Cybersecurity

How does NIST CSF maturity work?

Understand how the NIST Cybersecurity Framework assesses maturity and helps organizations improve security capabilities.

By Inventive HQ Team

NIST CSF "maturity" works through two distinct measures that people constantly conflate: the framework's four official Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive), which describe how rigorously your organization manages cyber risk, and an unofficial per-function maturity score (typically Level 1 ad-hoc through Level 4 optimized) that consultants overlay to show how completely each practice is implemented. NIST itself never defined maturity levels — it defined Tiers and Profiles. You assess maturity by building a Current Profile of what you do today, a Target Profile of where risk says you should be, and measuring the gap between them; that gap becomes a multi-year improvement roadmap.

That is the summary an AI Overview will give you. What it flattens is the part that actually matters when you sit down to run an assessment: how the six CSF 2.0 functions relate, where Tiers stop and maturity scoring begins, and how a real score turns into a roadmap. The diagrams and tables below map exactly that.

Updated for CSF 2.0: NIST released Cybersecurity Framework 2.0 on February 26, 2024, adding a sixth function — Govern — at the center of the model. The five functions in this article's core section (Identify, Protect, Detect, Respond, Recover) are the outer ring; Govern now wraps all of them with strategy, roles, policy, and supply-chain risk. If you are standing up a new program today, start from CSF 2.0's six functions.

NIST Cybersecurity Framework Overview

The NIST Cybersecurity Framework (CSF) is a flexible, voluntary guide for organizations to manage and reduce cybersecurity risk. Unlike prescriptive compliance standards, the NIST CSF is flexible and adaptable to different organization types, sizes, and risk profiles.

The framework organizes cybersecurity outcomes around its core functions and is widely used for maturity assessment — even though, as noted above, formal maturity levels were never part of the framework. What NIST defines are Implementation Tiers and Profiles; the numbered "maturity levels" you will see almost everywhere are a practical overlay the community adopted from CMMI-style maturity models.

NIST CSF 2.0 six functions with Govern at the center Govern sits in the middle surrounded by an orbiting ring of five functions: Identify, Protect, Detect, Respond, and Recover. NIST CSF 2.0 — six functions Govern (new in 2.0) wraps the original five Identify assets, risk Protect safeguards Detect monitoring Respond contain Recover restore GOVERN strategy • policy roles • supply chain

Five Core Functions

The NIST CSF organizes cybersecurity activities around five core functions:

1. Identify

Purpose: Understand assets, systems, data, and risks to manage cybersecurity exposure

Key activities:

  • Asset management: Know what systems and data you have
  • Business environment: Understand mission and strategy
  • Governance: Establish security policies and roles
  • Risk assessment: Identify vulnerabilities and threats
  • Risk management strategy: Define risk approach

Example practices:

  • Maintain inventory of systems and software
  • Map critical business processes to IT systems
  • Document security policies and procedures
  • Conduct regular risk assessments
  • Define risk tolerance and acceptance criteria

2. Protect

Purpose: Implement safeguards to ensure critical systems and data are protected

Key activities:

  • Access control: Control who can access systems and data
  • Asset management: Manage security of systems and devices
  • Business continuity: Maintain operations during disruptions
  • Governance: Implement security policies
  • Data security: Protect sensitive data
  • Information protection: Secure information systems
  • Maintenance: Keep systems in secure state
  • Protective technology: Deploy security tools

Example practices:

  • Implement multi-factor authentication (MFA)
  • Encrypt sensitive data
  • Maintain regular backups
  • Implement access controls and least privilege
  • Deploy intrusion detection systems
  • Maintain secure configurations

3. Detect

Purpose: Identify security incidents and anomalies in timely manner

Key activities:

  • Anomalies and events: Monitor for unusual activity
  • Continuous monitoring: Detect threats in real-time
  • Detection processes: Investigate detected events

Example practices:

  • Deploy SIEM for log aggregation and analysis
  • Implement intrusion detection systems (IDS)
  • Monitor network traffic for anomalies
  • Review access logs for unauthorized activity
  • Investigate suspicious user behavior
  • Conduct regular threat hunting

4. Respond

Purpose: Respond to detected security incidents to contain and mitigate impact

Key activities:

  • Response planning: Develop incident response procedures
  • Communications: Notify affected parties
  • Analysis: Investigate incident cause
  • Mitigation: Take action to contain incident
  • Improvements: Learn from incidents

Example practices:

  • Develop and test incident response plan
  • Define incident escalation procedures
  • Conduct incident response drills and tabletop exercises
  • Analyze incidents to understand root cause
  • Implement corrective actions
  • Communicate with stakeholders and regulators

5. Recover

Purpose: Restore normal operations after security incident

Key activities:

  • Recovery planning: Prepare for restoration
  • Recovery communication: Notify stakeholders
  • Recovery procedures: Execute restoration
  • Improvement: Reduce risk of similar incidents

Example practices:

  • Maintain disaster recovery and business continuity plans
  • Test recovery procedures regularly
  • Maintain verified backups
  • Document recovery procedures
  • Train staff on recovery processes
  • Conduct post-incident reviews

The Official Layer: NIST CSF Implementation Tiers

Before the informal "maturity levels," understand what NIST actually publishes. The framework defines four Implementation Tiers that describe how deeply cyber-risk management is woven into the organization. Tiers are not a maturity ladder to climb for its own sake — CSF 2.0 is explicit that not every organization needs Tier 4. A small business at Tier 2 that has consciously accepted its risk may be exactly where it should be.

TierNameRisk managementIntegrationSupply chain
1PartialAd-hoc, reactive; risk handled case by caseLimited awareness; no org-wide approachLittle visibility into third-party risk
2Risk InformedRisk practices approved but not org-wide policyAwareness exists; not consistently acted onSome awareness of supplier risk
3RepeatableFormal policy; risk practices updated regularlyOrg-wide approach; consistent response to changeFormal, tracked third-party risk process
4AdaptiveContinuous improvement from lessons learned + predictive indicatorsRisk-informed culture; decisions embedded org-wideReal-time supply-chain risk management

Which tier should you target? Match the tier to your risk, not to a maximum score. Regulated or high-consequence environments (healthcare, critical infrastructure, finance) usually aim for Tier 3+. A resource-constrained SMB often lands at a deliberate Tier 2. The point of the Current-vs-Target Profile exercise is to decide the right tier per your risk tolerance, then close the gap.

Advertisement

NIST CSF Maturity Levels (Informal)

While NIST doesn't formally define maturity levels, the framework is commonly assessed using an informal maturity progression borrowed from CMMI-style models. This scores how completely each practice is implemented, function by function — a finer-grained view than the whole-program Tiers above.

NIST CSF informal maturity ladder from ad-hoc to optimized Four ascending steps labelled Ad-hoc, Partial, Consistent, and Optimized, with a marker climbing the steps. Informal maturity progression (per function) 1 · Ad-hoc reactive, undocumented 2 · Partial some practices, inconsistent 3 · Consistent documented, org-wide 4 · Optimized measured, continuously improved

Level 1: Ad-hoc

  • Practices not yet implemented
  • No documented processes
  • Reactive approach (respond after incidents)
  • Minimal awareness of cybersecurity

Level 2: Partial

  • Some practices implemented
  • Basic documented processes
  • Awareness emerging in some areas
  • Inconsistent application across organization

Level 3: Consistent

  • Most practices implemented across core functions
  • Documented policies and procedures
  • Regular monitoring and assessment
  • Consistent application organization-wide
  • Proactive approach developing

Level 4: Optimized

  • All core functions implemented
  • Metrics track effectiveness
  • Continuous improvement processes
  • Automation of many security tasks
  • Risk-informed decision making

Assessing NIST CSF Maturity

Organizations assess maturity by evaluating each core function:

For each function, assess:

  • Are practices documented?
  • Are practices consistently followed?
  • Are resources allocated to practice?
  • Are processes measured and monitored?
  • Are processes continuously improved?

Assessment approach:

  1. Review documentation (policies, procedures, records)
  2. Interview staff to verify understanding and application
  3. Observe implementation (systems, configurations, processes)
  4. Test controls through sampling and validation
  5. Score each practice on 1-4 scale
  6. Calculate overall maturity for each function

Result: Organization understands maturity across all five functions, enabling targeted improvement.

Want a quick starting-point score before you commission a formal assessment? Run our free Cybersecurity Maturity Assessment to benchmark your current state across the core functions in a few minutes.

NIST CSF Profiles

The framework includes "profiles" that allow customization:

Target profile: Desired future state for the organization

  • Define which functions are most important
  • Set target practices for each function
  • Align with business strategy and risk tolerance

Current profile: Current state assessment

  • Assess current practices
  • Identify gaps between current and target
  • Prioritize improvements

Profile-to-profile comparison:

  • Identify gaps
  • Determine effort needed
  • Create roadmap for improvement

Example:

  • Financial services target profile: Heavy focus on Identify, Protect, Detect (most critical for financial risk)
  • Manufacturing target profile: Heavy focus on Protect, Respond, Recover (protecting critical processes)
  • Small business target profile: Focus on Protect and Detect (cost-effective approach for limited resources)

Using NIST CSF for Maturity Improvement

Organizations use NIST CSF to guide improvement:

Phase 1 (Establish baseline):

  • Assess current maturity across all functions
  • Identify gaps vs. target maturity
  • Understand current risk exposure

Phase 2 (Prioritize improvements):

  • Identify which functions to improve first
  • Prioritize practices within each function
  • Allocate resources
  • Create implementation roadmap

Phase 3 (Implement improvements):

  • Execute improvements according to roadmap
  • Ensure processes are documented
  • Train staff on new practices
  • Monitor implementation progress

Phase 4 (Measure and optimize):

  • Measure effectiveness of implemented practices
  • Gather metrics on practice execution
  • Identify optimization opportunities
  • Make data-driven improvements

NIST CSF vs. CMMC vs. ISO 27001

These three get compared constantly, but they answer different questions. NIST CSF tells you what outcomes to pursue; CMMC and ISO 27001 tell you whether you can prove it to a third party.

NIST CSF 2.0CMMC 2.0ISO 27001
NatureVoluntary frameworkMandatory (DoD contractors)Voluntary standard
Maturity modelImplementation Tiers 1–4 (no formal maturity levels)Formal levels 1–3No maturity levels; certify or not
CertificationNone — self-assessedThird-party assessment (C3PAO) at Level 2+Third-party audit + certificate
BasisOutcome-based Functions/CategoriesNIST SP 800-171 controlsAnnex A controls + ISMS
ScopeAll sectors, any sizeDefense supply chain (CUI)Any org handling info assets
Which to use / whenBuilding or maturing a program from scratch; need a flexible risk-based roadmapYou handle Controlled Unclassified Information for the DoDYou need an internationally recognized certificate for customers or contracts

Many organizations use NIST CSF as the foundation, then map its outcomes to CMMC, ISO 27001, or SP 800-53 where a certifiable or contractual standard is required. See our NIST frameworks comparison guide and ISO 27001 certification guide for the mapping details.

Maturity and Business Value

NIST CSF explicitly connects maturity to business value:

As organizations mature:

  • Risk exposure decreases
  • Incident detection time improves (Detect function)
  • Incident impact reduces (Respond/Recover functions)
  • Business continuity improves
  • Customer trust increases
  • Regulatory compliance easier
  • Cost of security becomes more efficient

Measuring business impact:

  • Mean time to detect (MTTD): Lower with mature Detect function
  • Mean time to respond (MTTR): Lower with mature Respond function
  • Breach cost reduction: Mature organizations have lower breach costs
  • Compliance violations: Decrease with mature Identify/Protect functions
  • Customer satisfaction: Increases with demonstrated mature security

Real-World NIST CSF Implementation

Common implementation examples:

Healthcare organization:

  • Focus primarily on Protect and Identify (HIPAA requirements)
  • Detect through continuous monitoring for breach indicators
  • Respond with formal incident response
  • Recover through backup and disaster recovery
  • Maturity improvement roadmap: 2-3 years to reach consistent maturity

Critical infrastructure utility:

  • Heavy focus on Identify and Protect (operational technology)
  • Detect through industrial control system monitoring
  • Respond with rapid incident containment
  • Recover with operational technology restoration
  • Maturity improvement roadmap: 3-5 years to reach optimized maturity

Small business:

  • Simplified Identify and Protect (basic asset management and access control)
  • Basic Detect through log monitoring
  • Simple Respond process
  • Basic disaster recovery
  • Maturity improvement roadmap: 1-2 years to reach consistent maturity

Conclusion

NIST CSF provides framework for assessing and improving cybersecurity maturity across five core functions: Identify, Protect, Detect, Respond, and Recover. While NIST doesn't formally define maturity levels, organizations can assess maturity informally from ad-hoc (Level 1) through optimized (Level 4). Framework allows customization through profiles tailored to organization type, size, and risk profile. NIST CSF is foundational for many organizations; others map it to more specific frameworks (CMMC, ISO 27001) based on their specific requirements. Maturity improvement through NIST CSF typically takes 2-5 years and correlates with reduced breach risk, improved incident response, and lower security costs.

Frequently Asked Questions

Does NIST CSF have official maturity levels?

No. NIST CSF does not define maturity levels. What it does define are four Implementation Tiers — Tier 1 Partial, Tier 2 Risk Informed, Tier 3 Repeatable, and Tier 4 Adaptive — which describe how rigorously an organization manages cyber risk, not how many controls it has deployed. The "Level 1 to Level 4 maturity" scoring most consultants use is a widely adopted overlay borrowed from CMMI-style models; it is useful but not part of the official framework.

What are the functions of NIST CSF 2.0?

NIST CSF 2.0, published February 26, 2024, has six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern is new in 2.0 and sits at the center, wrapping the other five — it covers strategy, roles and responsibilities, policy, and supply-chain risk. The original 2014/2018 framework (version 1.1) had only the five outer functions.

What is the difference between Implementation Tiers and maturity levels?

Implementation Tiers (1–4) are the official NIST measure of how well cyber-risk decisions are integrated into the organization — how repeatable, risk-informed, and adaptive the program is. Maturity levels are an unofficial per-control or per-function score (typically 1–4 or 1–5) showing how completely each practice is implemented. Tiers describe the whole program's rigor; maturity scores describe individual capabilities. Many assessments report both.

How long does it take to improve NIST CSF maturity?

For most organizations, moving from an ad-hoc baseline to consistent (roughly Tier 3) maturity takes 2–3 years; reaching optimized/adaptive maturity generally takes 3–5 years. Small businesses with narrow scope can reach consistent maturity in 1–2 years. The timeline depends on budget, staffing, executive sponsorship, and how many gaps the current-vs-target profile comparison surfaces.

What is a NIST CSF profile?

A profile is the framework tailored to a specific organization. A Current Profile documents the outcomes you already achieve; a Target Profile documents the outcomes you want, prioritized by business risk. The gap between the two becomes your improvement roadmap. CSF 2.0 also introduced Community Profiles — shared baselines for a sector or use case (for example, ransomware or manufacturing).

Is NIST CSF the same as CMMC?

No. NIST CSF is voluntary, flexible, and has no third-party certification. CMMC (Cybersecurity Maturity Model Certification) is mandatory for U.S. defense contractors, defines specific practices at each level, and requires third-party assessment. CMMC 2.0 builds on NIST SP 800-171 controls, not on CSF directly. Many organizations use CSF as a foundation and map it to CMMC, ISO 27001, or SP 800-53 as needed.

Do I need to be certified to use NIST CSF?

No. There is no NIST CSF certification and no auditor issues a CSF certificate. Organizations self-assess, or hire a consultant to assess maturity, but the output is an internal profile and roadmap, not a formal certificate. If you need attestable certification, you map CSF to a certifiable standard such as ISO 27001 or CMMC.

How do you score NIST CSF maturity?

Assessors evaluate each function's Categories and Subcategories against evidence — documentation, staff interviews, system configuration, and control testing — then assign a score (commonly 1–4) per practice. Function-level and overall scores are averaged or weighted by risk. The goal is not a high number for its own sake; it is closing the gap between your Current and Target Profiles where business risk is greatest.

nist-csfmaturity-assessmentcybersecurity-framework