FAQGLOBALNIST CSF 2.0

NIST CSF 2.0 How should teams handle tiers under NIST CSF 2.0

Use Tiers to describe the rigor of cybersecurity risk governance and management practices for a defined Profile, with observations that explain the characterization.

Tiers complement the organization's risk-management method. They do not replace it, certify conformity, score individual controls, or require every organization to target Tier 4.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 26, 2026
Questions
2

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 26, 2026
Overview

characterize the rigor of cybersecurity risk governance and management practices: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4). They can inform Current and Target Profiles, but they are not certification levels, universal maturity scores, or a requirement that every organization reach Tier 4.

Search this module

Find a question or answer quickly

2 of 2 questions
Question 1

What do CSF tiers mean in practice?

Select a Tier only after defining the Profile scope and reviewing both sides of NIST's notional illustration: cybersecurity risk governance and cybersecurity risk management. Consider how practices are approved and communicated, whether they operate organization-wide, how risk information is shared, how practices adjust to change, and how supplier risk is handled.

NIST encourages movement to a higher Tier when risks or mandates are greater or a cost-benefit analysis shows a feasible, cost-effective reduction in negative cybersecurity risk. A higher Tier is not automatically the right target for every scope, and a Tier should not be calculated by averaging unrelated control scores.

is voluntary guidance. It does not prescribe a Tier assessment formula, universal target, certification, effective date, or reassessment interval. A law, regulator, contract, or internal policy may set a separate expectation; record that authority and do not present it as a NIST requirement.

  • Document the Profile boundary, assessment date, and whether the characterization informs a or .
  • At Tier 1, look for ad hoc strategy application and irregular, case-by-case risk management with limited organizational and supplier-risk awareness.
  • At Tier 2, look for management-approved practices and organizational awareness without a consistently established organization-wide approach.
  • At Tier 3, look for formally approved policy, defined and reviewed processes, routine information sharing, consistent monitoring, and formal supplier-risk action.
  • At Tier 4, look for risk-informed adaptation, continuous improvement, predictive or near-real-time information, and integration of cybersecurity risk with organizational objectives and other enterprise risks.
  • Record contrary evidence and variation across business units instead of forcing a precise enterprise-wide number.
Citations
NIST CSF 2.0 (CSWP 29)

NIST CSF 2.0 is the primary source for using Tiers to characterize risk governance and management practices without treating them as a universal maturity score.

Question 2

What evidence should support tiers under NIST CSF 2.0?

Support the Tier characterization with observations about strategy approval, policy, repeatability, information sharing, risk monitoring, executive involvement, workforce capability, supplier-risk practices, and adaptation to change. The evidence should match the scope and assessment period.

If practices fit different Tier descriptions, explain the variation. The framework does not prescribe a formula for collapsing mixed evidence into a single score. Do not round, average, or select the highest observed practice without a documented method and decision authority.

Set an assessment date and review cadence for the selected Profile boundary. Reassess after material changes in risk, mandates, governance, leadership, business or mission objectives, technology, suppliers, or the boundary, and after improvement work changes the underlying practices. Retain the evidence set, contrary observations, method, reviewers, approver, and rationale for any Current or Target Tier.

  • Cite approved strategies, policies, governance records, risk reports, recurring process records, monitoring results, and supplier-risk records relevant to the Tier descriptions.
  • Record evidence periods, covered business units, exceptions, and practices that support a different Tier.
  • Name the authority approving a Target Tier and the owner of each improvement needed to reach it.
  • Tie proposed progression to risk, mandates, or a documented cost-benefit case rather than an assumed need to reach Tier 4.
  • Reassess when risk, requirements, governance, suppliers, mission objectives, or the Profile boundary changes.
Citations
NIST CSF 2.0 (CSWP 29)

NIST CSF 2.0 is the primary source for using Tiers to characterize risk governance and management practices without treating them as a universal maturity score.

Primary sources

References and citations

doi.org
Referenced sections
  • NIST CSF 2.0 is the primary source for using Tiers to characterize risk governance and management practices without treating them as a universal maturity score.
"does not prescribe how outcomes should be achieved"
Related guides

Explore more topics

How should teams handle evidence mapping under NIST CSF 2.0?
Map policies, configurations, tests, logs, approvals, and operating records to specific NIST CSF 2.0 outcomes without treating a reference or policy as proof of performance.
How should teams handle implementation examples under NIST CSF 2.0?
Use NIST CSF 2.0 Implementation Examples as optional, non-exhaustive ways to help achieve a Subcategory outcome, then tailor and test the chosen practice.
How should teams handle supplier risk under NIST CSF 2.0?
Apply NIST CSF 2.0 supplier-risk outcomes across selection, contracting, monitoring, incident coordination, and relationship exit, with effort based on criticality and risk.
How should teams handle target profiles under NIST CSF 2.0?
Build a NIST CSF 2.0 Target Profile by selecting and prioritizing desired Core outcomes, then turn Current-to-Target gaps into owned risk actions.
NIST CSF 2.0 Core Functions Guide
Understand GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER, including their Categories, concurrent use, ownership, evidence, and Profile decisions.
NIST CSF 2.0 current and target profile template: operating columns and evidence rows
A field-by-field NIST CSF 2.0 Current and Target Profile worksheet for compatible outcome comparisons, evidence, gaps, and action plans.
NIST CSF 2.0 Current vs Target Profile Template
Build a NIST CSF 2.0 Current and Target Profile with a defined scope, outcome-level evidence, priorities, owners, milestones, and reassessment triggers.
NIST CSF 2.0 Evidence Mapping Workflow
Map a NIST CSF 2.0 outcome to evidence, test what the record proves, document gaps, and assign the next risk decision.
NIST CSF 2.0 FAQ: practical implementation questions
Direct answers on NIST CSF 2.0 Tiers, GOVERN, Profiles, supplier risk, Implementation Examples, evidence mapping, and board reporting.
NIST CSF 2.0 GOVERN Function FAQ
Start the NIST CSF 2.0 GOVERN function by naming decision owners, risk strategy, policy expectations, oversight cadence, and supplier-risk accountability before mapping controls.
NIST CSF 2.0 Governance and Metrics Guide
Connect NIST CSF 2.0 GOVERN outcomes to decisions, owners, risk appetite, and metrics without inventing a single maturity score.
NIST CSF 2.0 Implementation Examples Guide
Use NIST CSF 2.0 Implementation Examples as optional prompts, adapt them to one scoped outcome, and define evidence that tests the result.
NIST CSF 2.0 Profile Workshop Template
A fill-in NIST CSF 2.0 Profile workshop template for scope, roles, outcome decisions, evidence gaps, approvals, and follow-up.
NIST CSF 2.0 Profile Workshop Workflow
Prepare and run a NIST CSF 2.0 Profile workshop that produces scoped outcome decisions, evidence requests, and an owned gap plan.
NIST CSF 2.0 Requirements Mapping Guide
Build a traceable mapping from applicable requirements to NIST CSF 2.0 outcomes, controls, evidence, gaps, and owners without treating the mapping as proof of compliance.
NIST CSF 2.0 vs CIS Controls v8.1: Mapping and Gap Analysis
Map CSF 2.0 outcomes to CIS Controls v8.1 safeguards without confusing a crosswalk with implementation evidence or full outcome achievement.
NIST CSF 2.0 vs CIS Controls v8.1: Which to Use
Choose CSF 2.0 for outcome-based risk governance, CIS Controls v8.1 for prioritized safeguards, or combine them with separate claims and evidence.
NIST CSF 2.0 vs ISO/IEC 27001:2022: Which to Use
Choose CSF 2.0 for outcome-based cyber-risk governance or ISO/IEC 27001:2022 for a requirements-based ISMS and possible certification.
NIST CSF 2.0 vs NIST RMF: practical side-by-side comparison
Decide when to use NIST CSF 2.0 outcomes and Profiles, when to use the seven-step NIST RMF process, and how to connect their evidence.
NIST CSF 2.0 vs SP 800-53 Rev. 5: control mapping and coverage gaps
Map CSF 2.0 outcomes to SP 800-53 Rev. 5 controls while preserving scope, tailoring, assessment, and partial-coverage limits.
NIST CSF 2.0 vs SP 800-53 Rev. 5: Which to Use
Choose CSF 2.0 for outcome-based cybersecurity governance or SP 800-53 Rev. 5 for control selection, tailoring, implementation, and assessment.
NIST CSF 2.0: step-by-step workflow for building current and target profiles
Build compatible NIST CSF 2.0 Current and Target Profiles, analyze each gap, and turn the comparison into a risk-informed action plan.
What should an NIST CSF 2.0 Current Profile include to be useful for audits and risk decisions?
A useful CSF 2.0 Current Profile should show current outcomes, accountable owners, supporting evidence, known gaps, dependencies, and review dates. It should be specific enough that a reviewer can understand what is true today without re-interviewing every team.
Which NIST CSF 2.0 metrics are useful for board and executive reporting?
Use board-level CSF 2.0 metrics that show risk decisions, business impact, target-profile gaps, and progress against priorities. Avoid only reporting control counts; executives need to see whether cybersecurity outcomes are improving in the context of organizational objectives.