Artifact GuideGLOBALNIST CSF 2.0

NIST CSF 2.0 Current vs Target Profile Template

Record what the organization achieves now, what it wants to achieve, and the prioritized work needed to close each gap.

Use one row per selected CSF outcome. Keep the Profile scope, evidence, rationale, owner, milestone, and reassessment trigger visible.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
1

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Use one row per selected CSF outcome in an . Record the - what is achieved or attempted and to what extent - beside the - the desired outcome selected and prioritized for the same scope. Then record the gap, risk response, owner, evidence, milestone, and reassessment trigger. NIST CSF 2.0 does not prescribe a universal score, evidence set, template, deadline, or Profile cadence.

Side-by-side comparison

NIST CSF 2.0 Current vs Target Profile Template

Compare NIST CSF 2.0 Current and Target Profiles across functions, categories, subcategories, implementation status, owners, evidence, target outcomes, gaps, and roadmap decisions.

Review all sources
First framework
Current

Current captures the CSF outcomes the organization is already achieving, including how or to what extent they are achieved, so the team can see the baseline posture, gaps, and risk context.

Second framework
Target Profile Template

Template captures the desired CSF outcomes the organization has selected and prioritized, including new requirements, new technology, and threat trends that should shape the future posture.

Comparison row 1

Scope and covered activity

Current

Current: define the current business unit, mission/business process, information system, or supplier context and record which CSF outcomes are actually being achieved there today.

Target Profile Template

Target: select and prioritize desired CSF outcomes for the same boundary. If the target intentionally changes the boundary, requirements, assumptions, technology, or threat scenario, record the change explicitly.

Operational implication

Do not interpret a difference as a capability gap until the two rows use compatible boundaries and assumptions.

Comparison row 2

Who must act

Current

Current: identify the teams, roles, and owners already responsible for each CSF outcome, including where governance, operations, and suppliers are already assigned.

Target Profile Template

Template: name the future accountable owners for each selected outcome and note any new governance or supplier responsibilities needed to close the gap.

Operational implication

Keep owners explicit on both sides so the comparison shows who is already accountable and who must be added or changed in the target state.

Comparison row 3

Trigger or threshold

Current

Current: record the assessment date and the facts that may make the characterization stale, such as a material system, supplier, threat, requirement, mission, or evidence change.

Target Profile Template

Target: record the requirement, risk decision, technology change, threat intelligence, or stakeholder expectation that caused the organization to select or reprioritize the desired outcome.

Operational implication

Set reassessment triggers from the Profile's risk context. CSF 2.0 does not impose one universal refresh interval.

Comparison row 4

Profile content and gap decision

Current

A specifies the Core outcomes the organization is achieving or attempting to achieve and characterizes how or to what extent each is achieved. Supporting evidence and judgment fields are useful implementation choices, not fields mandated by CSF 2.0.

Target Profile Template

A specifies desired outcomes the organization has selected and prioritized. Target dates, acceptance criteria, owners, and milestones belong in the resulting action plan when useful; CSF 2.0 does not require one universal template or a Tier for every outcome.

Operational implication

Compare the two characterizations, analyze the risk implications, and create a prioritized action plan. Do not turn an implementation choice into a claimed CSF requirement.

Comparison row 5

Evidence and records

Current

Current: link evidence that supports the characterization, such as configuration or inventory records, logs, tests, exercise results, approvals, contracts, and interviews. Record the evidence date, boundary, owner, and limitations.

Target Profile Template

Target: record the selected outcome, priority, rationale, planned practice or control, expected completion evidence, and acceptance decision. A target plan is not current-state evidence.

Operational implication

Separate design evidence, operating evidence, and future plans. A document can support more than one outcome, but each outcome claim still needs its own rationale.

Comparison row 6

Timing and cadence

Current

Current: state when the evidence was collected and when the characterization will be reassessed. Refresh it after material changes rather than carrying forward an old result by default.

Target Profile Template

Target: set action-plan milestones and a review point for checking whether priorities, assumptions, and desired outcomes still fit the risk context.

Operational implication

Track the evidence date, reassessment date, and delivery milestone separately; none is a universal NIST deadline.

Comparison row 7

Enforcement or assurance route

Current

Current: name who reviewed the characterization and what level of evidence they examined. CSF 2.0 itself does not provide certification or require independent assurance.

Target Profile Template

Target: name who will accept completion and what evidence will support that decision. Contract, policy, regulation, customer, or audit criteria may add requirements beyond CSF 2.0.

Operational implication

Do not label a Profile as certified or compliant merely because the organization completed the template.

Comparison row 8

Relationship between the two records

Current

Current: record observed or verified conditions for the assessment period. A policy, design, purchase order, or implementation plan supports intent but does not by itself show that an outcome operates.

Target Profile Template

Target: record the selected desired outcome, its priority, rationale, dependencies, and acceptance criteria. Existing evidence may inform feasibility, but completion evidence belongs in a later Current update.

Operational implication

Compare only like-for-like outcome text and boundaries. If scope, population, period, or assumptions differ, label the mismatch before describing or prioritizing the gap.

Comparison row 9

Practical decision rule

Current

Current: use this column when the question is what the organization is already doing today and what gaps remain against the CSF Core outcomes.

Target Profile Template

Template: use this column when the question is what CSF outcomes the organization has selected, prioritized, and plans to achieve next.

Operational implication

Choose the side that answers the present decision: baseline posture, desired posture, or the gap between them.

Practical decision rule

How to use the completed comparison

  • Validate the Current characterization against dated evidence before measuring the gap.
  • Prioritize gaps from mission objectives, stakeholder expectations, threats, requirements, and risk implications rather than averaging row scores.
  • Approve the action plan, track completion evidence, and update the Profile as actions close or the scope and risk context change.
Section 1

What to record in a Current and Target Profile

Start by defining the Profile boundary and assumptions. A Profile may cover the whole organization, a business unit, a system, a supplier relationship, a technology, or a threat scenario. Use the same boundary for the Current and Target comparison; if the target boundary is intentionally broader, record that change before interpreting the gap.

For each selected Function, Category, or Subcategory outcome, describe how or to what extent the outcome is achieved now. Then record the desired outcome and its priority. Keep observed current-state support separate from target-state plans: a policy or planned control shows intent, not that the outcome is operating.

Analyze each difference and choose a response. The action plan may be a risk register, risk detail report, or plan of action and milestones. It should state the action or accepted risk, accountable owner, dependencies, milestone, completion evidence, and the event that will cause the Profile to be updated.

If the organization uses labels such as achieved, partly achieved, attempted, and unknown, define each label before assessment. Apply it at the same outcome level and boundary, and preserve the supporting narrative. Do not average labels across Functions or convert optional into outcome scores.

  • Scope record: boundary, mission or business objective, stakeholders, dependencies, assumptions, requirements, risk priorities, and assessment date.
  • row: CSF identifier and outcome text, present characterization, supporting records, evidence limitations, and known improvement opportunities.
  • row: selected desired outcome, priority and rationale, requirement or risk driver, and any Community Profile used as a starting point rather than adopted without tailoring.
  • Gap action: treatment decision, accountable owner, dependencies, milestone, acceptance criterion, residual-risk decision, and Profile update trigger.
  • Optional Tier context: use only when they help characterize the rigor of governance and risk-management practices. Do not treat Tier numbers as outcome scores or assume every organization must move to Tier 4.
  • Reassessment record: scheduled review date plus event triggers such as a material requirement, threat, technology, supplier, mission, boundary, evidence, incident, or action-plan change.
Primary sources

References and citations

nist.gov
Referenced sections
  • NIST states that it does not offer certification or endorsement for CSF implementations.
"NIST does not offer certifications or endorsements of CSF-related products, implementations, or services"
doi.org
Referenced sections
  • Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and implementation approach.
"does not prescribe how outcomes should be achieved"
Related guides

Explore more topics

How should teams handle evidence mapping under NIST CSF 2.0?
Map policies, configurations, tests, logs, approvals, and operating records to specific NIST CSF 2.0 outcomes without treating a reference or policy as proof of performance.
How should teams handle implementation examples under NIST CSF 2.0?
Use NIST CSF 2.0 Implementation Examples as optional, non-exhaustive ways to help achieve a Subcategory outcome, then tailor and test the chosen practice.
How should teams handle supplier risk under NIST CSF 2.0?
Apply NIST CSF 2.0 supplier-risk outcomes across selection, contracting, monitoring, incident coordination, and relationship exit, with effort based on criticality and risk.
How should teams handle target profiles under NIST CSF 2.0?
Build a NIST CSF 2.0 Target Profile by selecting and prioritizing desired Core outcomes, then turn Current-to-Target gaps into owned risk actions.
How should teams handle tiers under NIST CSF 2.0?
Use NIST CSF 2.0 Tiers to characterize risk governance and management rigor for a defined scope without turning them into certification levels or a universal maturity score.
NIST CSF 2.0 Core Functions Guide
Understand GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER, including their Categories, concurrent use, ownership, evidence, and Profile decisions.
NIST CSF 2.0 current and target profile template: operating columns and evidence rows
A field-by-field NIST CSF 2.0 Current and Target Profile worksheet for compatible outcome comparisons, evidence, gaps, and action plans.
NIST CSF 2.0 Evidence Mapping Workflow
Map a NIST CSF 2.0 outcome to evidence, test what the record proves, document gaps, and assign the next risk decision.
NIST CSF 2.0 FAQ: practical implementation questions
Direct answers on NIST CSF 2.0 Tiers, GOVERN, Profiles, supplier risk, Implementation Examples, evidence mapping, and board reporting.
NIST CSF 2.0 GOVERN Function FAQ
Start the NIST CSF 2.0 GOVERN function by naming decision owners, risk strategy, policy expectations, oversight cadence, and supplier-risk accountability before mapping controls.
NIST CSF 2.0 Governance and Metrics Guide
Connect NIST CSF 2.0 GOVERN outcomes to decisions, owners, risk appetite, and metrics without inventing a single maturity score.
NIST CSF 2.0 Implementation Examples Guide
Use NIST CSF 2.0 Implementation Examples as optional prompts, adapt them to one scoped outcome, and define evidence that tests the result.
NIST CSF 2.0 Profile Workshop Template
A fill-in NIST CSF 2.0 Profile workshop template for scope, roles, outcome decisions, evidence gaps, approvals, and follow-up.
NIST CSF 2.0 Profile Workshop Workflow
Prepare and run a NIST CSF 2.0 Profile workshop that produces scoped outcome decisions, evidence requests, and an owned gap plan.
NIST CSF 2.0 Requirements Mapping Guide
Build a traceable mapping from applicable requirements to NIST CSF 2.0 outcomes, controls, evidence, gaps, and owners without treating the mapping as proof of compliance.
NIST CSF 2.0 vs CIS Controls v8.1: Mapping and Gap Analysis
Map CSF 2.0 outcomes to CIS Controls v8.1 safeguards without confusing a crosswalk with implementation evidence or full outcome achievement.
NIST CSF 2.0 vs CIS Controls v8.1: Which to Use
Choose CSF 2.0 for outcome-based risk governance, CIS Controls v8.1 for prioritized safeguards, or combine them with separate claims and evidence.
NIST CSF 2.0 vs ISO/IEC 27001:2022: Which to Use
Choose CSF 2.0 for outcome-based cyber-risk governance or ISO/IEC 27001:2022 for a requirements-based ISMS and possible certification.
NIST CSF 2.0 vs NIST RMF: practical side-by-side comparison
Decide when to use NIST CSF 2.0 outcomes and Profiles, when to use the seven-step NIST RMF process, and how to connect their evidence.
NIST CSF 2.0 vs SP 800-53 Rev. 5: control mapping and coverage gaps
Map CSF 2.0 outcomes to SP 800-53 Rev. 5 controls while preserving scope, tailoring, assessment, and partial-coverage limits.
NIST CSF 2.0 vs SP 800-53 Rev. 5: Which to Use
Choose CSF 2.0 for outcome-based cybersecurity governance or SP 800-53 Rev. 5 for control selection, tailoring, implementation, and assessment.
NIST CSF 2.0: step-by-step workflow for building current and target profiles
Build compatible NIST CSF 2.0 Current and Target Profiles, analyze each gap, and turn the comparison into a risk-informed action plan.
What should an NIST CSF 2.0 Current Profile include to be useful for audits and risk decisions?
A useful CSF 2.0 Current Profile should show current outcomes, accountable owners, supporting evidence, known gaps, dependencies, and review dates. It should be specific enough that a reviewer can understand what is true today without re-interviewing every team.
Which NIST CSF 2.0 metrics are useful for board and executive reporting?
Use board-level CSF 2.0 metrics that show risk decisions, business impact, target-profile gaps, and progress against priorities. Avoid only reporting control counts; executives need to see whether cybersecurity outcomes are improving in the context of organizational objectives.