IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

The 22 CyberFundamentals Control Categories Explained

CyberFundamentals 2025 organises security measures into 22 control categories across six functions. How many apply depends on your level: 17 at Basic, 20 at Important, 22 at Essential. Each category addresses a specific aspect of cybersecurity. Here's what they cover and why they matter.

Interlocking gears - systematic security controls
The 22 control categories work together as one system

The NIST Framework Structure

CyberFundamentals 2025 follows the six core functions of NIST CSF 2.0. GOVERN is the one CSF 1.1 did not have, and it carries 40 of the 218 controls at Essential level: Learn more about what CyberFundamentals is and how it works.

Govern: Decide who is accountable and what the rules are Identify: Know what you have and your risks Protect: Safeguard your assets Detect: Find security events Respond: Take action on incidents Recover: Restore normal operations

The 22 Categories

GV.OC

Organisational Context

Govern

1 Basic / 6 Important / 9 Essential

What the business actually does, and which legal duties come with it.

Why it matters: Without it you cannot say which systems are critical, so every control spend becomes arguable.

Examples:

  • • A written mission and the services it depends on
  • • The legal and regulatory obligations you are subject to
  • • The critical systems whose failure stops the business
GV.RM

Risk Management Strategy

Govern

1 Basic / 6 Important / 6 Essential

How the organisation decides which risks it accepts, and who signs that off.

Why it matters: An auditor asks what your risk appetite is. Without a written answer, every later decision looks arbitrary.

Examples:

  • • A risk appetite statement approved by management
  • • A documented risk management process
  • • Risks recorded with an owner and a treatment
GV.RR

Roles, Responsibilities and Authorities

Govern

1 Basic / 5 Important / 7 Essential

Who is accountable for security, and what they are allowed to decide.

Why it matters: Under NIS2 management is personally accountable, so the names have to be written down.

Examples:

  • • A named security owner, not a role in the abstract
  • • Security duties in job descriptions
  • • A joiner, mover and leaver process
GV.PO

Policy

Govern

1 Basic / 2 Important / 2 Essential

The written security policy, approved, current, and actually circulated.

Why it matters: A policy nobody approved or read scores as a draft, which is to say as nothing.

Examples:

  • • A policy with an approval date and an approver
  • • Evidence it was communicated to staff
  • • A review cycle that has actually run
GV.OV

Oversight

Govern

- Basic / - Important / 2 Essential

Management checking that the security strategy still matches the risks.

Why it matters: Essential level only. It is the difference between having a strategy and steering by it.

Examples:

  • • Management review minutes with decisions
  • • Security performance reported to the board
  • • Strategy adjusted after a review
GV.SC

Cybersecurity Supply Chain Risk Management

Govern

- Basic / 4 Important / 14 Essential

What you require of suppliers, in writing, and how you check they deliver it.

Why it matters: The largest category at Essential, with 14 controls, and where NIS2 pushes obligations down the chain.

Examples:

  • • Security requirements written into contracts
  • • A supplier register with a risk rating
  • • Breach notification clauses you can point to
ID.AM

Asset Management

Identify

5 Basic / 19 Important / 28 Essential

A current list of the hardware, software, services and data you actually run.

Why it matters: You cannot protect what you have not written down, and auditors start here.

Examples:

  • • Hardware and software inventories that are dated
  • • A list of every external service you use
  • • Owners assigned to critical assets
ID.RA

Risk Assessment

Identify

2 Basic / 11 Important / 15 Essential

Finding the weaknesses that matter, and deciding what to do about each.

Why it matters: This is where your CyFun level comes from, so it is the one you cannot skip.

Examples:

  • • Vulnerability scans with dated results
  • • A risk register linked to assets
  • • Remediation decisions with deadlines
ID.IM

Improvement

Identify

1 Basic / 8 Important / 12 Essential

What you learned last time, actually changing how you work.

Why it matters: New in CSF 2.0. It is what separates a live management system from a folder of documents.

Examples:

  • • A tabletop exercise with a written outcome
  • • Lessons learned after a real incident
  • • Tests run together with suppliers
PR.AA

Identity Management, Authentication and Access Control

Protect

8 Basic / 15 Important / 26 Essential

Who can get in, and whether you can prove you took it away again.

Why it matters: The biggest category at Basic, with 8 of its 34 controls, and the first thing an auditor asks for.

Examples:

  • • MFA on remote access and critical systems
  • • No administrative rights for daily work
  • • Timestamped proof that leavers lost access
PR.AT

Awareness and Training

Protect

1 Basic / 6 Important / 7 Essential

Making sure people know what is expected of them, and proving they were told.

Why it matters: Training without an attendance record is not evidence, it is an intention.

Examples:

  • • Training records showing who completed what
  • • Phishing simulations with results
  • • Signed acknowledgement of the policy
PR.DS

Data Security

Protect

2 Basic / 7 Important / 15 Essential

Data stays private and unaltered, at rest and in transit.

Why it matters: Backups live here, and a backup you have never restored is a theory.

Examples:

  • • Encryption at rest and in transit
  • • Backups that have been restore-tested
  • • A record of where sensitive data lives
PR.PS

Platform Security

Protect

2 Basic / 10 Important / 18 Essential

Systems hardened and patched, with logging switched on.

Why it matters: Logging sits here, and logs are the evidence every other control leans on.

Examples:

  • • A patch process with timing targets
  • • Hardened baseline configurations
  • • Logs kept, reviewed and retained
PR.IR

Technology Infrastructure Resilience

Protect

2 Basic / 6 Important / 13 Essential

Network and physical protections, and the capacity to keep running.

Why it matters: Firewalls and segmentation live here, and segmentation is where audits commonly find gaps.

Examples:

  • • Firewalls installed and actively maintained
  • • Network segmentation for critical systems
  • • Physical access controls to server rooms
DE.AE

Adverse Event Analysis

Detect

1 Basic / 5 Important / 8 Essential

Turning raw signals into a judgement about whether something is actually wrong.

Why it matters: Alerts nobody correlates are noise, and noise is what auditors treat as no detection at all.

Examples:

  • • Logging enabled on protection tools
  • • Events correlated across sources
  • • A defined threshold for declaring an incident
DE.CM

Continuous Monitoring

Detect

3 Basic / 9 Important / 14 Essential

Watching for trouble across networks, endpoints and the suppliers you depend on.

Why it matters: Anti-malware and endpoint monitoring are Basic-level controls, not advanced ones.

Examples:

  • • Anti-malware deployed and updated
  • • Endpoint and network monitoring in place
  • • External service providers monitored too
RS.MA

Incident Management

Respond

1 Basic / 5 Important / 6 Essential

Running the incident response plan when something actually happens.

Why it matters: NIS2 sets reporting clocks, so the plan has to name who starts them.

Examples:

  • • An incident response plan with named roles
  • • Incidents categorised and prioritised
  • • Evidence the plan was executed
RS.AN

Incident Analysis

Respond

- Basic / - Important / 4 Essential

Working out what happened, and keeping the proof intact while you do.

Why it matters: Essential level only, and the part most organisations discover they cannot do mid-incident.

Examples:

  • • Forensic evidence preserved with integrity
  • • Root cause established and recorded
  • • Incident records kept for the retention period
RS.CO

Incident Response Reporting and Communication

Respond

1 Basic / 2 Important / 2 Essential

Telling the people and authorities who have to be told, on time.

Why it matters: This is where the NIS2 24-hour early warning obligation actually lands.

Examples:

  • • A contact list for authorities and customers
  • • Reporting deadlines written into the plan
  • • Proof a notification was actually sent
RS.MI

Incident Mitigation

Respond

- Basic / 2 Important / 2 Essential

Stopping the spread.

Why it matters: Two controls, and the ones that decide whether an incident stays small.

Examples:

  • • A documented containment step
  • • Isolation of affected systems
  • • Eradication confirmed before recovery
RC.RP

Incident Recovery Plan Execution

Recover

1 Basic / 3 Important / 4 Essential

Getting back to normal operation, in a known order, from clean backups.

Why it matters: Recovery is the control most often assumed and least often tested.

Examples:

  • • A recovery plan with restoration order
  • • Restores verified before going live
  • • Recovery time objectives that are written down
RC.CO

Incident Recovery Communication

Recover

- Basic / 2 Important / 4 Essential

Telling staff, customers and authorities that service is back, and what happened.

Why it matters: The final NIS2 report closes here, and a missed final report is a reportable failure.

Examples:

  • • A communication plan for recovery
  • • The NIS2 final report submitted
  • • Stakeholders told service is restored

Controls by Tier

Each tier builds on the previous one: See the full level comparison.

Basic 34 17 of 22 categories
Important 133 20 of 22 categories
Essential 218 All 22 categories

Implementation Approach

Work through categories systematically: These controls map directly to NIS2 requirements, and successful implementation can lead to official certification.

  1. 1 Start with the Basic tier controls - they're foundational
  2. 2 Within each category, implement basic controls first
  3. 3 Build evidence and documentation as you go
  4. 4 Progress to advanced controls as resources allow
  5. 5 Review and improve continuously

Need Help with Implementation?

Easy Cyber Protection guides you through each control category with clear tasks, evidence templates, and progress tracking.

Frequently Asked Questions

Do I need to implement all categories?

Not at Basic. Basic has controls in 17 of the 22 categories. Supply Chain Risk Management (GV.SC), Incident Mitigation (RS.MI) and Incident Recovery Communication (RC.CO) start at Important (20 categories). Oversight (GV.OV) and Incident Analysis (RS.AN) start at Essential (all 22). Within each category, the depth grows with the level.

Which categories are most important?

At Basic, the framework puts the most controls in Identity Management, Authentication and Access Control (PR.AA, 8 of the 34) and Asset Management (ID.AM, 5). But all categories work together: a gap in one area can undermine the others.

How do categories relate to NIS2 requirements?

CyberFundamentals categories map directly to NIS2 Article 21 requirements. Implementing CyberFundamentals at the appropriate tier demonstrates NIS2 compliance.

Can I focus on certain categories first?

Yes. Start where Basic puts most of its controls: PR.AA (8), ID.AM (5) and Continuous Monitoring (DE.CM, 3). Together they hold 16 of the 34 Basic controls.

How are controls within categories prioritized?

The CCB framework assigns controls to tiers based on importance and effort. Basic tier has the foundational controls. Each subsequent tier adds more advanced measures.

Related Articles