NIST CSF 2.0

Use a Current and Target Profile to connect business priorities, risk gaps, control ownership, and measurable improvement.

Set the business context

Define the mission or service, important assets, stakeholders, obligations, and risk appetite. Decide whether a single organization-wide Profile is useful or whether a major business unit or service needs its own. NIST’s six functions include Govern alongside Identify, Protect, Detect, Respond, and Recover.

The context determines what “good” means. A generic maturity score cannot replace an explicit statement of which outcomes matter most to the service.

Build Current and Target Profiles

For a Current Profile, describe which selected CSF outcomes are being achieved and with what evidence. For a Target Profile, select the outcomes needed to meet business and risk objectives. The gap is a decision aid: some controls need new investment, while others need a clearer owner or a better operating record.

Prioritize by consequence, feasibility, dependency, and available resources. Tie each action to a responsible person, timeframe, and way to measure whether the outcome improved.

Use Tiers for context, not as a score

CSF Tiers characterize the rigor of cybersecurity risk governance and management and can be applied to Profiles. They help leaders discuss how consistent and adaptive the program needs to be. NIST cautions that Tiers inform risk decisions; they do not replace a risk assessment or automatically define the right target.

Show where the target is deliberately different across functions or services. A single enterprise number often hides important trade-offs.

Keep the Profile alive

Review progress with control owners and executives. Refresh the Profile after incidents, acquisitions, major supplier changes, new services, or material threat shifts. Existing ISO/IEC 27001 and SOC 2 evidence may support selected outcomes, but each mapping should state the real scope and evidence period.

NIST CSF 2.0 does not itself create a certificate. Its value is a shared language for choosing and tracking risk-reduction work.

Put it into practice

  • Define a service or organizational boundary for the Profile.
  • Select and evidence Current outcomes before setting Target outcomes.
  • Prioritize gaps using risk, dependency, and business value.
  • Review the Profile as the operating environment changes.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources