Skip to main content
GuidesBy Jason LeeAugust 28, 20267 min read

NIST CSF Maturity Levels: The Four Tiers Explained

NIST CSF Maturity Levels: The Four Tiers Explained

The direct answer: NIST CSF 2.0 has four Tiers, Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4). Most people searching for "NIST CSF maturity levels" are looking for these. NIST itself calls them Implementation Tiers and never calls them maturity levels, and that distinction changes how you should use them. They describe how rigorously you govern and manage cybersecurity risk. They do not score how many controls you have implemented, and no Tier makes you compliant or certified.

Sourced from NIST SP 1302, the CSF 2.0 Quick-Start Guide for Using the CSF Tiers, published October 2024. Status verified August 28, 2026.

The four Tiers

NIST's own framing is that the Tiers "capture an organization's outcomes over a range" and "reflect a progression from informal, ad hoc responses to approaches that are agile, risk-informed, and continuously improving." Appendix B of the CSF carries the full notional descriptions.

Tier What it describes What it looks like in practice
Tier 1
Partial
Ad hoc, reactive risk management with limited awarenessSecurity decisions happen case by case. There is no organization-wide approach, and risk is discussed after incidents rather than before them.
Tier 2
Risk Informed
Awareness exists, but practice is not organization-wideIn NIST's words, there is awareness of cybersecurity risks at the organizational level, but an organization-wide approach has not been established. Risk assessment happens but is "not typically repeatable or reoccurring," and information is shared informally.
Tier 3
Repeatable
Practices are formalized as policy and applied consistentlyRisk management is expressed in approved policy, applied consistently across the organization, and updated on a defined cadence rather than after surprises.
Tier 4
Adaptive
Practices are continuously improved from experience and threat intelligenceThe organization adapts its approach based on lessons learned and predictive indicators, and cybersecurity risk is managed as part of enterprise risk.

Why NIST does not call these maturity levels

This is the part most summaries get wrong, and it matters commercially. A maturity model implies that a higher number is always better and that the goal is to reach the top. The CSF Tiers are not built that way. NIST's guidance is that "progression to higher Tiers is encouraged when needed to address risks or mandates," which makes the target a business decision rather than a default ambition.

The second reason is scope. Tiers characterize the rigor of your risk governance and management. They say nothing directly about how many controls you have deployed or how well they operate. An organization can hold a large control inventory and still sit at Tier 1 because nothing governs how those controls are chosen, funded, or reviewed. That is a common and expensive pattern.

NIST is also explicit about the limit of the instrument: "Tiers should be used to guide and inform an organization's cybersecurity risk governance and management methodologies rather than take their place." A Tier is a lens, not a program.

Not sure which Tier you are actually at?

A Z Cyber advisor runs the assessment against the Govern and Management descriptions and shows you the gap to your target Tier.

NIST CSF Assessment →

Governance and management are scored separately

Each Tier carries two distinct descriptions. Cybersecurity Risk Governance corresponds to the Govern Function, which CSF 2.0 moved to the center of the framework. Cybersecurity Risk Management covers the other five Functions: Identify, Protect, Detect, Respond, and Recover.

That split is useful, because organizations are rarely uniform. A company can run competent detection and response while its governance is informal, or the reverse. NIST explicitly allows using only one component if your scope calls for it: if you are assessing governance only, you can omit the risk management descriptions entirely.

How leadership is supposed to select a Tier

NIST places Tier selection with organization leadership, not with the security team alone, and recommends selecting Tiers overall or at the Function or Category level rather than at the Subcategory level, because a higher-level selection gives a better sense of actual practice.

The factors NIST names for the decision are worth reading as a checklist:

  • Current risk management practices
  • Threat environment
  • Legal and regulatory requirements
  • Information sharing practices
  • Business and mission objectives
  • Supply chain requirements
  • Organizational constraints, including resources

The test NIST sets is that the selected Tiers "help to meet organizational goals, are feasible to implement, and reduce cybersecurity risks to critical assets and resources to levels that are acceptable to the organization." Feasibility is written into the standard. A Tier 4 target that the budget cannot sustain is not an ambitious plan, it is a failed one.

Applying Tiers to your Current and Target Profiles

Tiers and Profiles work together. Once leadership selects a Tier, your Current Profile reflects how well those Tier characteristics are achieved today for each Category in scope, and your Target Profile reflects the improvements needed to fully meet the Tier description. That pairing is what turns a Tier from a label into a roadmap, and it is the mechanism our CSF 2.0 compliance checklist walks through in sequence.

How CSF Tiers differ from the maturity models you may be comparing them to

Buyers usually arrive at this question holding another model in mind, so the contrasts are worth stating plainly.

CMMC levels are a certification scheme tied to federal contract requirements, with defined control sets and, for some levels, third-party assessment. A CSF Tier is self-selected and confers nothing contractually. We cover that program separately in the CMMC status tracker.

The retired FFIEC CAT paired inherent risk with maturity domains for financial institutions. Since its sunset, examiners point to recognized frameworks including CSF 2.0, which is why so many banks and credit unions are now mapping to CSF Tiers for the first time. Our CAT migration guide covers that transition.

ISO 27001 is a certifiable management system with an external audit and a certificate. The CSF has no certification body and no certificate, which is precisely why Tiers are a planning instrument rather than a market signal. If you are weighing certifiable options, see ISO 27001 versus SOC 2.

A realistic target for mid-market organizations

For most mid-market companies the defensible target is Tier 3, Repeatable, with Tier 4 reserved for the Functions where the threat environment or a regulator genuinely demands it. Tier 3 is where risk management stops depending on individual initiative: policy is approved, practice is consistent, and the cadence survives a change of staff. That is also the point at which auditors, carriers, and enterprise customers can see a program rather than a collection of tools.

Getting there is less about buying anything and more about whether the governance clock has an owner. If you want a read on where you actually sit against the Govern and Management descriptions, talk to a Z Cyber advisor, or start with our NIST CSF assessment.

Primary sources

The Tier names, the progression language, the selection guidance, and the Tier 2 description quoted above come from NIST SP 1302, the CSF 2.0 Quick-Start Guide for Using the CSF Tiers (October 2024). The full notional Tier descriptions live in Appendix B of the CSF 2.0 framework document itself.

Frequently Asked Questions

What are the NIST CSF maturity levels?

NIST CSF 2.0 defines four Tiers: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4). NIST calls them Implementation Tiers, not maturity levels. They reflect a progression from informal, ad hoc responses to approaches that are agile, risk informed, and continuously improving, and they characterize the rigor of an organization's cybersecurity risk governance and management.

Is the NIST Cybersecurity Framework a maturity model?

No. NIST does not present the CSF as a maturity model and does not use the word maturity for the Tiers. The Tiers characterize how rigorously an organization governs and manages cybersecurity risk, not how many controls it has implemented. A Tier is a description of practice, not a score or a certification, and no Tier makes an organization compliant or certified.

What is the difference between a CSF Tier and a CSF Profile?

A Profile describes which outcomes an organization is targeting, drawn from the CSF Core. A Tier describes how rigorously it governs and manages risk. NIST's guidance is to apply Tiers to Profiles: once leadership selects a Tier, the Current Profile reflects how well those characteristics are achieved today, and the Target Profile reflects the improvements needed to fully meet the Tier description.

Should every organization aim for Tier 4 Adaptive?

No. NIST says progression to higher Tiers is encouraged when needed to address risks or mandates, which makes the target a business decision rather than a default. Leadership is meant to select a Tier by weighing current practices, the threat environment, legal and regulatory requirements, business objectives, supply chain requirements, and organizational constraints including resources. For many mid-market organizations Tier 3 is the defensible target.

Can you have different CSF Tiers for different Functions?

Yes. NIST recommends selecting Tiers overall or at the Function or Category level rather than at the lower Subcategory level. Each Tier carries separate descriptions for Cybersecurity Risk Governance, which maps to the Govern Function, and Cybersecurity Risk Management, which covers Identify, Protect, Detect, Respond, and Recover. An organization can legitimately target Tier 3 for Govern and Tier 2 elsewhere.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.