What do CSF tiers mean in practice?
Select a Tier only after defining the Profile scope and reviewing both sides of NIST's notional illustration: cybersecurity risk governance and cybersecurity risk management. Consider how practices are approved and communicated, whether they operate organization-wide, how risk information is shared, how practices adjust to change, and how supplier risk is handled.
NIST encourages movement to a higher Tier when risks or mandates are greater or a cost-benefit analysis shows a feasible, cost-effective reduction in negative cybersecurity risk. A higher Tier is not automatically the right target for every scope, and a Tier should not be calculated by averaging unrelated control scores.
is voluntary guidance. It does not prescribe a Tier assessment formula, universal target, certification, effective date, or reassessment interval. A law, regulator, contract, or internal policy may set a separate expectation; record that authority and do not present it as a NIST requirement.
- Document the Profile boundary, assessment date, and whether the characterization informs a or .
- At Tier 1, look for ad hoc strategy application and irregular, case-by-case risk management with limited organizational and supplier-risk awareness.
- At Tier 2, look for management-approved practices and organizational awareness without a consistently established organization-wide approach.
- At Tier 3, look for formally approved policy, defined and reviewed processes, routine information sharing, consistent monitoring, and formal supplier-risk action.
- At Tier 4, look for risk-informed adaptation, continuous improvement, predictive or near-real-time information, and integration of cybersecurity risk with organizational objectives and other enterprise risks.
- Record contrary evidence and variation across business units instead of forcing a precise enterprise-wide number.
NIST CSF 2.0 is the primary source for using Tiers to characterize risk governance and management practices without treating them as a universal maturity score.
NIST resource center for CSF 2.0 quick-start guides, examples, profiles, and informative references.
NIST risk assessment guidance used as adjacent support for risk analysis and prioritization.