CSF 2.0 Informative References
Informative References help inform how an organization may achieve the Core’s outcomes. The CSF 2.0 Informative References Quick-Start Guide introduces readers to NIST tools available for accessing, viewing, and using informative references for cybersecurity risk management, including direct download, the CSF 2.0 Reference Tool, and the Online Informative References Program. The document also provides two sample use cases along with examples of how artificial intelligence (AI) tools can support reference data use when implemented with continuous evaluation and improvement. Download CSF 2.0 Informative Reference in the Core
Directly download all the Informative References for CSF 2.0
For users that want all informative references.
Download English (xlsx)
Download Translations (xlsx)
Select Informative References to be included with the Core
For users that want to select specific informative references.
Browse
Informative Reference Catalog
Browse and download specific informative references
Catalog
Compare Informative References
Generate, view and download Comparison Reports between CSF 2.0 Informative References
Comparison Reports
Recent Additions
Informative references are developed by NIST and non-NIST entities. NIST conducts limited conformance testing of OLIR submission to IR 8278A, Revision 1. NIST does not conduct correctness testing on non-NIST submitted mappings, and the listing for non-NIST mappings in the catalog does not imply NIST endorsement. NIST publishes each informative reference submission for a 30-day public comment period prior to publishing it as final. For additional context regarding unilateral mappings and NIST’s role, please refer to Section 2.3.1 of NISTIR 8278 Revision 1.
Created February 15, 2024, Updated August 25, 2026