Compliance
NIST CSF 2.0 with PuReAI
NIST CSF 2.0 asks what you own, what it is exposed to, and who else touches it. PuReAI answers all three from the outside, continuously, and keeps the evidence dated.
Where PuReAI fits
CSF 2.0 is voluntary but is the reference model most auditors and enterprise customers use to phrase their questions. The gaps that show up most are ID.AM asset inventory and GV.SC supply chain governance.
Requirement → module → evidence
Each row is a control or requirement, the PuReAI module that produces relevant signal, and the artefact you can put in front of an auditor.
| Requirement | Module | Evidence produced |
|---|---|---|
| GV.SC — Cybersecurity supply chain risk management | Supply Chain, News / Threats | Continuous vendor scoring, dated per-supplier findings, ransomware actor activity in your sector. |
| ID.AM-01/04 — Asset and service inventory | Domain, IP, Certificate, Technology | Discovered domains, subdomains, hosts, open services, TLS certificates and stack fingerprints. |
| ID.RA-01 — Vulnerabilities identified and recorded | Vulnerability | Findings matched against NVD and CISA KEV, each with severity, confidence and status. |
| PR.DS / PR.AA — Data and credential protection | Leaked Data, Git Leaks, Sensitive Files | Exposed credentials, committed secrets and indexed documents tied to your domain. |
| DE.CM-06 — External service provider monitoring | Supply Chain | Vendor score history, so degradation is visible between reviews rather than at renewal. |
| RS.MA — Incident management support | News / Threats, Threat graph | MITRE ATT&CK TTP context for the actor group active against your sector and stack. |
Scope and limits
- PuReAI is an external, unauthenticated view. It does not replace internal controls under PR.PS or DE.CM-01 — it evidences the outside-in half.
- Scores and findings export as dated records, which is what CSF profiles and current/target-state gap analyses need.
Questions we get asked
Does PuReAI make us NIST CSF compliant?
No tool does. CSF is a governance model, not a certification. PuReAI supplies continuous external evidence for the Identify, Detect and Govern outcomes that depend on knowing your exposed estate and your suppliers.
Which CSF function does PuReAI cover best?
Govern (GV.SC) and Identify (ID.AM, ID.RA) — supplier risk and external asset inventory are the two areas where internal tooling has no visibility by definition.
See the evidence for your own domain
Start with a free domain report, or read the full scoring methodology.