CCPA / CPRA → NIST CSF 2.0 crosswalk
A control-by-control mapping between California Consumer Privacy Act (as amended by CPRA) and NIST Cybersecurity Framework 2.0. 3 mappings.
| CCPA / CPRA | NIST CSF 2.0 | Relationship | Notes |
|---|---|---|---|
| §1798.100 Consumers' right to know and notice at collection | GV.OC-01 Organizational mission and security role understood | RelatedCurated | Gouvernance et politique de sécurité |
| §1798.130 Methods for handling consumer requests | ID.AM-01 Inventories of hardware managed | RelatedCurated | Inventaire des actifs et des données |
| §1798.150 Duty to implement reasonable security | ID.RA-01 Vulnerabilities identified and recorded | RelatedCurated | Évaluation et gestion des risques |
Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.