By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. Why CSF fits NHI well
  2. GOVERN, and why it matters here
  3. Mapping across the six functions
  4. Where PR.AA assumes humans
  5. Using a profile to scope
  6. FAQ

TL;DR

  • CSF 2.0 (February 2024) added GOVERN as a sixth function alongside Identify, Protect, Detect, Respond and Recover.
  • That matters for NHI specifically because the recurring failure is ownership and accountability, which had no natural home in CSF 1.1.
  • PR.AA: Identity Management, Authentication and Access Control. Is the densest category, and its subcategories are routinely implemented for human users only.
  • CSF is voluntary and not certifiable. Its value is as a common vocabulary and a scoping instrument, not as an obligation.
  • Use a Target Profile to scope an NHI programme. It converts "improve NHI governance" into a defensible list of subcategories with a current and target state.

Why CSF fits non-human identity better than most frameworks

Two reasons. It is outcome-based rather than control-based, so it accommodates an asset class its authors were not centrally thinking about. The outcomes still apply whether the identity belongs to a person or a workload. And it is widely understood across security, risk and executive audiences, which matters when the work has to be funded jointly by security and platform engineering.

Status

Ratified and voluntary. CSF 2.0 was published by NIST in February 2024. It is not certifiable and conformance is not assessed by anyone. Some sectors and contracts reference it; that is a contractual obligation rather than a regulatory one. See the standards tracker for tiering.

GOVERN, and why it matters here

The GOVERN function covers organisational context, risk management strategy, roles and responsibilities, policy, and oversight. It is the newest and, for non-human identity, the most consequential.

The reason is that NHI programmes fail predominantly on accountability rather than technique. Identities sit between identity management, platform engineering and security operations, and belong to none of them. Under CSF 1.1 that had no clean home; the framework asked whether you protected identities, not whose job it was. GOVERN gives the ownership question a place to be recorded, assessed and reported.

Concretely, the artefacts that belong here: a named owner for the NHI programme, a policy that explicitly addresses non-human accounts, a risk register entry with NHI-specific risks rather than a generic identity entry, and a reporting line into whichever forum receives security metrics. If you cannot name the person accountable for non-human identity, GOVERN is where that shows up first.

Mapping across the six functions

Our practical reading. CSF does not name non-human identities; this is where the work lands.

FunctionNHI workArtefact
GOVERNAccountability, policy, risk strategy for machine credentialsNamed programme owner; NHI-specific policy and risk register entries; reporting cadence
IDENTIFYInventory of non-human identities and what they reach; supplier-held credentialsDated inventory export with owner and reach; third-party grant register
PROTECTCredential issuance, scope, lifetime, rotation, authentication strengthLifetime distribution; rotation logs; least-privilege diff of granted versus exercised
DETECTMonitoring machine credential use; anomaly baselines that do not assume a humanDetection coverage per identity class; alerting on unexpected source or scope use
RESPONDContainment via revocation rather than network isolationMeasured revocation time; tested kill path. See agent incident response.
RECOVERReissuance at scale without outageEvidence of mass reissuance capability. Shared with certificate lifecycle work

RECOVER is the function most often left empty for NHI, and it is where the certificate-lifetime and post-quantum programmes supply evidence for free. If you can reissue an estate on a short cycle, you have a RECOVER story.

Where PR.AA quietly assumes human users

PR.AA, Identity Management, Authentication and Access Control, is the densest category for this work, and it is where implementations narrow without anyone noticing. Its subcategories cover identities being managed and credentials issued, identities proofed and bound, access permissions being defined and managed with least privilege and separation of duties, and physical and logical access being managed appropriately.

Every one of those applies to machine identities. In practice most are implemented against a human population, because the tooling that satisfies them (the joiner-mover-leaver workflow, the recertification campaign, the MFA policy) was built for people and was never extended.

The test: for each PR.AA subcategory, ask what your evidence would be if the auditor's population were service accounts, API keys and workload credentials rather than employees. Where the honest answer is "the same evidence, filtered", you are fine. Where it is "we would have to build that", you have found the gap.

Using a Target Profile to scope the programme

The most practical use of CSF here is not the mapping but the profile mechanism, because it solves a real problem: "improve non-human identity governance" is not a fundable statement.

  1. Select the subcategories that matter for your NHI risk, typically the GOVERN roles and policy items, ID.AM inventory items, the PR.AA and PR.DS protection items, and the RS containment items.
  2. Score current state honestly against each, using evidence you could produce today rather than intent.
  3. Set a target state and a date, and be explicit about what you are deliberately not addressing.
  4. Report the delta. A profile with fourteen scored subcategories, a current state, a target and a documented deferral list is a fundable artefact in a way that a maturity adjective is not.

This composes cleanly with our maturity model: the maturity model tells you which level you are at and what moves you; the CSF profile expresses that in vocabulary your board and your auditors already use.

Frequently asked questions

Does the NIST Cybersecurity Framework cover non-human identities?

Not by name, but the outcomes apply directly because CSF is outcome-based rather than control-based. The densest category is PR.AA covering identity management, authentication and access control, and NHI work also lands in ID.AM inventory, the protect subcategories on credentials and data, response containment, and, since CSF 2.0, the GOVERN function on accountability and policy.

What did CSF 2.0 add that matters for non-human identity?

The GOVERN function, published February 2024. It matters because NHI programmes fail predominantly on accountability rather than technique: identities sit between identity management, platform engineering and security operations and belong to none of them. GOVERN gives that ownership question a place to be recorded, assessed and reported, which CSF 1.1 did not have.

Is the NIST CSF certifiable?

No. It is a voluntary framework and conformance is not assessed by anyone. Some sectors and contracts reference it, which makes it a contractual rather than a regulatory obligation in those cases. Its value for non-human identity is as a shared vocabulary across security, risk and executive audiences, and as a scoping instrument through the profile mechanism.

How do you use a CSF profile to scope an NHI programme?

Select the subcategories that matter for your non-human identity risk, score current state against evidence you could produce today rather than against intent, set a target state with a date, and be explicit about what you are deliberately not addressing. The output is a scored list with a current state, a target and a documented deferral list, which is fundable in a way that a general commitment to improve governance is not.

Which CSF function is usually empty for non-human identity?

RECOVER. Most organisations have some inventory, some protection and some detection for machine credentials, and nothing at all for reissuing an estate at scale after a compromise. This is also the easiest gap to close indirectly, because the certificate-lifetime and post-quantum migration programmes build exactly that capability and supply the evidence for free.

Mapping NHI controls to a framework you are held to?

HumanAudit runs framework-mapping and readiness work where non-human and agent identity is in scope, and tests what you could actually produce on request rather than what the policy says.