# NIST CSF 2.0 Maturity Tiers, Explained (Partial to Adaptive) > NIST CSF 2.0 defines four tiers — Partial, Risk-Informed, Repeatable, Adaptive — that describe how mature and integrated your cybersecurity risk management is. What each tier means and how to run a maturity assessment. Source: https://playciso.com/blog/nist-csf-2-0-maturity-tiers-explained · Published: 2026-09-26 · Publisher: PlayCISO (https://playciso.com) --- "What NIST CSF tier are we?" is one of the most common board-level security questions, and it is easy to answer badly — by treating the Tiers as a report-card grade to maximise. NIST CSF 2.0 is explicit that they are not. The four Tiers describe _how_ your organisation manages cybersecurity risk — how formal, how integrated, how adaptive — not a score you should push to the top for its own sake. Here is what each Tier actually means, and how to run a maturity assessment that produces a plan rather than just a number. ## The four Tiers - Tier 1 — Partial: risk management is ad hoc and reactive. Cybersecurity risk is handled case by case, awareness is limited, and there is little organisation-wide coordination. - Tier 2 — Risk-Informed: risk-management practices are approved by management but may not be established as organisation-wide policy. Awareness exists but processes are inconsistent across the business. - Tier 3 — Repeatable: practices are formally defined, documented, consistently applied, and regularly updated as risk and business change. Roles and responsibilities are clear. - Tier 4 — Adaptive: the organisation continuously improves its practices from lessons learned and predictive indicators, and cybersecurity risk is embedded in enterprise risk culture and budgeting. Read them as a description of rigour and integration, not a ladder everyone must climb to the top of. ## Tiers are not a target — profiles are The practical mechanism in CSF 2.0 is the **Organizational Profile**: a Current Profile (what you do today) and a Target Profile (what your risk appetite, obligations and resources justify). Maturity work is closing the gap between them across the six Functions — **Govern, Identify, Protect, Detect, Respond, Recover** — where Govern is new in 2.0 and makes governance a first-class part of the assessment. ## How to run the assessment - Score the Current Profile. Walk each Function and its Categories, rating how consistently and completely each outcome is achieved. - Set a Target Profile. Decide the appropriate level per Function based on risk — not a blanket Tier 4. - Identify and prioritise gaps. Turn the differences into a costed, owned action plan, worst-risk-first. - Re-assess periodically. Track movement to show the board progress and justify investment. Run an interactive scored assessment with the free [NIST CSF assessment tool →](/tools/nist-csf), grab templates from the [NIST CSF toolkit](/tools/nist-csf-toolkit), and see the step-by-step method in [how to run a CSF 2.0 assessment](/blog/nist-csf-2-0-assessment-how-to-guide). ## Frequently asked questions **What are the four Tiers?** Partial (ad hoc), Risk-Informed (approved but uneven), Repeatable (formal and consistent), Adaptive (continuously improving, embedded in enterprise risk). They describe rigour, not a grade. **Does everyone need Tier 4?** No — NIST says progress to higher Tiers only when it reduces risk cost-effectively. **How is the assessment done?** Score a Current Profile across the six Functions, set a risk-appropriate Target Profile, close the gap, re-assess. **What changed in 2.0?** The Govern Function was added, scope broadened to all organisations, and Organizational Profiles became the vehicle for measuring maturity.