Get Demo

NIST CSF 2.0 Protect Function: Access, Data, Platforms & Resilience

CSF 2.0 Protect (PR) Categories PR.AA–PR.IR — access, training, data, platform security.

Published: September 2026 Compliance · NIST CSF 2.0 8-10 min read

NIST's Protect outcome statement (CSWP 29): "Safeguards to manage the organization's cybersecurity risks are used." After assets and risks are known under Identify, Protect lowers the likelihood and impact of adverse events (and supports taking positive opportunities). Start from the CSF 2.0 guide or NIST hub.

What the Protect Function Covers

Identity, authentication, and access control; awareness and training; data confidentiality, integrity, and availability; platform (hardware, software, and services) security; and technology infrastructure resilience — including networks, capacity, and mechanisms for normal and adverse situations.

Protect Categories (Official CSF 2.0)

Source: NIST CSWP 29, Table 1 / Appendix A — 5 Categories.

ID
Category
Outcome (brief)
PR.AA
Identity Management, Authentication, and Access Control
Physical and logical access limited to authorized users, services, and hardware; managed commensurate with risk
PR.AT
Awareness and Training
Personnel receive awareness and training to perform cybersecurity-related tasks
PR.DS
Data Security
Data managed per risk strategy to protect confidentiality, integrity, and availability
PR.PS
Platform Security
Hardware, software, and services of physical and virtual platforms managed per risk strategy
PR.IR
Technology Infrastructure Resilience
Architectures managed to protect CIA and organizational resilience

Why Protect Matters

PR.AA replaces the retired PR.AC label — use 2.0 IDs in crosswalks. PR.PS (configuration, patching, logging, unauthorized software, secure SDLC) and PR.IR are where hardening and resilience meet continuous assurance. Protect outcomes are what CIS Benchmarks and identity programs often evidence against in dual-framework programs.

How CyberSilo Helps Operationalize Protect

Evidence Protect Outcomes Continuously

Tie access, platform hardening, and data safeguards to PR.AA–PR.IR with audit-ready evidence packs.

Frequently Asked Questions

Is PR.AC still valid in CSF 2.0?

No. CSF 1.1 PR.AC was replaced by Identity Management, Authentication, and Access Control (PR.AA) in CSF 2.0. Use PR.AA in crosswalks and Profiles.

Where do backups sit in Protect?

Data backups are covered under Data Security — for example PR.DS-11 (backups of data are created, protected, maintained, and tested) in CSWP 29 Appendix A.

How does Protect differ from Recover?

Protect uses safeguards to prevent or lower the likelihood and impact of adverse cybersecurity events. Recover restores assets and operations after a cybersecurity incident. Both should be planned under Govern and informed by Identify.

Govern · Identify · Detect · Respond · Recover

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!