NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
The National Retail Federation (NRF) provides cybersecurity and data privacy guidance for the US retail industry. NRF represents the world's largest retail market. Key initiatives include: NRF Cybersecurity and Privacy Council, retail-specific threat intelligence sharing via RH-ISAC (Retail and Hospitality ISAC), and advocacy for federal data privacy legislation. NRF's cybersecurity guidance covers: point-of-sale (POS) security, e-commerce platform protection, customer data privacy, supply chain cybersecurity, payment card security (complementing PCI DSS), and workforce cyber training. NRF collaborated with NIST on the Cybersecurity Framework retail profile.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Consumer Privacy
| Code | Title |
|---|---|
| NRF-7 | Data Erasure and Portability |
| NRF-8 | Consent and Legitimate Interest |
| NRF-9 | Customer Profiling Compliance |
Data Breach and Incident Response
| Code | Title |
|---|---|
| NRF-10 | Breach Notification Rules |
| NRF-11 | Incident Response Planning |
Fraud Prevention
| Code | Title |
|---|---|
| NRF-12 | Fraud Detection and Prevention |
| NRF-13 | Digital Trust Building |
Governance and Risk Management
Cybersecurity governance, risk management, and compliance
| Code | Title |
|---|---|
| NRF-1 | Cybersecurity Governance Structure |
| NRF-2 | Risk Assessment and Management |
| NRF-3 | Regulatory Change Management |
| OMAN-GOV-01 | Cybersecurity Governance Structure |
| OMAN-GOV-02 | Cybersecurity Risk Management |
| OMAN-GOV-03 | Cybersecurity Policies and Procedures |
| OMAN-GOV-04 | Regulatory Compliance |
Supply Chain Security
Customs security and risk management
| Code | Title |
|---|---|
| AEO-SC-1 | Cargo Security |
| AEO-SC-2 | Conveyance Security |
| AEO-SC-3 | Premises Security |
| AEO-SC-4 | Trading Partner Security |
| CTPAT-SCS-01 | Physical Security |
| CTPAT-SCS-02 | Personnel Security |
| CTPAT-SCS-03 | Conveyance and Cargo Security |
| EU-CHIPS-SUP-01 | Supply Chain Monitoring |
| EU-CHIPS-SUP-02 | Crisis Assessment and Response |
| EU-CHIPS-SUP-03 | International Partnerships |
| EU-CRMA-SUP-01 | Strategic Benchmarks |
| EU-CRMA-SUP-02 | Strategic Projects Recognition |
| EU-CRMA-SUP-03 | Supply Chain Monitoring |
| NIS2-IA-7 | Supply Chain Security Policy |
| NIS2-IA-8 | Supplier Security Assessment |
| NRF-4 | Supply Chain Risk Identification |
| NRF-5 | Third-Party Partner Standards |
| NRF-6 | Vendor Risk Management |
| UKTSA-SC-01 | Supply Chain Risk Assessment |
| UKTSA-SC-02 | High-Risk Vendor Restrictions |
| UKTSA-SC-03 | Vendor Diversification |
| UKTSA-SC-04 | Third-Party Access Controls |
| WCO-SAFE-SCS-01 | Advance Electronic Information |
| WCO-SAFE-SCS-02 | Risk Management |
| WCO-SAFE-SCS-03 | Non-Intrusive Inspection |
Maps to 632 other frameworks
Frequently Asked Questions
What is NRF Cybersecurity and Data Privacy Framework (National Retail Federation)?
NRF Cybersecurity and Data Privacy Framework (National Retail Federation) is a compliance framework from United States (NRF) with 5 domains and 39 controls. The National Retail Federation (NRF) provides cybersecurity and data privacy guidance for the US retail industry. NRF represents the world's largest retail market. Key initiatives include: NRF Cybersecurity and Privacy Council, retail-specific threat intelligence sharing via RH-ISAC (Retail and Hospitality ISAC), and advocacy for federal data privacy legislation. NRF's cybersecurity guidance covers: point-of-sale (POS) security, e-commerce platform protection, customer data privacy, supply chain cybersecurity, payment card security (complementing PCI DSS), and workforce cyber training. NRF collaborated with NIST on the Cybersecurity Framework retail profile. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NRF Cybersecurity and Data Privacy Framework (National Retail Federation) have?
NRF Cybersecurity and Data Privacy Framework (National Retail Federation) has 39 controls organised across 5 domains. The largest domains are Supply Chain Security (25 controls), Governance and Risk Management (7 controls), Consumer Privacy (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NRF Cybersecurity and Data Privacy Framework (National Retail Federation) map to?
NRF Cybersecurity and Data Privacy Framework (National Retail Federation) maps to 632 other compliance frameworks. The top mapping partners are NIST Privacy Framework 1.0 (44% coverage), New Zealand Information Security Manual (NZISM) (44% coverage), CFTC System Safeguards (17 CFR 37, 38, 39, 49) (44% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NRF Cybersecurity and Data Privacy Framework (National Retail Federation) compliance?
Start your NRF Cybersecurity and Data Privacy Framework (National Retail Federation) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NRF Cybersecurity and Data Privacy Framework (National Retail Federation) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 39 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required