NIST Privacy Framework
NIST's voluntary framework for managing privacy risk through enterprise risk management. It is guidance, not a regulation or certification.
1.0 · National Institute of Standards and Technology · published 2020-01-16
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
NIST Privacy Framework is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Metadata only; the Privacy Framework core is not ingested, normalized, or released as a product module.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Identify-P · Govern-P · Control-P · Communicate-P · Protect-P
- Applies to
- all sectors · healthcare · technology · US · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-28
- Pending change
- NIST Privacy Framework 1.1 remains an Initial Public Draft; NIST lists the final version as coming soon. Version 1.0 remains the current final framework.Expected: Final version 1.1 pending
03Version ledger
| 1.0 | Current edition | 2020-01-16 |
06Related frameworks
- Shared Assessments SIG2026 annual release
Also applies to all sectors · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.
- HITRUST CSFv11.8.0
Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
- ISO/IEC 270182025
Also applies to technology · Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.
- ISO 223012019 (Amd 1:2024)
Also applies to all sectors · The certifiable business continuity management system standard for preparing for, responding to, and recovering from disruption. Tracking it does not claim that ControlFrame or any customer holds ISO 22301 certification.