Use one row per selected CSF outcome in an . Record the - what is achieved or attempted and to what extent - beside the - the desired outcome selected and prioritized for the same scope. Then record the gap, risk response, owner, evidence, milestone, and reassessment trigger. NIST CSF 2.0 does not prescribe a universal score, evidence set, template, deadline, or Profile cadence.
Side-by-side comparison
NIST CSF 2.0 Current vs Target Profile Template
Compare NIST CSF 2.0 Current and Target Profiles across functions, categories, subcategories, implementation status, owners, evidence, target outcomes, gaps, and roadmap decisions.
Current captures the CSF outcomes the organization is already achieving, including how or to what extent they are achieved, so the team can see the baseline posture, gaps, and risk context.
Second framework
Target Profile Template
Template captures the desired CSF outcomes the organization has selected and prioritized, including new requirements, new technology, and threat trends that should shape the future posture.
Current: define the current business unit, mission/business process, information system, or supplier context and record which CSF outcomes are actually being achieved there today.
Target: select and prioritize desired CSF outcomes for the same boundary. If the target intentionally changes the boundary, requirements, assumptions, technology, or threat scenario, record the change explicitly.
Current: identify the teams, roles, and owners already responsible for each CSF outcome, including where governance, operations, and suppliers are already assigned.
Template: name the future accountable owners for each selected outcome and note any new governance or supplier responsibilities needed to close the gap.
Current: record the assessment date and the facts that may make the characterization stale, such as a material system, supplier, threat, requirement, mission, or evidence change.
Target: record the requirement, risk decision, technology change, threat intelligence, or stakeholder expectation that caused the organization to select or reprioritize the desired outcome.
A specifies the Core outcomes the organization is achieving or attempting to achieve and characterizes how or to what extent each is achieved. Supporting evidence and judgment fields are useful implementation choices, not fields mandated by CSF 2.0.
A specifies desired outcomes the organization has selected and prioritized. Target dates, acceptance criteria, owners, and milestones belong in the resulting action plan when useful; CSF 2.0 does not require one universal template or a Tier for every outcome.
Compare the two characterizations, analyze the risk implications, and create a prioritized action plan. Do not turn an implementation choice into a claimed CSF requirement.
Current: link evidence that supports the characterization, such as configuration or inventory records, logs, tests, exercise results, approvals, contracts, and interviews. Record the evidence date, boundary, owner, and limitations.
Target: record the selected outcome, priority, rationale, planned practice or control, expected completion evidence, and acceptance decision. A target plan is not current-state evidence.
Separate design evidence, operating evidence, and future plans. A document can support more than one outcome, but each outcome claim still needs its own rationale.
Current: state when the evidence was collected and when the characterization will be reassessed. Refresh it after material changes rather than carrying forward an old result by default.
Current: name who reviewed the characterization and what level of evidence they examined. CSF 2.0 itself does not provide certification or require independent assurance.
Target: name who will accept completion and what evidence will support that decision. Contract, policy, regulation, customer, or audit criteria may add requirements beyond CSF 2.0.
Current: record observed or verified conditions for the assessment period. A policy, design, purchase order, or implementation plan supports intent but does not by itself show that an outcome operates.
Target: record the selected desired outcome, its priority, rationale, dependencies, and acceptance criteria. Existing evidence may inform feasibility, but completion evidence belongs in a later Current update.
Compare only like-for-like outcome text and boundaries. If scope, population, period, or assumptions differ, label the mismatch before describing or prioritizing the gap.
Current: define the current business unit, mission/business process, information system, or supplier context and record which CSF outcomes are actually being achieved there today.
Target: select and prioritize desired CSF outcomes for the same boundary. If the target intentionally changes the boundary, requirements, assumptions, technology, or threat scenario, record the change explicitly.
Current: identify the teams, roles, and owners already responsible for each CSF outcome, including where governance, operations, and suppliers are already assigned.
Template: name the future accountable owners for each selected outcome and note any new governance or supplier responsibilities needed to close the gap.
Current: record the assessment date and the facts that may make the characterization stale, such as a material system, supplier, threat, requirement, mission, or evidence change.
Target: record the requirement, risk decision, technology change, threat intelligence, or stakeholder expectation that caused the organization to select or reprioritize the desired outcome.
A specifies the Core outcomes the organization is achieving or attempting to achieve and characterizes how or to what extent each is achieved. Supporting evidence and judgment fields are useful implementation choices, not fields mandated by CSF 2.0.
A specifies desired outcomes the organization has selected and prioritized. Target dates, acceptance criteria, owners, and milestones belong in the resulting action plan when useful; CSF 2.0 does not require one universal template or a Tier for every outcome.
Compare the two characterizations, analyze the risk implications, and create a prioritized action plan. Do not turn an implementation choice into a claimed CSF requirement.
Current: link evidence that supports the characterization, such as configuration or inventory records, logs, tests, exercise results, approvals, contracts, and interviews. Record the evidence date, boundary, owner, and limitations.
Target: record the selected outcome, priority, rationale, planned practice or control, expected completion evidence, and acceptance decision. A target plan is not current-state evidence.
Separate design evidence, operating evidence, and future plans. A document can support more than one outcome, but each outcome claim still needs its own rationale.
Current: state when the evidence was collected and when the characterization will be reassessed. Refresh it after material changes rather than carrying forward an old result by default.
Current: name who reviewed the characterization and what level of evidence they examined. CSF 2.0 itself does not provide certification or require independent assurance.
Target: name who will accept completion and what evidence will support that decision. Contract, policy, regulation, customer, or audit criteria may add requirements beyond CSF 2.0.
Current: record observed or verified conditions for the assessment period. A policy, design, purchase order, or implementation plan supports intent but does not by itself show that an outcome operates.
Target: record the selected desired outcome, its priority, rationale, dependencies, and acceptance criteria. Existing evidence may inform feasibility, but completion evidence belongs in a later Current update.
Compare only like-for-like outcome text and boundaries. If scope, population, period, or assumptions differ, label the mismatch before describing or prioritizing the gap.
Start by defining the Profile boundary and assumptions. A Profile may cover the whole organization, a business unit, a system, a supplier relationship, a technology, or a threat scenario. Use the same boundary for the Current and Target comparison; if the target boundary is intentionally broader, record that change before interpreting the gap.
For each selected Function, Category, or Subcategory outcome, describe how or to what extent the outcome is achieved now. Then record the desired outcome and its priority. Keep observed current-state support separate from target-state plans: a policy or planned control shows intent, not that the outcome is operating.
Analyze each difference and choose a response. The action plan may be a risk register, risk detail report, or plan of action and milestones. It should state the action or accepted risk, accountable owner, dependencies, milestone, completion evidence, and the event that will cause the Profile to be updated.
If the organization uses labels such as achieved, partly achieved, attempted, and unknown, define each label before assessment. Apply it at the same outcome level and boundary, and preserve the supporting narrative. Do not average labels across Functions or convert optional into outcome scores.
Scope record: boundary, mission or business objective, stakeholders, dependencies, assumptions, requirements, risk priorities, and assessment date.
row: CSF identifier and outcome text, present characterization, supporting records, evidence limitations, and known improvement opportunities.
row: selected desired outcome, priority and rationale, requirement or risk driver, and any Community Profile used as a starting point rather than adopted without tailoring.
Gap action: treatment decision, accountable owner, dependencies, milestone, acceptance criterion, residual-risk decision, and Profile update trigger.
Optional Tier context: use only when they help characterize the rigor of governance and risk-management practices. Do not treat Tier numbers as outcome scores or assume every organization must move to Tier 4.
Reassessment record: scheduled review date plus event triggers such as a material requirement, threat, technology, supplier, mission, boundary, evidence, incident, or action-plan change.