Artifact GuideGLOBALNIST CSF 2.0

NIST CSF 2.0 Current and Target Profile Decision Workflow

Build compatible NIST CSF 2.0 Current and Target Profiles, analyze each gap, and turn the comparison into a risk-informed action plan.

Use the same boundary and Core identifiers for both Profiles. Record what is achieved now, what is desired, why the difference matters, and who owns the response.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

An describes an organization's current and/or target cybersecurity posture for a defined scope. Use this workflow to compare where the organization is now with where it wants to be. A records outcomes currently achieved or attempted; a records desired outcomes selected and prioritized for cybersecurity risk management. Define the scope, gather evidence, compare compatible current and target states, then decide how to address each gap.

Section 1

Decide the purpose and boundary before comparing Profiles

Use this workflow to answer three questions: which Core outcomes are achieved or attempted now, which desired outcomes are selected and prioritized, and what action or risk decision follows from each difference.

NIST allows multiple Organizational Profiles with different scopes. A Profile may cover the entire organization, financial systems, a ransomware scenario, or another defined boundary. Compare Current and Target entries only when their organization, technology, service, threat scenario, assumptions, evidence date, and planning horizon are compatible; otherwise record separate Profiles rather than presenting a false gap.

  • State the decision the Profile must support, such as investment planning, supplier expectations, ransomware preparation, or communication of current capabilities.
  • Record mission objectives, stakeholders, dependencies, threat assumptions, requirements, risk appetite or tolerance, and available resources that affect selection and priority.
  • Identify the sponsor, Profile lead, outcome owners, evidence owners, and people authorized to approve targets or accept risk.
  • Treat CSF 2.0 as voluntary guidance unless a separate law, regulation, contract, grant, policy, or authority makes a particular use or outcome binding.
Section 2

Build the Current Profile from supported outcome judgments

A identifies Core outcomes currently achieved or attempted and describes how or to what extent each is achieved. It is not limited to a numeric score, and NIST does not prescribe one scoring scale.

For each selected Subcategory, write a short current-state statement, cite the supporting information, name limitations or uncertainty, and identify the person accountable for the judgment. Policies may show intent; tests, configurations, logs, tickets, approvals, and operating records may show implementation, depending on the outcome.

  • Achieved | The scoped evidence supports the outcome and any stated exceptions are within the approved characterization.
  • Partly achieved | Some parts, systems, populations, or periods meet the outcome; state the boundary instead of marking the whole outcome complete.
  • Attempted | Work is underway but the available evidence does not yet support achievement.
  • Unknown | Evidence is missing, stale, conflicting, or cannot be reviewed; assign an evidence request rather than assuming failure or success.
  • Not selected | Keep this separate from 'not achieved.' Record why the outcome is outside the Profile or decision scope.
Section 3

Select and prioritize the Target Profile

A contains desired Core outcomes selected and prioritized for the organization's cybersecurity risk management objectives. It should account for anticipated changes such as new requirements, technology adoption, and threat intelligence trends.

A can be a starting point, but it does not decide the organization's target. Confirm each imported outcome against the local scope, risks, requirements, stakeholders, and resources.

  • Record the desired outcome and priority, not a preferred product or control, unless that implementation choice is separately required.
  • State the driver: mission need, stakeholder expectation, threat, legal or contractual requirement, internal policy, dependency, or planned change.
  • Define what acceptable achievement would look like for the scope and who can approve that criterion.
  • If Tiers are used, apply them as context for the rigor of risk governance and management practices. NIST says Tiers complement rather than replace the organization's risk management methodology.
Section 4

Analyze each gap and choose a documented response

A gap is a difference between compatible Current and Target entries. Analyze its risk and dependencies before assigning a date or ranking. NIST gives examples of action-plan formats, including a risk register, risk detail report, and Plan of Action and Milestones, but does not require one format.

For each gap, record the consequence of leaving it open, chosen response, rationale, owner, resources, dependencies, milestones, acceptance criterion, and reassessment trigger.

  • Close or reduce | Implement actions that move the current state toward the target and define the evidence needed to confirm the change.
  • Accept | Record the authorized decision, scope, duration, rationale, and monitoring or review trigger under the organization's risk process.
  • Transfer or share | Document the contract, insurance, service arrangement, or other mechanism and the risk that remains with the organization.
  • Avoid or change the target | Stop or alter the activity, or revise the desired outcome when the risk decision and governing requirements allow it.
  • Escalate | Route unresolved, cross-boundary, underfunded, or out-of-tolerance gaps to the authority that can decide them.
Section 5

Five-step decision workflow and required outputs

NIST presents five steps as one way to create and use an . Repeat them when the scope, requirements, threats, technology, evidence, risk direction, or completed actions materially change.

The completed package should let another reader reconstruct the comparison without relying on workshop memory.

  • Step 1 | Scope | Output: Profile charter with boundary, purpose, assumptions, stakeholders, decision rights, exclusions, and version.
  • Step 2 | Gather | Output: source and evidence index covering policies, risk priorities, enterprise-risk information, business impacts, requirements, practices, tools, and work roles.
  • Step 3 | Create | Output: outcome-level Current and/or Target entries with identifiers, characterizations, priorities, rationale, owners, and uncertainty.
  • Step 4 | Analyze | Output: gap register and prioritized action plan with response, owner, dependencies, milestones, resources, and acceptance criteria.
  • Step 5 | Implement and update | Output: progress records, new evidence, approved decisions, revised Current entries, and the next review or event trigger.
Primary sources

References and citations

doi.org
Referenced sections
  • Source for the five-step Profile cycle and the instruction that organizations may repeat the steps as often as needed.
nist.gov
Referenced sections
  • Official tool for selecting and exporting consistent CSF 2.0 Core identifiers and reviewing related Implementation Examples and Informative References.
Related guides

Explore more topics

How should teams handle evidence mapping under NIST CSF 2.0?
Map policies, configurations, tests, logs, approvals, and operating records to specific NIST CSF 2.0 outcomes without treating a reference or policy as proof of performance.
How should teams handle implementation examples under NIST CSF 2.0?
Use NIST CSF 2.0 Implementation Examples as optional, non-exhaustive ways to help achieve a Subcategory outcome, then tailor and test the chosen practice.
How should teams handle supplier risk under NIST CSF 2.0?
Apply NIST CSF 2.0 supplier-risk outcomes across selection, contracting, monitoring, incident coordination, and relationship exit, with effort based on criticality and risk.
How should teams handle target profiles under NIST CSF 2.0?
Build a NIST CSF 2.0 Target Profile by selecting and prioritizing desired Core outcomes, then turn Current-to-Target gaps into owned risk actions.
How should teams handle tiers under NIST CSF 2.0?
Use NIST CSF 2.0 Tiers to characterize risk governance and management rigor for a defined scope without turning them into certification levels or a universal maturity score.
NIST CSF 2.0 Core Functions Guide
Understand GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER, including their Categories, concurrent use, ownership, evidence, and Profile decisions.
NIST CSF 2.0 current and target profile template: operating columns and evidence rows
A field-by-field NIST CSF 2.0 Current and Target Profile worksheet for compatible outcome comparisons, evidence, gaps, and action plans.
NIST CSF 2.0 Current vs Target Profile Template
Build a NIST CSF 2.0 Current and Target Profile with a defined scope, outcome-level evidence, priorities, owners, milestones, and reassessment triggers.
NIST CSF 2.0 Evidence Mapping Workflow
Map a NIST CSF 2.0 outcome to evidence, test what the record proves, document gaps, and assign the next risk decision.
NIST CSF 2.0 FAQ: practical implementation questions
Direct answers on NIST CSF 2.0 Tiers, GOVERN, Profiles, supplier risk, Implementation Examples, evidence mapping, and board reporting.
NIST CSF 2.0 GOVERN Function FAQ
Start the NIST CSF 2.0 GOVERN function by naming decision owners, risk strategy, policy expectations, oversight cadence, and supplier-risk accountability before mapping controls.
NIST CSF 2.0 Governance and Metrics Guide
Connect NIST CSF 2.0 GOVERN outcomes to decisions, owners, risk appetite, and metrics without inventing a single maturity score.
NIST CSF 2.0 Implementation Examples Guide
Use NIST CSF 2.0 Implementation Examples as optional prompts, adapt them to one scoped outcome, and define evidence that tests the result.
NIST CSF 2.0 Profile Workshop Template
A fill-in NIST CSF 2.0 Profile workshop template for scope, roles, outcome decisions, evidence gaps, approvals, and follow-up.
NIST CSF 2.0 Profile Workshop Workflow
Prepare and run a NIST CSF 2.0 Profile workshop that produces scoped outcome decisions, evidence requests, and an owned gap plan.
NIST CSF 2.0 Requirements Mapping Guide
Build a traceable mapping from applicable requirements to NIST CSF 2.0 outcomes, controls, evidence, gaps, and owners without treating the mapping as proof of compliance.
NIST CSF 2.0 vs CIS Controls v8.1: Mapping and Gap Analysis
Map CSF 2.0 outcomes to CIS Controls v8.1 safeguards without confusing a crosswalk with implementation evidence or full outcome achievement.
NIST CSF 2.0 vs CIS Controls v8.1: Which to Use
Choose CSF 2.0 for outcome-based risk governance, CIS Controls v8.1 for prioritized safeguards, or combine them with separate claims and evidence.
NIST CSF 2.0 vs ISO/IEC 27001:2022: Which to Use
Choose CSF 2.0 for outcome-based cyber-risk governance or ISO/IEC 27001:2022 for a requirements-based ISMS and possible certification.
NIST CSF 2.0 vs NIST RMF: practical side-by-side comparison
Decide when to use NIST CSF 2.0 outcomes and Profiles, when to use the seven-step NIST RMF process, and how to connect their evidence.
NIST CSF 2.0 vs SP 800-53 Rev. 5: control mapping and coverage gaps
Map CSF 2.0 outcomes to SP 800-53 Rev. 5 controls while preserving scope, tailoring, assessment, and partial-coverage limits.
NIST CSF 2.0 vs SP 800-53 Rev. 5: Which to Use
Choose CSF 2.0 for outcome-based cybersecurity governance or SP 800-53 Rev. 5 for control selection, tailoring, implementation, and assessment.
What should an NIST CSF 2.0 Current Profile include to be useful for audits and risk decisions?
A useful CSF 2.0 Current Profile should show current outcomes, accountable owners, supporting evidence, known gaps, dependencies, and review dates. It should be specific enough that a reviewer can understand what is true today without re-interviewing every team.
Which NIST CSF 2.0 metrics are useful for board and executive reporting?
Use board-level CSF 2.0 metrics that show risk decisions, business impact, target-profile gaps, and progress against priorities. Avoid only reporting control counts; executives need to see whether cybersecurity outcomes are improving in the context of organizational objectives.