NIST CSF 2.0PR.AT-1 → PR.AT-4 coverage 

NIST CSF awareness, evidenced.

NIST Cybersecurity Framework 2.0 puts awareness training under Protect (PR.AT). Cyber Aware covers all four PR.AT controls with auto-collected evidence - and exports a branded report mapped to every function your client's auditor cares about.

WHAT IS IT?

The US federal cybersecurity framework.

NIST Cybersecurity Framework 2.0 organises security into five functions - Identify, Protect, Detect, Respond, Recover. Cyber Aware is concentrated in Protect (PR.AT) - Awareness and Training - and contributes to Detect (DE.CM) and Respond (RS.CO).

ID

Identify

Risk identification. Pair with our gap assessment + dark web exposure scan.

PR

Protect

Awareness & training. Cyber Aware's core territory. Full PR.AT coverage.

DE

Detect

Report-a-phish events + phishing simulation results feed DE.CM-3.

RS

Respond

Communication of training breach. RS.CO-1 covered via our reporting plane.

RC

Recover

Lessons-learned modules deployed post-incident close the loop on RC.IM-1.

GV

Govern

Risk-score trend, exec reports, and policy attestations support GV.RR-1 reporting cadence.

DETAILED MAPPING

The four PR.AT controls.

PR.AT-01
All users are informed and trained.120+ Cyber Aware modules, baseline training auto-assigned via Auto Enrol, monthly cadence on each user's gap-analysis profile.
PR.AT-02
Privileged users understand their roles. Role-targeted training paths for administrators, developers, and finance teams - covering the elevated threats that target them.
PR.AT-03
Third-party stakeholders are informed. Sub-tenant branded portals let MSPs deliver consistent training to contractors and managed third parties.
PR.AT-04
Senior executives understand their roles. Executive-focused training paths (deepfake awareness, wire transfer fraud, BEC) + monthly exec-summary risk report.
REPORTING

Map your activity to NIST functions.

Branded control reports.

Auto-generated PDFs that group every training event under PR.AT-01 through 04 - ready for auditor consumption.

Risk tier alignment.

Maturity tiers Partial, Risk-Informed, Repeatable, Adaptive - mapped to your platform usage patterns.

Tier progression.

Track improvement quarter over quarter as training cadence and engagement deepens.

Profile templates.

Pre-built NIST Profile templates for SaaS, MSP, healthcare, finance - apply in one click.

Get audit-ready

One platform.
Every framework.

Spin up a fully branded compliance assessment portal under your name. Evidence collected automatically as learners complete training.