Key Takeaways
1. NIST CSF 2.0 Does Not Define Formal Maturity Levels: Organizations can create their own maturity scoring methodology, while using Organizational Profiles and Implementation Tiers to assess cybersecurity outcomes and the rigor of risk management practices.
2. Meaningful Maturity Assessments Require More Than a Single Score: Effective assessments combine evidence-based ratings, Current and Target Profiles, and analysis across all six CSF Functions to reveal where capabilities are strong, inconsistent, or underdeveloped.
3. Cybersecurity Maturity Should Be Driven by Risk, Not the Highest Possible Rating: The appropriate target varies across organizations, systems, and business functions. The goal is to reach the level of capability needed to manage risk effectively—not simply maximize a maturity score.
For cybersecurity leaders, knowing what controls are in place is only part of the picture. The bigger question is whether those controls are consistently implemented, governed, measured, and improved as risks change.
That is where cybersecurity maturity assessments become valuable. By evaluating NIST CSF 2.0 maturity levels, organizations can establish a baseline for their cybersecurity program, identify weaknesses, prioritize investments, and measure progress toward a stronger target state.
However, NIST CSF 2.0 does not prescribe a formal set of “maturity levels.” Instead, the framework provides Organizational Profiles for assessing cybersecurity outcomes and Implementation Tiers for characterizing the rigor of cybersecurity risk governance and management. NIST also allows organizations to apply their own rating scales when evaluating Current Profiles.
As a result, determining your NIST CSF maturity levels requires more than choosing a number between one and four. A meaningful assessment combines evidence-based scoring, Current and Target Profiles, Implementation Tiers, and business risk to understand both where the organization stands today and where it needs to go next.
NIST CSF Maturity Levels vs. Implementation Tiers
The terms are often used interchangeably, but NIST CSF maturity levels and Implementation Tiers are not exactly the same thing.
A maturity assessment typically assigns ratings to cybersecurity practices or outcomes so that an organization can quantify its current capabilities and track improvement. NIST’s Organizational Profile guidance explicitly allows organizations to evaluate current practices using scales such as high/medium/low, 1–5, 0–100%, or red/yellow/green.
Implementation Tiers serve a different purpose. They characterize the rigor of an organization’s overall cybersecurity risk governance and risk management practices:
Tier 1: Partial
At Tier 1, cybersecurity risk management tends to be informal and reactive. Risk strategy and prioritization may be handled on an ad hoc basis, organizational awareness of cybersecurity risk is limited, and risk management activities often occur case by case.
Tier 2: Risk Informed
At Tier 2, management understands cybersecurity risk and uses risk information to help prioritize security activities. However, practices may not yet be formalized or implemented consistently across the entire organization.
Tier 3: Repeatable
Tier 3 organizations have established, formally approved cybersecurity policies and risk management practices. Processes are implemented consistently across the organization, cybersecurity information is routinely shared, and leadership regularly considers cyber risk as part of business operations.
Tier 4: Adaptive
At Tier 4, cybersecurity risk management is embedded in organizational culture and continually evolves. Organizations use lessons learned, changing risk conditions, and predictive indicators to adapt practices. Cybersecurity risk is considered alongside other enterprise risks, and practices continuously improve as business objectives, technology, and threats change.
How to Assess NIST CSF 2.0 Maturity Levels
1. Define the Scope of the Assessment
Before assigning scores, establish what you are actually assessing.
A maturity assessment might cover the entire enterprise, but it can also focus on a specific business unit, technology environment, product, data type, or regulatory scope. Large or complex organizations may need multiple profiles rather than a single enterprise-wide maturity score.
Define:
- Systems, applications, and infrastructure in scope
- Business units and geographic locations
- Critical data and business processes
- Third parties and supply chain dependencies
- Applicable laws, regulations, and contractual requirements
- Key stakeholders responsible for the assessment
A clearly defined scope helps make maturity scores comparable over time. Otherwise, an apparent improvement or decline may simply reflect a change in what was assessed.
2. Build Your Current Profile
Next, assess how well the organization currently achieves the applicable CSF outcomes.
NIST recommends documenting current cybersecurity practices within a Current Profile, including policies, processes, procedures, activities, and evidence that demonstrates whether an outcome is being achieved.
This is where an organization can introduce a standardized maturity scale. For example, an internally defined five-point methodology might distinguish between practices that are:
- Not established: The expected practice or capability is largely absent.
- Partially implemented: Some activities occur, but implementation is inconsistent or informal.
- Defined and implemented: Policies and processes are documented and generally followed.
- Managed and measured: Practices are consistently implemented, monitored, and measured.
- Continuously improved: Performance data, lessons learned, and changing risks are systematically used to improve practices.
Note that this scale is not an official NIST five-level maturity model. Rather, it is an example of how organization-defined assessment methodology can be applied to NIST CSF outcomes.
3. Require Evidence Behind Every Rating
One of the biggest mistakes organizations can make is treating a maturity assessment like a questionnaire.
A control owner may believe a process is mature because the team performs it regularly. An objective assessment may reveal that the process is undocumented, inconsistently applied, dependent on a single employee, or not measured for effectiveness.
Ratings should therefore be supported by evidence such as:
- Approved policies and procedures
- Risk registers and risk assessments
- Asset inventories
- Security architecture documentation
- Vulnerability and patching records
- Access reviews
- Security monitoring records
- Incident response plans and exercises
- Business continuity and recovery testing
- Third-party risk assessments
- Interviews with control owners and business leaders
4. Evaluate Maturity Across the Six CSF Functions
After assessing individual outcomes, aggregate the results to identify patterns across the six NIST CSF 2.0 Functions: Govern, Identify, Protect, Detect, Respond, and Recover.
An organization might discover, for example, that Protect and Detect capabilities are relatively advanced because years of investment have gone into technical safeguards and security monitoring. At the same time, Govern may lag because risk ownership, executive reporting, supply chain governance, or cybersecurity metrics remain informal. That result is more useful than a single enterprise maturity score.
A company that reports “3.4 out of 5” without understanding where the weaknesses lie has gained very little actionable insight. A company that knows its recovery practices are significantly less mature than its preventative controls can make a much more informed investment decision.
5. Create a Risk-Based Target Profile
Once the Current Profile establishes where the organization stands, the Target Profile establishes where it needs to go.
NIST defines a Target Profile around the desired cybersecurity outcomes an organization has selected and prioritized according to its cybersecurity risk management objectives. It can account for changes such as new regulatory requirements, emerging technologies, and evolving threat intelligence.
Organizations should consider:
- Business and mission objectives
- Risk tolerance
- Criticality of systems and data
- Threat environment
- Customer expectations
- Legal and regulatory obligations
- Contractual requirements
- Supply chain risks
- Available staffing and budget
- Planned technology and business changes
A highly regulated financial application, for example, may require significantly more mature controls than a low-risk internal system. Applying the same target to both could either leave critical risk unresolved or direct resources toward improvements that offer little additional business value. Cybersecurity maturity is ultimately about reaching the level of capability necessary to manage risk, not maximizing a score.
6. Use NIST CSF Tiers to Add Organizational Context
Maturity scores tell you how effectively individual outcomes are being achieved. CSF Tiers help answer another question: How consistently and strategically does the organization manage cybersecurity risk as a whole?
NIST recommends considering factors including current risk management practices, the threat environment, regulatory requirements, information sharing, business objectives, supply chain requirements, and organizational resource constraints when selecting Tiers.
An organization may also evaluate Tiers at the overall, Function, or Category level rather than forcing one rating across every element of the CSF.
For example, an organization might demonstrate Tier 3 characteristics around its Protect activities but operate closer to Tier 2 in cybersecurity governance. That difference can reveal an important strategic issue: strong technology may be compensating for immature organizational processes.
For many cybersecurity leaders, those differences are precisely where the most valuable maturity conversations begin.
7. Perform a Gap Analysis and Build a Roadmap
The real value of determining NIST CSF 2.0 maturity levels comes after the scoring is finished.
Compare the Current Profile with the Target Profile to identify the gaps that matter most. NIST’s Organizational Profile methodology specifically calls for organizations to analyze those differences and build a prioritized action plan based on factors such as mission drivers, risk, benefits, staffing, and funding.
Your roadmap should answer:
- Which gaps create the greatest business or cybersecurity risk?
- Which improvements are required by regulations or customer commitments?
- What can be remediated quickly?
- Which initiatives require longer-term investment?
- Who owns each improvement?
- What resources are required?
- What metrics will demonstrate progress?
This converts a maturity assessment from a snapshot into a management tool.

NIST CSF Maturity Is a Measure of Progress, Not a Finish Line
The most useful NIST CSF maturity levels help leadership understand where cybersecurity practices are working, where risk remains, and what investments should come next.
NIST CSF 2.0 is intentionally flexible. Organizations can define assessment scales appropriate to their environments, use Current and Target Profiles to evaluate individual outcomes, and apply Implementation Tiers to understand the rigor of cybersecurity risk governance and management. NIST’s own guidance calls for organizations to repeat the process as risks and priorities evolve.
That flexibility is powerful, but it also places responsibility on organizations to use a consistent and defensible methodology. An objective maturity assessment can help validate internal assumptions, benchmark current practices, and turn hundreds of cybersecurity considerations into a prioritized improvement roadmap.
IS Partners helps organizations evaluate cybersecurity programs through objective assessments, gap analyses, risk assessments, document reviews, and continuous monitoring strategies. An independent assessment can also help organizations connect NIST requirements with other standards and compliance obligations, reducing duplicated effort while creating a clearer view of enterprise risk.
Ultimately, determining your NIST CSF 2.0 maturity is not about arriving at a number. It is about creating an evidence-based understanding of where your cybersecurity program stands today—and a risk-informed plan for where it needs to go next.
What Should You Do Next?
Establish a Consistent NIST CSF Maturity Assessment Methodology: Define the scope of your assessment, select a standardized rating scale, and evaluate applicable CSF outcomes using documented evidence rather than self-reported practices alone.
Build Current and Target Profiles Based on Business Risk: Use your Current Profile to establish where cybersecurity capabilities stand today, then define a risk-based Target Profile that reflects business objectives, regulatory requirements, system criticality, and available resources.
Prioritize Gaps and Create a Maturity Improvement Roadmap: Compare current and target states across Govern, Identify, Protect, Detect, Respond, and Recover. Focus remediation on the gaps that create the greatest business risk, assign ownership, and establish metrics for tracking progress over time.








