# NIST CSF 2.0 maturity assessments

> How to assess a client against NIST CSF 2.0's six functions, why the framework has no built-in maturity scale, and a practical 0 to 5 scoring rubric that ties each score to evidence.

Canonical: https://controls.run/frameworks/nist-csf
Updated: 2026-09-29

A NIST CSF 2.0 assessment measures how well a client achieves the outcomes in the framework's six functions: Govern, Identify, Protect, Detect, Respond and Recover. CSF describes outcomes rather than prescribing controls, and it has no built-in maturity score for each outcome. That makes it flexible, and it means the consultant has to bring a consistent scoring method. The useful deliverable is a current profile, a target profile and a prioritized path between them.

## How CSF 2.0 is structured

CSF 2.0 organizes outcomes into 6 functions, 22 categories and 106 subcategories. Subcategory identifiers such as PR.AA-01 combine the function (PR for Protect), the category (AA for Identity Management, Authentication and Access Control) and a number.

| Function | What it covers |
|---|---|
| Govern (GV) | Strategy, risk tolerance, roles, policy, oversight and supply chain risk |
| Identify (ID) | Asset management, risk assessment and improvement |
| Protect (PR) | Identity and access, awareness and training, data security, platform security and resilience |
| Detect (DE) | Continuous monitoring and analysis of adverse events |
| Respond (RS) | Incident management, analysis, reporting and mitigation |
| Recover (RC) | Restoring assets and operations, and communicating during recovery |

## Profiles and Tiers

A **current profile** records the outcomes the client achieves today. A **target profile** records the outcomes they want, based on their risks and priorities. The gap between the two is the roadmap.

**Tiers** (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous the organization's overall risk governance and management are. They are not a score for each subcategory.

## A practical scoring rubric

Clients and boards want numbers they can compare over time. A rubric tied to evidence keeps those numbers defensible. This is the scale Control+s uses for every control:

| Score | Meaning | What the evidence shows |
|---|---|---|
| 0 | Not implemented | Evidence establishes neither intent nor implementation |
| 1 | Intent | A policy, plan or stated expectation exists, but implementation is not shown |
| 2 | Partial | Implementation is visible but narrow, inconsistent or one-off |
| 3 | Defined and repeatable | A documented process, followed repeatedly in the assessed scope |
| 4 | Managed and measured | Monitoring, review, metrics or management follow-through |
| 5 | Improved over time | A review-and-improvement cycle that has changed the practice |

Two rules keep the scale honest. Missing evidence is not proof of a zero: it leaves the outcome unresolved. And a policy on its own stays at intent, however good the policy is.

## How Control+s supports CSF assessments

- **Scope the profile.** Record the organizational profile, target outcomes, risk tolerance and key supplier dependencies before scoring.
- **Score every subcategory against evidence** with the rubric above, a rationale citing the evidence, and the gaps that remain. You review and override.
- **Show the picture by function and category**, with evidence coverage alongside the results so unassessed areas stay visible.
- **Reuse evidence** for ISO 27001, CIS Controls or SOC 2 in the same assessment.
- **Compare cycles.** Start the next assessment from the last one and show what changed.

## Frequently asked questions

### What are the six functions of NIST CSF 2.0?

Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in version 2.0, published on 26 February 2024. It covers strategy, roles, policy, oversight and supply chain risk management.

### Do NIST CSF Tiers measure maturity?

Not per outcome. The four Tiers (Partial, Risk Informed, Repeatable and Adaptive) describe how rigorous an organization's cyber security risk governance and management practices are overall. Most consultants who need comparable numbers use their own maturity scale for each subcategory and keep Tiers for the overall picture.

### Is there a newer version than CSF 2.0?

As of September 2026, CSF 2.0 is the current version. NIST continues to publish supporting material, such as Informative References, quick-start guides and community profiles.

### How do I compare CSF results from one year to the next?

Use the same scoring rubric each cycle, tie each score to evidence, and record why a score changed. Control+s keeps the history of every control across cycles, so you can show the client what moved and why.

## Related

- [ISO 27001 gap assessments for consultants](https://controls.run/frameworks/iso-27001)
- [CIS Controls v8.1 assessments for consultants](https://controls.run/frameworks/cis-controls)
- [Reusing evidence across ISO 27001, NIST CSF, CIS Controls, SOC 2 and CPCSC](https://controls.run/frameworks/cross-framework-evidence)

## Sources

- [NIST: The NIST Cybersecurity Framework (CSF) 2.0, CSWP 29](https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final)
- [NIST: CSF 2.0 Informative References](https://www.nist.gov/cyberframework/informative-references)
- [NIST: Cybersecurity Framework updates archive](https://www.nist.gov/cyberframework/updates-archive)

## About Control+s

Control+s is a control assessment platform for security consultants and vCISO teams. It maps client evidence across the frameworks in scope, drafts maturity scores with cited rationale for the assessor to review, and produces client deliverables.

- Try it free: https://controls.run/try
- Agent guide: https://controls.run/llms.txt
