Frameworks · NIST CSF 2.0

Six functions, evidenced.

The Cybersecurity Framework 2.0 organizes outcomes into six Functions — Govern, Identify, Protect, Detect, Respond, Recover — each broken into Categories and Subcategories. Pentr produces signed evidence mapped to the Subcategories a penetration test can substantiate, in the outcomes language your risk team already reports in.

Functions
6 / 6
Subcategories
18 mapped
Cadence
Continuous + annual
Evidence retention
12 months
Subcategories covered

Outcomes, substantiated.

Each row is a CSF 2.0 Subcategory, the phase in the agent that produces evidence for it, and the artifacts the locker holds for your risk team.

ID
Subcategory
Phase
Artifacts
GV.RM-01
Risk management objectives & scope agreed
Scope, rules of engagement, and consent sealed before the run.
01 · pre-engagement
3 sealed
ID.AM-01
Asset & service inventory maintained
Hosts and services resolved across the declared scope.
02 · intelligence
6 sealed
ID.RA-05
Threats & vulnerabilities used to determine risk
Attack surface prioritised into likely exploitation paths.
03 · threat modeling
5 sealed
ID.RA-01
Asset vulnerabilities identified, validated, recorded
Cross-referenced against KEV + NIST NVD, evidenced per finding.
04 · vuln analysis
14 sealed
PR.AA-05
Access permissions & authorizations enforced
Access-control weaknesses proven with a re-viewable chain.
05 · exploitation
11 sealed
DE.CM-01
Networks monitored to find adverse events
Detector alerts triggered by agent traffic, captured.
06 · post-exploit
4 sealed
ID.IM-02
Improvements identified from security tests
Control-mapped findings sealed for the risk register.
07 · reporting
3 sealed
Phase → function mapping

Where each phase earns its evidence.

01 · Pre-engagement

Govern

Scope, rules of engagement, and consent sealed up front.

GV.RM
02 · Intelligence

Identify

Resolves hosts and services into an asset inventory.

ID.AM
03 · Threat modeling

Identify

Prioritises threats and vulnerabilities into risk.

ID.RA
04 · Vuln analysis

Identify

Validates and records asset vulnerabilities per finding.

ID.RA-01
05 · Exploitation

Protect

Proves whether access-control outcomes actually hold.

PR.AA
06 · Post-exploitation

Detect / Respond

Captures whether monitoring detected the agent's activity.

DE.CMRS.MA
07 · Reporting

Recover / Govern

sha-256 chain signed at seal time. Risk-register ready.

ID.IMGV.OV

Run a CSF 2.0 assessment.

Plug in a scope. The agent runs all seven PTES phases and seals evidence mapped to the CSF 2.0 Subcategories your risk team reports against.