๐ŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
All posts

NIST CSF 2.0 Maturity Tiers, Explained (Partial to Adaptive)

September 26, 2026 ยท PlayCISO
TL;DR

The NIST Cybersecurity Framework (CSF) 2.0 describes cybersecurity risk-management maturity with four Tiers: Tier 1 Partial, Tier 2 Risk-Informed, Tier 3 Repeatable, and Tier 4 Adaptive. The Tiers are not a grade or a compliance target โ€” NIST is explicit that not every organisation needs to reach Tier 4. They describe the degree to which risk-management practices are formalised, integrated across the organisation, and informed by external context. A maturity assessment scores where you sit today across the six CSF 2.0 Functions (Govern, Identify, Protect, Detect, Respond, Recover), decides a target profile appropriate to your risk, and turns the gap into a prioritised plan. This explainer covers what each Tier means and how to run the assessment.

"What NIST CSF tier are we?" is one of the most common board-level security questions, and it is easy to answer badly โ€” by treating the Tiers as a report-card grade to maximise. NIST CSF 2.0 is explicit that they are not. The four Tiers describe how your organisation manages cybersecurity risk โ€” how formal, how integrated, how adaptive โ€” not a score you should push to the top for its own sake. Here is what each Tier actually means, and how to run a maturity assessment that produces a plan rather than just a number.

The four Tiers

  • Tier 1 โ€” Partial: risk management is ad hoc and reactive. Cybersecurity risk is handled case by case, awareness is limited, and there is little organisation-wide coordination.
  • Tier 2 โ€” Risk-Informed: risk-management practices are approved by management but may not be established as organisation-wide policy. Awareness exists but processes are inconsistent across the business.
  • Tier 3 โ€” Repeatable: practices are formally defined, documented, consistently applied, and regularly updated as risk and business change. Roles and responsibilities are clear.
  • Tier 4 โ€” Adaptive: the organisation continuously improves its practices from lessons learned and predictive indicators, and cybersecurity risk is embedded in enterprise risk culture and budgeting.

Read them as a description of rigour and integration, not a ladder everyone must climb to the top of.

Tiers are not a target โ€” profiles are

The practical mechanism in CSF 2.0 is the Organizational Profile: a Current Profile (what you do today) and a Target Profile (what your risk appetite, obligations and resources justify). Maturity work is closing the gap between them across the six Functions โ€” Govern, Identify, Protect, Detect, Respond, Recover โ€” where Govern is new in 2.0 and makes governance a first-class part of the assessment.

How to run the assessment

  1. Score the Current Profile. Walk each Function and its Categories, rating how consistently and completely each outcome is achieved.
  2. Set a Target Profile. Decide the appropriate level per Function based on risk โ€” not a blanket Tier 4.
  3. Identify and prioritise gaps. Turn the differences into a costed, owned action plan, worst-risk-first.
  4. Re-assess periodically. Track movement to show the board progress and justify investment.

Run an interactive scored assessment with the free NIST CSF assessment tool โ†’, grab templates from the NIST CSF toolkit, and see the step-by-step method in how to run a CSF 2.0 assessment.

Frequently asked questions

What are the four Tiers? Partial (ad hoc), Risk-Informed (approved but uneven), Repeatable (formal and consistent), Adaptive (continuously improving, embedded in enterprise risk). They describe rigour, not a grade.

Does everyone need Tier 4? No โ€” NIST says progress to higher Tiers only when it reduces risk cost-effectively.

How is the assessment done? Score a Current Profile across the six Functions, set a risk-appropriate Target Profile, close the gap, re-assess.

What changed in 2.0? The Govern Function was added, scope broadened to all organisations, and Organizational Profiles became the vehicle for measuring maturity.

Ready to practise the decisions these articles describe?

Run a free War Room โ†’
NIST CSF 2.0 Maturity Tiers, Explained (Partial to Adaptive) | PlayCISO Blog ยท PlayCISO