Skip to main content
Framework library
Framework module · nist-privacy-framework

NIST Privacy Framework

NIST's voluntary framework for managing privacy risk through enterprise risk management. It is guidance, not a regulation or certification.

1.0 · National Institute of Standards and Technology · published 2020-01-16

Standing today
Directory entry

00Answer

from the registry record
What is NIST Privacy Framework?
NIST's voluntary framework for managing privacy risk through enterprise risk management. It is guidance, not a regulation or certification.
Who does NIST Privacy Framework apply to?
NIST Privacy Framework applies to all sectors, healthcare, technology, US, global, per National Institute of Standards and Technology.
What is the current version of NIST Privacy Framework?
The current edition is 1.0, issued by National Institute of Standards and Technology and published 2020-01-16. Source: https://www.nist.gov/privacy-framework/privacy-framework.
What does an assessment under NIST Privacy Framework require?
No control catalog has been ingested for NIST Privacy Framework yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

NIST Privacy Framework is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Metadata only; the Privacy Framework core is not ingested, normalized, or released as a product module.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Identify-P · Govern-P · Control-P · Communicate-P · Protect-P
Applies to
all sectors · healthcare · technology · US · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28
Pending change
NIST Privacy Framework 1.1 remains an Initial Public Draft; NIST lists the final version as coming soon. Version 1.0 remains the current final framework.Expected: Final version 1.1 pending

03Version ledger

1 edition
1.0Current edition2020-01-16

06Related frameworks

scored from registry facts
  1. Shared Assessments SIG2026 annual release

    Also applies to all sectors · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.

  2. Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

  3. Also applies to technology · Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.

  4. ISO 223012019 (Amd 1:2024)

    Also applies to all sectors · The certifiable business continuity management system standard for preparing for, responding to, and recovering from disruption. Tracking it does not claim that ControlFrame or any customer holds ISO 22301 certification.

NIST Privacy Framework | ControlFrame