- Directs organizations to implement the action plan, update the Organizational Profile, and repeat the cycle as often as needed.
References and citations
- Official source for rechecking the Core and supplementary resources when a Profile is revised.
A fill-in NIST CSF 2.0 Profile workshop template for scope, roles, outcome decisions, evidence gaps, approvals, and follow-up.
NIST does not require this meeting format. Use it when several owners must agree on Current and Target Profile judgments for one defined boundary.
Structured answer sets in this page tree.
Cited legal and guidance references.
Use this structured workshop to produce an draft, decision log, evidence requests, and owned gap plan for one explicit boundary. Prepare the risk context and supporting information in advance. Spend workshop time characterizing current outcomes, selecting and prioritizing target outcomes, resolving disagreements, and assigning follow-up work. NIST CSF 2.0, published on February 26, 2024, does not require this meeting format or set a universal Profile deadline.
The workshop should produce an approved scope, outcome-level Current and draft, unresolved questions, and prioritized gaps with owners. A Function-level color or average score cannot replace those records.
Invite people who can explain mission and risk priorities, current implementation and evidence, requirements and stakeholder expectations, supplier dependencies, and authority for target-state or risk-response decisions. Collect factual updates asynchronously when no group judgment is needed.
Complete and circulate the charter before the session. Use the same boundary for Current and Target judgments, and label any outcome that cannot be compared because its scope or time horizon differs.
Pre-read material should distinguish the official CSF outcome from optional Implementation Examples, Informative References, external requirements, internal controls, and evidence.
Keep the session focused on one boundary and a manageable set of outcomes. The facilitator owns the process and record, not the underlying risk decision.
Suggested roles: sponsor; Profile lead; facilitator; risk owner; system, process, control, supplier, and evidence owners as relevant; legal, compliance, privacy, procurement, audit, or assurance advisers when their subject matter is in scope.
Agenda: confirm charter and authority; review outcome cards; decide or qualify Current entries; select and prioritize Targets; analyze gaps and responses; assign actions; read back decisions, open questions, approvals, and reassessment triggers.
Evidence must support the stated scope and claim. A policy can show intent; system records, tests, transactions, tickets, approvals, and reviews may show deployment or operation, depending on the outcome.
Do not force agreement when evidence conflicts or authority is missing. Record the question, its effect on the Profile, the resolver, and a due date.
Use the cited sources to turn the guidance into scoped decisions, owners, evidence requests, and review checkpoints.
Create cited tasks, evidence requests, and review checkpoints for this NIST CSF 2.0 scope.
Check source coverage, ownership, evidence gaps, and next steps before publishing or operationalizing the work.
Read back every decision and open item before ending. After the session, issue the Profile version, action plan, evidence requests, and approval record through the organization's normal document and risk-governance process.
Update the only after the agreed evidence supports the revised characterization. Track gap actions in the organization's chosen action-plan format and preserve links back to the affected outcome rows.
Repeat the cycle after a material change in scope, requirements, threats, technology, supplier dependency, risk direction, evidence, or action status, and at any cadence the organization sets.