WorkflowGLOBALNIST CSF 2.0

NIST CSF 2.0 Current and Target Profile Operating Template

A field-by-field NIST CSF 2.0 Current and Target Profile worksheet for compatible outcome comparisons, evidence, gaps, and action plans.

This is an optional operating template, not a NIST-mandated form. Keep one Profile header and one row per selected Core outcome.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

An describes current and/or target cybersecurity posture through selected CSF Core outcomes. This worksheet follows NIST's five-step Profile cycle: scope the Profile, gather information, create the and/or , analyze gaps and create an action plan, then implement the plan and update the Profile. Adapt the fields, characterization scale, review cadence, and retention rules to the organization and any controlling requirements; CSF 2.0 does not mandate a form, score, deadline, or evidence package.

Section 1

Profile header: define the comparison once

The Profile owner completes the header before outcome owners, evidence custodians, and reviewers add rows. Every Current and Target entry must use the same stated boundary or clearly identify why a comparison is not valid.

  • Identity | Profile name, version, status, owner, sponsor, creation date, last decision date, and linked prior version.
  • Boundary | Organization or unit, systems and services, locations, suppliers, technology environment, threat or use-case focus, covered period, and explicit exclusions.
  • Purpose | Decision the Profile supports, audience, mission or business objectives, and intended use inside or outside the organization.
  • Context | Stakeholders, dependencies, requirements, threats, risk appetite or tolerance, assumptions, resources, and planned changes.
  • Method | Core version, selected Functions or outcomes, characterization scale and definitions, evidence standard, decision authority, and review or event triggers.
Section 2

Outcome row: Current, Target, gap, and decision fields

Create one row for each selected CSF Subcategory. Keep the official outcome text separate from the organization's characterization, implementation method, and evidence.

  • CSF fields | Function, Category, Subcategory identifier, official outcome text, and source or export date.
  • Current fields | Characterization; plain-language statement of how or to what extent the outcome is achieved or attempted; evidence links; covered population and period; exceptions; uncertainty; reviewer and review date.
  • Target fields | Selected desired outcome; priority; driver; planned context or threat change; acceptance criterion; target owner; and any optional Tier context.
  • Gap fields | Difference between Current and Target; risk or consequence; affected stakeholders or dependencies; and any requirement linked to the gap.
  • Decision fields | Mitigate, accept, transfer or share, avoid, change target, request evidence, or escalate; rationale; authorized decision owner; conditions; and residual uncertainty.
  • Action fields | Accountable owner, supporting teams, resources, dependency, milestone or due date, completion evidence, status, and reassessment trigger.
Section 3

Completion rules and worked row

Do not mark a row complete because a policy exists or an action has been assigned. Close it only when the stated acceptance criterion is met, the supporting evidence covers the scope, and the authorized reviewer records the updated Current characterization.

Worked row: GV.RM-02 concerns establishing, communicating, and maintaining risk appetite and risk tolerance statements. A Current entry might record that an approved statement exists but distribution and scheduled maintenance are not evidenced. The Target entry can select the complete outcome, the gap can identify communication and maintenance, and the action plan can assign distribution records and a review mechanism. This example illustrates the worksheet; NIST does not prescribe those particular artifacts.

  • Use 'unknown' when evidence is missing or conflicting; do not convert missing evidence into either achievement or failure.
  • Use 'not selected' only for an outcome outside the Profile decision scope, and record the rationale separately from Current achievement.
  • Protect restricted logs, security configurations, contracts, and personal data by linking to controlled records instead of copying them into the worksheet.
  • Version the Profile when decisions change, preserve the prior rationale, and identify the event or review that triggered the update.
  • Repeat the Profile cycle when scope, requirements, threats, technology, risk direction, evidence, or action-plan results materially change.
Primary sources

References and citations

doi.org
Referenced sections
  • Provides the exact GV.RM-02 outcome and states that organizations can repeat the Profile steps as often as needed.
nist.gov
Referenced sections
  • Use the official tool to confirm the outcome text and current supplementary resources before updating a row.
Related guides

Explore more topics

How should teams handle evidence mapping under NIST CSF 2.0?
Map policies, configurations, tests, logs, approvals, and operating records to specific NIST CSF 2.0 outcomes without treating a reference or policy as proof of performance.
How should teams handle implementation examples under NIST CSF 2.0?
Use NIST CSF 2.0 Implementation Examples as optional, non-exhaustive ways to help achieve a Subcategory outcome, then tailor and test the chosen practice.
How should teams handle supplier risk under NIST CSF 2.0?
Apply NIST CSF 2.0 supplier-risk outcomes across selection, contracting, monitoring, incident coordination, and relationship exit, with effort based on criticality and risk.
How should teams handle target profiles under NIST CSF 2.0?
Build a NIST CSF 2.0 Target Profile by selecting and prioritizing desired Core outcomes, then turn Current-to-Target gaps into owned risk actions.
How should teams handle tiers under NIST CSF 2.0?
Use NIST CSF 2.0 Tiers to characterize risk governance and management rigor for a defined scope without turning them into certification levels or a universal maturity score.
NIST CSF 2.0 Core Functions Guide
Understand GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER, including their Categories, concurrent use, ownership, evidence, and Profile decisions.
NIST CSF 2.0 Current vs Target Profile Template
Build a NIST CSF 2.0 Current and Target Profile with a defined scope, outcome-level evidence, priorities, owners, milestones, and reassessment triggers.
NIST CSF 2.0 Evidence Mapping Workflow
Map a NIST CSF 2.0 outcome to evidence, test what the record proves, document gaps, and assign the next risk decision.
NIST CSF 2.0 FAQ: practical implementation questions
Direct answers on NIST CSF 2.0 Tiers, GOVERN, Profiles, supplier risk, Implementation Examples, evidence mapping, and board reporting.
NIST CSF 2.0 GOVERN Function FAQ
Start the NIST CSF 2.0 GOVERN function by naming decision owners, risk strategy, policy expectations, oversight cadence, and supplier-risk accountability before mapping controls.
NIST CSF 2.0 Governance and Metrics Guide
Connect NIST CSF 2.0 GOVERN outcomes to decisions, owners, risk appetite, and metrics without inventing a single maturity score.
NIST CSF 2.0 Implementation Examples Guide
Use NIST CSF 2.0 Implementation Examples as optional prompts, adapt them to one scoped outcome, and define evidence that tests the result.
NIST CSF 2.0 Profile Workshop Template
A fill-in NIST CSF 2.0 Profile workshop template for scope, roles, outcome decisions, evidence gaps, approvals, and follow-up.
NIST CSF 2.0 Profile Workshop Workflow
Prepare and run a NIST CSF 2.0 Profile workshop that produces scoped outcome decisions, evidence requests, and an owned gap plan.
NIST CSF 2.0 Requirements Mapping Guide
Build a traceable mapping from applicable requirements to NIST CSF 2.0 outcomes, controls, evidence, gaps, and owners without treating the mapping as proof of compliance.
NIST CSF 2.0 vs CIS Controls v8.1: Mapping and Gap Analysis
Map CSF 2.0 outcomes to CIS Controls v8.1 safeguards without confusing a crosswalk with implementation evidence or full outcome achievement.
NIST CSF 2.0 vs CIS Controls v8.1: Which to Use
Choose CSF 2.0 for outcome-based risk governance, CIS Controls v8.1 for prioritized safeguards, or combine them with separate claims and evidence.
NIST CSF 2.0 vs ISO/IEC 27001:2022: Which to Use
Choose CSF 2.0 for outcome-based cyber-risk governance or ISO/IEC 27001:2022 for a requirements-based ISMS and possible certification.
NIST CSF 2.0 vs NIST RMF: practical side-by-side comparison
Decide when to use NIST CSF 2.0 outcomes and Profiles, when to use the seven-step NIST RMF process, and how to connect their evidence.
NIST CSF 2.0 vs SP 800-53 Rev. 5: control mapping and coverage gaps
Map CSF 2.0 outcomes to SP 800-53 Rev. 5 controls while preserving scope, tailoring, assessment, and partial-coverage limits.
NIST CSF 2.0 vs SP 800-53 Rev. 5: Which to Use
Choose CSF 2.0 for outcome-based cybersecurity governance or SP 800-53 Rev. 5 for control selection, tailoring, implementation, and assessment.
NIST CSF 2.0: step-by-step workflow for building current and target profiles
Build compatible NIST CSF 2.0 Current and Target Profiles, analyze each gap, and turn the comparison into a risk-informed action plan.
What should an NIST CSF 2.0 Current Profile include to be useful for audits and risk decisions?
A useful CSF 2.0 Current Profile should show current outcomes, accountable owners, supporting evidence, known gaps, dependencies, and review dates. It should be specific enough that a reviewer can understand what is true today without re-interviewing every team.
Which NIST CSF 2.0 metrics are useful for board and executive reporting?
Use board-level CSF 2.0 metrics that show risk decisions, business impact, target-profile gaps, and progress against priorities. Avoid only reporting control counts; executives need to see whether cybersecurity outcomes are improving in the context of organizational objectives.