recovery and exit. To test how a complete cybersecurity framework can support that lifecycle, MTF Institute analysed the full set of 106 subcategories in the NIST Cybersecurity Framework 2.0 and all 363 implementation examples in NIST&#039;s official workbook, captured on 18 August 2026.

The census was coded into one primary procurement action and one primary buyer evidence class per subcategory. Twenty-three subcategories mapped to governance and requirements, nine to scoping and supplier tiering, ten to pre-contract due diligence, 23 to contracting and onboarding, 17 to continuous assurance, 23 to incident and recovery, and one to exit and transition. Only 36 of 106 subcategories (34.0%) explicitly referenced suppliers, third parties, partners or related external dependencies in the outcome or implementation examples. Fourteen (13.2%) explicitly referenced a contract or agreement.

The practical implication is not that every supplier must answer 106 questions. It is that a procurement control system should draw a risk-tiered evidence set from the whole lifecycle rather than treating supplier security as a one-time document collection exercise. This report provides a seven-gate model and a row-level supporting workbook for adapting that logic.

## Research question

How can the complete set of NIST CSF 2.0 subcategories be translated into a procurement-oriented vendor lifecycle, and what does that mapping reveal about where buyers should request evidence?

The report analyses the framework&#039;s structure and implementation examples. It does not evaluate a supplier, measure the prevalence of controls in industry or create a NIST-endorsed procurement standard.

## Scope and source selection

The unit of analysis is one NIST CSF 2.0 subcategory. The source universe is the official [NIST CSF 2.0 implementation examples workbook](https://www.nist.gov/document/csf-20-implementation-examples-xlsx), captured on 18 August 2026.

The source contains:

- 106 distinct subcategories;
- 22 categories;
- six functions: Govern, Identify, Protect, Detect, Respond and Recover;
- 363 implementation examples.

This is a full census of the official subcategories in the captured workbook, not a sample. No subcategory was excluded. Blank continuation rows in the spreadsheet were associated with the preceding subcategory during parsing.

## Coding method

Each subcategory received four analytical fields:

1. **Primary procurement action.** One of seven lifecycle stages: governance and requirements; scope and tier; pre-contract due diligence; contract and onboarding; continuous assurance; incident and recovery; exit and transition.
2. **Primary evidence class.** A buyer-facing evidence domain aligned to the NIST category, such as supply-chain risk governance, identity and access control, incident communications or recovery validation.
3. **Explicit-reference flags.** Deterministic keyword tests across the subcategory and its implementation examples for supplier/third-party language, contract/agreement language and requirement/legal/regulatory language.
4. **Buyer evidence prompt.** An MTF-created request that turns the outcome into a starting question for procurement design.

The lifecycle assignment and evidence prompts are MTF analytical interpretations. They are not official NIST mappings. One primary stage was assigned for comparability even when a subcategory could support several stages. The supporting workbook preserves the original subcategory wording, examples, source row and code so readers can inspect or recode every decision.

## Results

### Distribution across NIST CSF 2.0 functions

| Function | Subcategories | Share |
|---|---:|---:|
| Govern | 31 | 29.2% |
| Protect | 22 | 20.8% |
| Identify | 21 | 19.8% |
| Respond | 13 | 12.3% |
| Detect | 11 | 10.4% |
| Recover | 8 | 7.5% |
| **Total** | **106** | **100.0%** |

The Govern function is the largest. For procurement, that matters because supplier security is not only a technical-control question. It includes context, risk appetite, accountability, policy, oversight and supply-chain governance before technical evidence is requested.

### Primary procurement lifecycle mapping

| Primary procurement action | Subcategories | Share |
|---|---:|---:|
| Governance and requirements | 23 | 21.7% |
| Scope and tier | 9 | 8.5% |
| Pre-contract due diligence | 10 | 9.4% |
| Contract and onboarding | 23 | 21.7% |
| Continuous assurance | 17 | 16.0% |
| Incident and recovery | 23 | 21.7% |
| Exit and transition | 1 | 0.9% |
| **Total** | **106** | **100.0%** |

Only ten subcategories were assigned primarily to pre-contract due diligence. Sixty-three were assigned across contract/onboarding, continuous assurance, incident/recovery and exit. This does not mean due diligence is unimportant. It shows why a questionnaire alone cannot carry the complete lifecycle.

### What the framework states explicitly

| Explicit wording in the subcategory or implementation examples | Count | Share |
|---|---:|---:|
| Supplier, third party, partner or comparable external dependency | 36 | 34.0% |
| Contract or agreement | 14 | 13.2% |
| Requirement, legal or regulatory language | 17 | 16.0% |

These flags describe wording, not applicability. A subcategory can be highly relevant to a purchased service without naming a supplier. For example, access management, logging, recovery testing and secure configuration can all become supplier evidence requirements when the service boundary makes them material.

### Evidence classes buyers should not collapse

The mapping produced 22 evidence classes, corresponding to the framework&#039;s 22 categories. The largest are:

| Evidence class | Subcategories | Typical buyer use |
|---|---:|---|
| Supply-chain risk governance | 10 | Supplier strategy, criticality, requirements, monitoring and lifecycle planning |
| Risk assessment and testing | 10 | Threat, vulnerability, impact and validation evidence |
| Risk method and decisions | 7 | Risk appetite, prioritisation, escalation and response choices |
| Asset, service and data inventory | 7 | Purchased-service boundary and dependency visibility |
| Identity and access control | 6 | Authentication, privileges, identity proofing and access review |
| Platform and software assurance | 6 | Configuration, maintenance, software practice and lifecycle risk |
| Event analysis and incident criteria | 6 | Triage, correlation, impact and incident declaration |
| Recovery execution and validation | 6 | Restoration order, integrity and return-to-operation evidence |

The remaining 14 evidence classes contain between two and five subcategories each. Their smaller size does not imply lower importance; incident communications, data protection and training can be mandatory for a particular service even when they occupy fewer rows.

## Five findings for procurement leaders

### 1. Requirements design is a governance activity

Govern accounts for 31 of 106 subcategories. Buyers therefore need a clear business context, risk appetite and responsibility model before selecting supplier questions. A generic questionnaire without an assurance tier can produce large evidence volumes while leaving the most important decision undefined.

### 2. Supplier-specific language is a minority of the framework

Only 36 subcategories explicitly reference suppliers or related external dependencies in the outcome or examples. Procurement teams that search only for the word “supplier” will miss control outcomes that become material when delivered by a third party.

The correct translation question is: **Which business outcome depends on this service, and what evidence would show that the supplier can support it?**

### 3. Contracting is a control-transfer point

Fourteen subcategories explicitly reference a contract or agreement. The analytical mapping assigns 23 subcategories primarily to contracting and onboarding because this is where a buyer turns evaluated capability into enforceable obligations, implementation tasks, responsibility boundaries and evidence cadence.

A supplier answer that never reaches the contract or onboarding plan remains an assurance statement, not an operating commitment.

### 4. Monitoring, response and recovery deserve equal design attention

Continuous assurance accounts for 17 mapped subcategories and incident/recovery for 23. Buyers should decide before award:

- what evidence will recur;
- which material changes trigger reassessment;
- how incidents will be declared and communicated;
- who preserves evidence and coordinates containment;
- how recovery objectives will be tested and confirmed.

These questions are difficult to negotiate after an incident begins.

### 5. Exit is underrepresented as a primary mapping

Only one subcategory was assigned primarily to exit and transition under the one-stage coding rule. Exit considerations also appear indirectly in inventory, resilience, data and supply-chain outcomes. Procurement teams should not interpret the single row as evidence that exit is unimportant. It is a prompt to add explicit data return, deletion, access removal, portability and transition requirements to the buyer&#039;s own lifecycle.

## Practical application: the seven-gate vendor lifecycle

Do not send all 106 rows to every supplier. Use the complete mapping as a control library, then select a proportionate evidence set through seven gates.

### Gate 1 — Business dependency

Define the process, service outcome, data, users, jurisdictions and failure consequence. If the business dependency is unclear, the security review cannot be proportionate.

### Gate 2 — Supplier tier

Score five dimensions from 0 to 2:

| Dimension | 0 | 1 | 2 |
|---|---|---|---|
| Data sensitivity | Public or none | Internal | Restricted, personal or regulated |
| System access | None | Standard integration | Privileged or production access |
| Operational dependency | Easily replaced | Material disruption | Critical service interruption |
| Concentration | Multiple substitutes | Some dependency | Single/complex dependency |
| External obligation | No special duty | Contractual expectation | Regulatory or legal consequence |

A total of 0-3 supports a light evidence set; 4-7 supports a standard review; 8-10 supports enhanced assurance. These thresholds are a starting rule, not a legal or regulatory classification.

### Gate 3 — Evidence selection

Select only subcategories connected to the service boundary and risk tier. For each, define:

- observable supplier evidence;
- recency and scope;
- evaluation owner;
- pass, score or exception treatment.

The [supporting workbook](https://zenodo.org/records/21992313/files/MTF-RR-2026-08-18-01-supporting-data.xlsx?download=1) provides one starting prompt per subcategory. Buyers should rewrite it for the service rather than copy it unchanged.

### Gate 4 — Decision and exception

Record whether the evidence meets the requirement. For each gap, document the consequence, compensating control, owner, due date and residual-risk acceptance. Do not allow a high average score to conceal a mandatory failure.

### Gate 5 — Contract and onboarding

Move winning commitments into the security schedule, implementation plan, service levels, responsibility matrix or documented exception. Confirm subprocessors, access, logging, notification, recovery and deletion responsibilities before go-live.

### Gate 6 — Continuous assurance

Set evidence frequency based on risk and volatility. Use material-change triggers — acquisition, subprocessor change, major architecture change, serious incident, control lapse or regulatory change — rather than relying only on an annual calendar.

### Gate 7 — Incident, recovery and exit

Agree communication routes, decision rights, preservation duties, recovery validation and transition actions while operations are normal. Test critical relationships and retain evidence that access and data were removed when the service ends.

## A 12-row executive dashboard

The full control library belongs in the working system. Executives need a shorter view:

| Measure | Decision it supports |
|---|---|
| Critical suppliers with current tier | Is the population scoped? |
| Reviews completed before award | Is sourcing governance operating? |
| Mandatory gaps still open | Are critical exceptions visible? |
| Exceptions past due | Is risk acceptance becoming permanent? |
| Critical contracts with security schedule | Did assurance reach the agreement? |
| Suppliers with current subprocessor inventory | Are dependencies visible? |
| Required recurring evidence received | Is continuous assurance operating? |
| Material changes awaiting review | Is the control system responsive? |
| Incidents notified within agreed time | Are communication commitments working? |
| Critical recovery exercises completed | Can services recover as planned? |
| Exits with verified access removal | Is termination controlled? |
| Concentration exposures above appetite | Is portfolio risk understood? |

The dashboard should link back to row-level evidence and named owners. A green summary without traceability is not assurance.

## Limitations

This report is a dated analytical mapping of the official workbook captured on 18 August 2026. It does not measure supplier performance, control effectiveness or adoption in any industry. The lifecycle stages, evidence classes and buyer prompts are MTF interpretations and have not been endorsed by NIST.

Keyword flags are descriptive. They can miss concepts expressed without the selected terms and can count a reference that is contextual rather than prescriptive. One primary lifecycle stage per subcategory simplifies outcomes that can apply at several points. The report does not replace the full NIST publications, contract drafting, professional cybersecurity assessment or legal advice.

## Data and references

- [NIST Cybersecurity Framework 2.0](https://doi.org/10.6028/NIST.CSWP.29)
- [NIST CSF 2.0 implementation examples workbook](https://www.nist.gov/document/csf-20-implementation-examples-xlsx)
- [NIST SP 800-161 Rev. 1 Update 1: Cybersecurity Supply Chain Risk Management Practices](https://doi.org/10.6028/NIST.SP.800-161r1-upd1)
- [MTF: Security Requirements in an RFP](https://mtfinstitute.com/insights/security-requirements-rfp-procurement-control-matrix/)
- [MTF: Procurement Information Security](https://mtfinstitute.com/insights/procurement-information-security-vendor-due-diligence-framework/)

## Turn the mapping into an operating system

The practical value of the 106-row mapping is not a longer questionnaire. It is a traceable chain from business dependency to supplier tier, selected evidence, documented decision, contractual commitment, recurring assurance and controlled exit.

MTF Institute&#039;s [Executive Certificate in Enterprise Risk Management and Business Continuity](https://mtfinstitute.com/programs/enterprise-risk-management-business-continuity/) covers enterprise risk, cyber risk, operational resilience and continuity through text-based learning and practical cases. Professionals can use the seven-gate lifecycle and supporting workbook as a starting artifact for applying those concepts to supplier governance. It is a professional certificate program, not an academic degree.


## Citation

When citing or summarizing this material, link to the canonical HTML page: https://mtfinstitute.com/insights/nist-csf-2-procurement-106-subcategory-mapping-august-2026/
