NIST CSF 2.0PCI DSS v4.0

CSF 2.0 RS.MI-01 → PCI DSS v4.0

4 mapped controls · identifier-only informative references · Respond function · one implementation can answer several obligations at once.

PCI DSS v4.0RelationshipSource tier
12.10.1relatedTier A2
5.2.1relatedTier A2
5.2.2relatedTier A2
5.3.2relatedTier A2

What evidence answers both

Assessors working from either framework ask for the same thing against RS.MI-01: exercise and execution artifacts - the incident procedure with its revision date, tabletop or live-incident records including timings, communication logs, and post-incident review output with assigned actions. A PCI DSS assessor scopes to the cardholder data environment first, so the same artifact can satisfy a requirement inside scope and be irrelevant outside it - the mapping tells you where to look, not whether you are in scope. Keeping one dated evidence register per control means a single artifact answers both frameworks instead of being produced twice.

AxiomLensStop redoing this mapping by hand.
AxiomLens is a GRC command deck you own outright. One-time license, per user — activate once, then it runs fully offline on your machine: your own database, 106 CSF 2.0 subcategories, computed coverage, evidence tied to controls, and board reports generated locally. It supports compliance documentation and audit-preparation workflows — it is a tool, not a certification or an assessment.

See AxiomLens →  ·  2-minute demo
Bayou Bytes
One email each Tuesday: the week’s threats that matter, one copy-paste hardening step, and the script to explain it to a non-technical stakeholder. Free, no pitch.
The Security Gator
© The Security Gator LLC · These mappings are informative references and a practical starting point — not a compliance determination, audit opinion, or legal advice. Mapping strength varies by environment; review and adapt every mapping to your organization and obligations with a qualified professional. · Source: NIST CSF 2.0 Informative References (CPRT/OLIR). Identifiers only — no copyrighted standard text is reproduced. Framework names and control identifiers are the property of their respective owners. · thesecuritygator.com