NIST CSF 2.0 maturity assessments

Updated

A NIST CSF 2.0 assessment measures how well a client achieves the outcomes in the framework’s six functions: Govern, Identify, Protect, Detect, Respond and Recover. CSF describes outcomes rather than prescribing controls, and it has no built-in maturity score for each outcome. That makes it flexible, and it means the consultant has to bring a consistent scoring method. The useful deliverable is a current profile, a target profile and a prioritized path between them.

How CSF 2.0 is structured

CSF 2.0 organizes outcomes into 6 functions, 22 categories and 106 subcategories. Subcategory identifiers such as PR.AA-01 combine the function (PR for Protect), the category (AA for Identity Management, Authentication and Access Control) and a number.

Function What it covers
Govern (GV) Strategy, risk tolerance, roles, policy, oversight and supply chain risk
Identify (ID) Asset management, risk assessment and improvement
Protect (PR) Identity and access, awareness and training, data security, platform security and resilience
Detect (DE) Continuous monitoring and analysis of adverse events
Respond (RS) Incident management, analysis, reporting and mitigation
Recover (RC) Restoring assets and operations, and communicating during recovery

Profiles and Tiers

A current profile records the outcomes the client achieves today. A target profile records the outcomes they want, based on their risks and priorities. The gap between the two is the roadmap.

Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous the organization’s overall risk governance and management are. They are not a score for each subcategory.

A practical scoring rubric

Clients and boards want numbers they can compare over time. A rubric tied to evidence keeps those numbers defensible. This is the scale Control+s uses for every control:

Score Meaning What the evidence shows
0 Not implemented Evidence establishes neither intent nor implementation
1 Intent A policy, plan or stated expectation exists, but implementation is not shown
2 Partial Implementation is visible but narrow, inconsistent or one-off
3 Defined and repeatable A documented process, followed repeatedly in the assessed scope
4 Managed and measured Monitoring, review, metrics or management follow-through
5 Improved over time A review-and-improvement cycle that has changed the practice

Two rules keep the scale honest. Missing evidence is not proof of a zero: it leaves the outcome unresolved. And a policy on its own stays at intent, however good the policy is.

How Control+s supports CSF assessments

  • Scope the profile. Record the organizational profile, target outcomes, risk tolerance and key supplier dependencies before scoring.
  • Score every subcategory against evidence with the rubric above, a rationale citing the evidence, and the gaps that remain. You review and override.
  • Show the picture by function and category, with evidence coverage alongside the results so unassessed areas stay visible.
  • Reuse evidence for ISO 27001, CIS Controls or SOC 2 in the same assessment.
  • Compare cycles. Start the next assessment from the last one and show what changed.

Frequently asked questions

What are the six functions of NIST CSF 2.0?

Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in version 2.0, published on 26 February 2024. It covers strategy, roles, policy, oversight and supply chain risk management.

Do NIST CSF Tiers measure maturity?

Not per outcome. The four Tiers (Partial, Risk Informed, Repeatable and Adaptive) describe how rigorous an organization's cyber security risk governance and management practices are overall. Most consultants who need comparable numbers use their own maturity scale for each subcategory and keep Tiers for the overall picture.

Is there a newer version than CSF 2.0?

As of September 2026, CSF 2.0 is the current version. NIST continues to publish supporting material, such as Informative References, quick-start guides and community profiles.

How do I compare CSF results from one year to the next?

Use the same scoring rubric each cycle, tie each score to evidence, and record why a score changed. Control+s keeps the history of every control across cycles, so you can show the client what moved and why.

Sources

  1. NIST: The NIST Cybersecurity Framework (CSF) 2.0, CSWP 29
  2. NIST: CSF 2.0 Informative References
  3. NIST: Cybersecurity Framework updates archive

Bring your next assessment to Control+s.

Start free with two frameworks and five evidence files. Use your own material to inspect the mapping, reasoning, and results, and see how Control+s fits your engagements.

Help shape the product around real consulting work. We welcome teams who want to build their assessment workflow with us.

Running a larger program? .