A NIST Privacy Framework Profile is a selection of privacy outcomes: either the ones your organisation achieves today, or the ones it needs to achieve. The difference between the two is what turns a framework into a plan.
A NIST Privacy Framework Profile is one of the framework’s three components, alongside the Core and Implementation Tiers. A toolkit or programme that ships only the Core has delivered a list of outcomes with no mechanism for deciding which of them matter to you.
What this guide covers
- The two NIST Privacy Framework Profiles: Current and Target
- Building an honest Current NIST Privacy Framework Profile
- Evidence, and what counts as it
- A Target Profile is chosen, not assumed
- Turning the NIST Privacy Framework Profile gap into a plan
- NIST Privacy Framework Profiles across a large organisation
- Common mistakes in a first NIST Privacy Framework Profile
- When to refresh a NIST Privacy Framework Profile
- A NIST Privacy Framework Profile is not an Implementation Tier
- Frequently asked questions
- Workbooks for both Profiles

The two NIST Privacy Framework Profiles: Current and Target
| Current Profile | Target Profile | |
|---|---|---|
| Question | What are we achieving now? | What do we need to achieve? |
| Basis | Evidence | Risk, obligations and strategy |
| Approved by | The privacy function | The accountable executive |
| Refreshed | At least annually | At least annually |
| Failure mode | Recording intentions as achievements | Assuming the target is everything |
The gap between the two is the programme’s work plan. Nothing else in the framework produces one, which is why a NIST Privacy Framework Profile is not an optional extra on top of the Core.
Building an honest Current NIST Privacy Framework Profile
For each of the 102 Subcategories in version 1.1, record one of four statuses:
- Achieved — happening repeatably, with evidence a third party would accept
- Partially achieved — happening for some systems, populations or cases
- Not achieved — not happening, or happening with no evidence
- Not applicable — with a recorded reason, which should be rare
Three rules make a Current Profile useful rather than flattering:
A document is not achievement. A retention policy that is not enforced does not achieve the retention outcome. The evidence is the deletion job’s output and a sample of records confirmed gone — not the policy that says they should be.
Partial is partial. An outcome achieved for the flagship system and not for the other forty is partially achieved. Recording it as achieved destroys the Profile’s value as a plan, because the gap analysis will not see the forty.
Not achieved is the expected first answer. An initial NIST Privacy Framework Profile showing most outcomes achieved is worth re-checking before it is approved: the test is whether each claim names evidence that exists independently of the assessor’s opinion.
Evidence, and what counts as it
Every “Achieved” claim in a NIST Privacy Framework Profile should name the artefact that evidences it. Evidence is something that exists independently of the assessor’s opinion — a record, a log, a test result, a completed register, a signed approval.
| Claim | Weak evidence | What to ask for instead |
|---|---|---|
| Data destroyed per policy | The retention policy | The destruction job’s output, plus records past their period confirmed gone |
| Personnel are trained | Completion rates | Comprehension results, and a sample of people asked a scenario question |
| Systems are inventoried | The inventory itself | The reconciliation record, and the count of systems found by reconciliation rather than registration |
| Preferences are honoured | The procedure | A preference set, a restore performed, the preference still in force afterwards |
| Suppliers are assessed | The assessment schedule | Completed assessments with evidence, and closure of any conditions |
Testing a sample of Achieved claims is the highest-value audit anyone can run against a NIST Privacy Framework Profile. The recurring finding is not a failed control but a claim supported by a document rather than by evidence that the document operates.
A Target Profile is chosen, not assumed
Here is the distinction that decides whether the plan is achievable. The Target Profile is not automatically all 102 Subcategories.
It is the set of outcomes needed to meet your privacy risk management goals, derived from assessed risks, legal and contractual obligations, your strategy, your role in the data processing ecosystem, stakeholder expectations, and the resources you actually have.
Deciding that an outcome is not a target is a legitimate, documented risk decision. Record it with its rationale. An unexamined “all of them” is a worse Target Profile than a reasoned subset, and it is a plan you will fail to deliver — which then shows up as an audit finding against your own stated intent.
Where resources cannot deliver the target, the honest response is to reduce the target and say so, not to leave commitments in place that will be missed.
Turning the NIST Privacy Framework Profile gap into a plan
For each gap — an outcome that is a target and is not achieved — record:
- The Subcategory and the outcome not currently achieved
- The privacy risk that stays open while it is not achieved, cross-referenced to your risk register
- The action, its owner and its due date
- The evidence that will demonstrate closure, stated now rather than decided later
Point 2 is the one that gives the plan its order. Gaps are prioritised by the risk they leave open, not by how easy they are to close — and a gap with no linked risk entry is a gap nobody has justified closing. That usually means either the target was set too wide, or the risk assessment missed something. Both are worth knowing.
NIST Privacy Framework Profiles across a large organisation
Where NIST Privacy Framework Profiles exist at more than one level — organisation-wide and per business unit — the organisation-wide Current Profile records the weakest position across the units, not an average.
An outcome achieved in three units and absent in the fourth is partially achieved organisation-wide. Averaging it produces a Profile that describes nowhere, and it hides the unit that needs attention.
Common mistakes in a first NIST Privacy Framework Profile
Four patterns are worth naming in advance, because each is cheap to avoid and expensive to unpick afterwards.
| Mistake | What it looks like | Consequence |
|---|---|---|
| Assessing before mapping | The Profile is completed before the data map exists | It records what people believe the organisation does. The systems nobody remembered are the ones with the least governance |
| Targeting before assessing | The Target Profile is set before the risk register exists | The target is a wish list rather than a response to assessed risk, and cannot be defended at review |
| Scoring the policy | “Achieved” wherever a document exists | The gap analysis finds nothing, because a Profile of unearned “Achieved” statuses has no gaps in it to find |
| Averaging across units | An outcome achieved in three of four units recorded as achieved | The unit that needs attention disappears from the plan |
The first two are sequencing errors and the fix is simply to do the steps in order. The second two are honesty errors, and the fix is to have someone who did not perform the assessment test a sample of the claims before the Profile is approved.
When to refresh a NIST Privacy Framework Profile
At least annually, and on any of: a new or materially changed system; a new processing purpose; a change in the population affected; a change in your ecosystem role; a merger, acquisition or divestment; a significant problematic data action; or a change in your legal obligations.
One further trigger is specific to the current draft. If NIST publishes the final version of Privacy Framework 1.1 and renumbers the Subcategory identifiers — something the draft’s own Note to Reviewers explicitly asks reviewers about — remap before you reassess. Evidence pointed at a renumbered identifier is evidence attached to the wrong outcome. See what changed between 1.1 and 1.0 for the mapping this involves.
A NIST Privacy Framework Profile is not an Implementation Tier
| Profile | Implementation Tier | |
|---|---|---|
| Answers | Which outcomes do we achieve? | How rigorously do we manage privacy risk? |
| Unit | Subcategories | The programme as a whole |
An organisation can achieve many outcomes in its NIST Privacy Framework Profile at low rigour — through individual effort and institutional memory rather than through process. That is a strong Current Profile on a fragile programme, and only the Tier assessment reveals it.
See Implementation Tiers for how that assessment works, and why Tier 4 is not the target for every organisation.
For the framework overall see our NIST Privacy Framework guide, and for the analysis that should precede any scoring, problematic data actions. The framework and its Core are free at nist.gov/privacy-framework.
Frequently asked questions
How long does a first Current Profile take?
Less time than the work that must precede it. The inventory and data map dominate the schedule, because you cannot assess outcomes for processing you have not yet described. Once the map exists, assessing 102 outcomes is a matter of weeks rather than months.
Can we use a Target Profile from elsewhere?
A published community or sector Profile is a useful starting point and a poor finishing point. Your target should follow from your own assessed risks, obligations and ecosystem role. Adopting someone else’s wholesale reproduces their judgement about their circumstances.
Who signs off a NIST Privacy Framework Profile?
The privacy function owns the Current Profile because it is a statement of fact about evidence. The Target Profile should be approved by whoever is accountable for privacy risk and controls the resources, because choosing it commits money and people.
What if an outcome genuinely does not apply?
Record it as not applicable with the reason, and expect that reason to be challenged at review. Genuine non-applicability is rarer than it first appears — many outcomes that look irrelevant turn out to apply once employee data or third-party processing is brought into scope.
Workbooks for both Profiles
Our NIST Privacy Framework Toolkit is 145 editable Word and Excel templates covering all 102 Subcategories of Privacy Framework 1.1. It ships Current and Target Profile workbooks pre-loaded with every outcome and its full text, a gap analysis that links each gap to the risk it leaves open, and an evidence register that points each outcome at the artefact proving it.