What this guide covers
- What the NIST CSF Tiers actually measure
- The two axes that most Tier assessments collapse into one
- The four NIST CSF Tiers, in NIST’s own terms
- Why Tier 4 is not the goal of the NIST CSF Tiers
- How to assess your NIST CSF Tiers without kidding yourself
- How the NIST CSF Tiers relate to Profiles and the Core
- What a good Tier record looks like
- Common questions about NIST CSF Tiers
- Assessing your Tiers with the right tooling

What the NIST CSF Tiers actually measure
The NIST CSF Tiers are the part of the Cybersecurity Framework that organisations most often get wrong, and the mistake is usually the same one: treating them as maturity levels to climb. They are not. NIST describes them as a notional illustration of how rigorously an organisation governs and manages cybersecurity risk, and there is no scheme, auditor or certificate attached to any of them.
There are four: Tier 1 Partial, Tier 2 Risk Informed, Tier 3 Repeatable and Tier 4 Adaptive. That much is widely known. What is far less widely understood — and what changes how you assess yourself — is that CSF 2.0 characterises each Tier across two separate dimensions, not one.
The two axes that most Tier assessments collapse into one
Appendix B of NIST CSWP 29 sets out the Tiers in a table with two columns:
- Cybersecurity risk governance — the GOVERN Function.
- Cybersecurity risk management — IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER.
An organisation can sit at Tier 3 on management and Tier 1 on governance. That is not a contradiction; it is one of the most common shapes a real security programme takes. A capable operations team patches on schedule, monitors properly and rehearses incident response, while nobody at board level has ever set a risk appetite, agreed risk management objectives with stakeholders, or written a policy that says who may accept a residual risk.
Score that organisation as a single Tier and you get “Tier 2, roughly” — a number that describes neither half accurately and tells the board nothing it can act on. Score it on both axes and the answer is immediately useful: the operational practice is strong, the governance around it does not exist, and the work to do is in GOVERN.
The four NIST CSF Tiers, in NIST’s own terms
| Tier | Risk governance | Risk management |
|---|---|---|
| 1 Partial | The risk strategy is applied ad hoc. Prioritisation is not formally based on objectives or the threat environment. | Limited organisational awareness of cybersecurity risk. Risk is managed irregularly and case by case. Supplier risk is largely unknown. |
| 2 Risk Informed | Practices are approved by management but may not be organisation-wide policy. Prioritisation is informed by risk objectives, threats or business requirements. | Awareness exists but there is no organisation-wide approach. Risk assessment happens but is not repeatable. Information is shared informally. Supplier risk is known but not acted on consistently. |
| 3 Repeatable | Practices are formally approved and expressed as policy. Risk-informed policies and procedures are defined, implemented as intended, and reviewed, and updated as requirements and technology change. | An organisation-wide approach exists. Information is routinely shared. Consistent methods respond to changes in risk. Personnel have the knowledge for their roles. Supplier risk is acted on formally through agreements and governance structures. |
| 4 Adaptive | Practices adapt on the basis of previous and current activities and predictive indicators. Continuous improvement is embedded in the culture. | The organisation-wide approach adapts to a changing threat and technology landscape. Supplier risk is managed at enterprise level using real-time information. |
Read those descriptions closely and a pattern appears. The jump from Tier 2 to Tier 3 on the governance axis is not incremental — it is the difference between management approved this and this is organisation-wide policy that is implemented as intended and reviewed. That usually means new forums, new reporting lines and new resource, not a better spreadsheet.
Why Tier 4 is not the goal of the NIST CSF Tiers
Nothing in the Framework says every organisation should reach Tier 4. The NIST CSF Tiers are not a ladder with a prize at the top. NIST’s own framing is that Tiers provide context for how an organisation views cybersecurity risk and the processes in place to manage it, and that the choice should reflect risk appetite, resources and the threat environment.
For a 40-person business with no regulated data and a modest threat profile, an honest Tier 2 on both axes with a documented decision to stay there is a better governance outcome than an aspirational Tier 4 nobody funds. For a critical national infrastructure operator, Tier 2 would be indefensible. The Tier is a statement of what is proportionate, and proportionate is not the same as maximal.
There is a practical trap in the other direction as well. Because there is no certification, some vendors sell “Tier 3 certification” or “Tier 4 accreditation”. No such thing exists, no body issues it, and a customer who has been told otherwise will eventually find out. If you are asked to evidence your Tier, evidence it — with the assessment behind it, not a claim.
How to assess your NIST CSF Tiers without kidding yourself
The Tier assessment is not a separate exercise from the rest of the Framework. It informs your Current and Target Profiles, and it is informed by them. A sensible sequence:
- Assess the Core first. Work through the 106 Subcategories and record what you actually do, with evidence. Rating intent rather than practice is the failure that makes everything downstream wrong.
- Read Appendix B against the evidence, axis by axis. For each Tier description, ask whether it describes you — not whether you would like it to.
- Record the current Tier on both axes. Two numbers, not one.
- Choose a target Tier on each axis, with a reason. “No change, because our risk profile does not warrant the investment” is a legitimate and defensible answer if it is written down.
- Reconsider at every management review. Reconsider, not carry forward. A Tier that has been copied across three annual reviews is not an assessment.
One useful test when you are stuck between two Tiers on the governance axis: can you produce the policy, and can you produce evidence that it was reviewed? If the policy exists but has never been reviewed, you are at Tier 2 however good the policy is. Tier 3 requires defined, implemented as intended, and reviewed, and the last word is the one that fails most often.
How the NIST CSF Tiers relate to Profiles and the Core
The NIST CSF Tiers sit alongside the other two components of CSF 2.0. The Core is the taxonomy of outcomes — 6 Functions, 22 Categories, 106 Subcategories. An Organizational Profile describes what you achieve now (Current) and what you intend to achieve (Target). The Tiers characterise the rigour behind all of it.
They are not interchangeable, and a Tier does not substitute for a Profile. The Profile carries the detail an assessor or a customer actually wants to see; the Tier is the one-line context that goes with it. If you are new to the Framework as a whole, the NIST Cybersecurity Framework overview covers how the three components fit together before you start on Tiers.
It is also worth knowing that the NIST CSF Tiers changed emphasis in CSF 2.0. In CSF 1.1 the Tier descriptions ran across risk management process, integrated risk management programme and external participation. In 2.0 the split is governance versus management, which reflects the arrival of GOVERN as a Function in its own right — and if you are carrying an old Tier rating across, it does not map cleanly.
What a good Tier record looks like
An assessment of your NIST CSF Tiers that will survive scrutiny records six things:
| Field | Why it matters |
|---|---|
| Current Tier — governance axis | The GOVERN Function alone |
| Current Tier — management axis | The other five Functions |
| Evidence for each | Without it the rating is an opinion |
| Target Tier on each axis | Including a deliberate “no change” |
| Rationale for the target | Ties the Tier to risk appetite and resources |
| Approver and date | Makes it a governance decision, not a self-description |
Notice what is not in that list: a score, a percentage, and a comparison against a peer group. The Tiers are not built to support any of the three, and forcing them to produces numbers that look precise and mean nothing.
Common questions about NIST CSF Tiers
Are the NIST CSF Tiers the same as a maturity model?
No. Maturity models describe process capability on a single ordinal scale and usually imply that higher is better. If you need a per-outcome score rather than a programme-level one, our guide to NIST CSF maturity levels sets out a five-point scale that works alongside the Tiers. The Tiers describe the rigour of risk governance and risk management across two dimensions, and NIST presents them as a notional illustration chosen against risk appetite. Treating them as a maturity model leads organisations to chase Tier 4 rather than choose the Tier their risk actually warrants.
Can we be certified at a particular Tier?
No. There is no certification against the NIST Cybersecurity Framework, no accreditation body and no auditor who can issue a Tier certificate. You can hold an independent assessment, and you can evidence your self-assessed Tier, but any offer of Tier certification is not what it claims to be.
Do we have to use the Tiers at all?
No. NIST says an organisation can choose to use the Tiers to inform its Current and Target Profiles. Plenty of organisations run the Framework on Profiles alone. The NIST CSF Tiers earn their place when you need a short way to tell a board or a customer how rigorous the programme is, without walking them through 106 outcomes.
How often should we reassess our Tier?
At every management review, and after any event that changes the picture — a significant incident, an acquisition, a new regulatory obligation, or a material change in the threat environment. The important discipline is reconsidering rather than rolling the previous rating forward.
What is the fastest way to move up a Tier on the governance axis?
Usually by turning approved practice into reviewed policy. An organisation sitting at Tier 2 on governance is usually already doing many of the right things; what is missing is that they are not expressed as organisation-wide policy, and there is no evidence anyone reviewed them. That gap is documentation and cadence rather than new technology, which makes it one of the cheaper Tier movements available.
Assessing your Tiers with the right tooling
Assessing the NIST CSF Tiers honestly means reading Appendix B of CSWP 29 against real evidence on both axes, then recording the result somewhere a board and an auditor can both follow. The Framework itself is free, and you should read it: NIST publishes it in full at nist.gov/cyberframework.
If you want the assessment already built, our NIST CSF Toolkit ships a two-axis Implementation Tier Self-Assessment with NIST’s own characterisation of each Tier on each axis, alongside a scored assessment tool pre-loaded with all 106 Subcategories, Current and Target Profile workbooks, and a gap analysis that turns the result into a dated plan. It is 164 editable Word and Excel documents, and every one of them names the Framework outcomes it answers.