Tiers (1–4) describe the sophistication of your cybersecurity risk management practices — they are a maturity assessment of how you govern and manage cybersecurity, not what you have implemented.
A Profile is a curated selection of CSF outcomes tailored to your organization's mission, risk tolerance, and resources — a Current Profile describes today; a Target Profile describes where you want to be.
The gap between Current and Target Profile is the implementation roadmap. Tiers help you contextualize how much effort closing that gap will require.
The NIST CSF is built around two complementary but distinct instruments — Tiers and Profiles — and they are frequently conflated, ignored, or used interchangeably. The result is CSF programs that either treat the Tier as a score to achieve ("we need to be at Tier 3") without implementing the underlying outcomes, or use the Framework Core without ever defining a Profile and therefore never measuring progress. Both instruments serve a real purpose; using them together, as NIST intended, produces a significantly more useful program.
The four Implementation Tiers — Partial (1), Risk Informed (2), Repeatable (3), and Adaptive (4) — describe how your organization manages cybersecurity risk in relation to its mission and risk environment. They are not a maturity scale for individual controls; they characterize the organizational context in which cybersecurity decisions are made. A Tier 1 organization has informal, reactive practices and no formal risk management integration. A Tier 3 organization has formally approved risk management practices that are consistently applied across the organization. A Tier 4 organization continuously adapts its cybersecurity practices based on real-time threat intelligence and lessons learned.
NIST is explicit that higher Tiers are not always better — the appropriate Tier is determined by the organization's risk tolerance, resources, and the criticality of its operations. A small professional services firm may be entirely appropriate at Tier 2; a critical infrastructure operator almost certainly needs Tier 3 or 4.
A CSF Profile is a prioritized selection of outcomes from the Framework Core — the subcategories across all six functions — that your organization has decided to implement based on its mission, legal and regulatory requirements, risk appetite, and available resources. A Current Profile describes the outcomes your organization is achieving today. A Target Profile describes the outcomes you want to achieve. The gap between the two is your implementation roadmap.
Profiles are intentionally flexible: two organizations in the same sector may have very different Profiles because their risk environments, customer commitments, and regulatory obligations differ. NIST provides sector-specific Profile guidance (for critical infrastructure, financial services, healthcare, etc.) as a starting point, but every Profile should be tailored to the specific organization.
The most practical way to use Tiers and Profiles together is to use the Tier assessment to contextualize the gap. Once you have a Current Profile and a Target Profile, the Tier tells you something about how much organizational change will be required to close the gap — not just what controls to implement, but how the organization needs to operate. A gap in the Govern function outcomes, combined with a Tier 1 or 2 assessment, signals that the issue is not just tooling but governance structure, accountability, and risk management integration. Closing it will require changes to how cybersecurity decisions are made and documented, not just additional security controls.