Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST Privacy Framework Profile — NIST Privacy Framework Profiles: Current vs Target in 2026

NIST Privacy Framework Profiles: Current vs Target in 2026

A NIST Privacy Framework Profile is a selection of privacy outcomes: either the ones your organisation achieves today, or the ones it needs to achieve. The difference between the two is what turns a framework into a plan.

A NIST Privacy Framework Profile is one of the framework’s three components, alongside the Core and Implementation Tiers. A toolkit or programme that ships only the Core has delivered a list of outcomes with no mechanism for deciding which of them matter to you.

What this guide covers

NIST Privacy Framework Profile explained
A NIST Privacy Framework Profile: the gap between Current and Target is the work plan.

The two NIST Privacy Framework Profiles: Current and Target

Current Profile Target Profile
Question What are we achieving now? What do we need to achieve?
Basis Evidence Risk, obligations and strategy
Approved by The privacy function The accountable executive
Refreshed At least annually At least annually
Failure mode Recording intentions as achievements Assuming the target is everything

The gap between the two is the programme’s work plan. Nothing else in the framework produces one, which is why a NIST Privacy Framework Profile is not an optional extra on top of the Core.

Building an honest Current NIST Privacy Framework Profile

For each of the 102 Subcategories in version 1.1, record one of four statuses:

  • Achieved — happening repeatably, with evidence a third party would accept
  • Partially achieved — happening for some systems, populations or cases
  • Not achieved — not happening, or happening with no evidence
  • Not applicable — with a recorded reason, which should be rare

Three rules make a Current Profile useful rather than flattering:

A document is not achievement. A retention policy that is not enforced does not achieve the retention outcome. The evidence is the deletion job’s output and a sample of records confirmed gone — not the policy that says they should be.

Partial is partial. An outcome achieved for the flagship system and not for the other forty is partially achieved. Recording it as achieved destroys the Profile’s value as a plan, because the gap analysis will not see the forty.

Not achieved is the expected first answer. An initial NIST Privacy Framework Profile showing most outcomes achieved is worth re-checking before it is approved: the test is whether each claim names evidence that exists independently of the assessor’s opinion.

Evidence, and what counts as it

Every “Achieved” claim in a NIST Privacy Framework Profile should name the artefact that evidences it. Evidence is something that exists independently of the assessor’s opinion — a record, a log, a test result, a completed register, a signed approval.

Claim Weak evidence What to ask for instead
Data destroyed per policy The retention policy The destruction job’s output, plus records past their period confirmed gone
Personnel are trained Completion rates Comprehension results, and a sample of people asked a scenario question
Systems are inventoried The inventory itself The reconciliation record, and the count of systems found by reconciliation rather than registration
Preferences are honoured The procedure A preference set, a restore performed, the preference still in force afterwards
Suppliers are assessed The assessment schedule Completed assessments with evidence, and closure of any conditions

Testing a sample of Achieved claims is the highest-value audit anyone can run against a NIST Privacy Framework Profile. The recurring finding is not a failed control but a claim supported by a document rather than by evidence that the document operates.

A Target Profile is chosen, not assumed

Here is the distinction that decides whether the plan is achievable. The Target Profile is not automatically all 102 Subcategories.

It is the set of outcomes needed to meet your privacy risk management goals, derived from assessed risks, legal and contractual obligations, your strategy, your role in the data processing ecosystem, stakeholder expectations, and the resources you actually have.

Deciding that an outcome is not a target is a legitimate, documented risk decision. Record it with its rationale. An unexamined “all of them” is a worse Target Profile than a reasoned subset, and it is a plan you will fail to deliver — which then shows up as an audit finding against your own stated intent.

Where resources cannot deliver the target, the honest response is to reduce the target and say so, not to leave commitments in place that will be missed.

Turning the NIST Privacy Framework Profile gap into a plan

For each gap — an outcome that is a target and is not achieved — record:

  1. The Subcategory and the outcome not currently achieved
  2. The privacy risk that stays open while it is not achieved, cross-referenced to your risk register
  3. The action, its owner and its due date
  4. The evidence that will demonstrate closure, stated now rather than decided later

Point 2 is the one that gives the plan its order. Gaps are prioritised by the risk they leave open, not by how easy they are to close — and a gap with no linked risk entry is a gap nobody has justified closing. That usually means either the target was set too wide, or the risk assessment missed something. Both are worth knowing.

NIST Privacy Framework Profiles across a large organisation

Where NIST Privacy Framework Profiles exist at more than one level — organisation-wide and per business unit — the organisation-wide Current Profile records the weakest position across the units, not an average.

An outcome achieved in three units and absent in the fourth is partially achieved organisation-wide. Averaging it produces a Profile that describes nowhere, and it hides the unit that needs attention.

Common mistakes in a first NIST Privacy Framework Profile

Four patterns are worth naming in advance, because each is cheap to avoid and expensive to unpick afterwards.

Mistake What it looks like Consequence
Assessing before mapping The Profile is completed before the data map exists It records what people believe the organisation does. The systems nobody remembered are the ones with the least governance
Targeting before assessing The Target Profile is set before the risk register exists The target is a wish list rather than a response to assessed risk, and cannot be defended at review
Scoring the policy “Achieved” wherever a document exists The gap analysis finds nothing, because a Profile of unearned “Achieved” statuses has no gaps in it to find
Averaging across units An outcome achieved in three of four units recorded as achieved The unit that needs attention disappears from the plan

The first two are sequencing errors and the fix is simply to do the steps in order. The second two are honesty errors, and the fix is to have someone who did not perform the assessment test a sample of the claims before the Profile is approved.

When to refresh a NIST Privacy Framework Profile

At least annually, and on any of: a new or materially changed system; a new processing purpose; a change in the population affected; a change in your ecosystem role; a merger, acquisition or divestment; a significant problematic data action; or a change in your legal obligations.

One further trigger is specific to the current draft. If NIST publishes the final version of Privacy Framework 1.1 and renumbers the Subcategory identifiers — something the draft’s own Note to Reviewers explicitly asks reviewers about — remap before you reassess. Evidence pointed at a renumbered identifier is evidence attached to the wrong outcome. See what changed between 1.1 and 1.0 for the mapping this involves.

A NIST Privacy Framework Profile is not an Implementation Tier

Profile Implementation Tier
Answers Which outcomes do we achieve? How rigorously do we manage privacy risk?
Unit Subcategories The programme as a whole

An organisation can achieve many outcomes in its NIST Privacy Framework Profile at low rigour — through individual effort and institutional memory rather than through process. That is a strong Current Profile on a fragile programme, and only the Tier assessment reveals it.

See Implementation Tiers for how that assessment works, and why Tier 4 is not the target for every organisation.

For the framework overall see our NIST Privacy Framework guide, and for the analysis that should precede any scoring, problematic data actions. The framework and its Core are free at nist.gov/privacy-framework.

Frequently asked questions

How long does a first Current Profile take?

Less time than the work that must precede it. The inventory and data map dominate the schedule, because you cannot assess outcomes for processing you have not yet described. Once the map exists, assessing 102 outcomes is a matter of weeks rather than months.

Can we use a Target Profile from elsewhere?

A published community or sector Profile is a useful starting point and a poor finishing point. Your target should follow from your own assessed risks, obligations and ecosystem role. Adopting someone else’s wholesale reproduces their judgement about their circumstances.

Who signs off a NIST Privacy Framework Profile?

The privacy function owns the Current Profile because it is a statement of fact about evidence. The Target Profile should be approved by whoever is accountable for privacy risk and controls the resources, because choosing it commits money and people.

What if an outcome genuinely does not apply?

Record it as not applicable with the reason, and expect that reason to be challenged at review. Genuine non-applicability is rarer than it first appears — many outcomes that look irrelevant turn out to apply once employee data or third-party processing is brought into scope.

Workbooks for both Profiles

Our NIST Privacy Framework Toolkit is 145 editable Word and Excel templates covering all 102 Subcategories of Privacy Framework 1.1. It ships Current and Target Profile workbooks pre-loaded with every outcome and its full text, a gap analysis that links each gap to the risk it leaves open, and an evidence register that points each outcome at the artefact proving it.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.