CSF 2.0 implementation tiers: how to use them without overthinking
CSF 2.0's four implementation tiers — Partial (1), Risk Informed (2), Repeatable (3), Adaptive (4) — describe how rigorous your cybersecurity risk management is. They're a planning tool, not a report card.
What the tiers actually measure
Tiers characterize your risk management practices: whether risk decisions are ad hoc or informed, whether processes repeat reliably, whether you adapt based on lessons learned and threat intelligence. A Tier 1 organization can still have strong controls in spots — it just manages risk informally.
Picking a target tier
- Most mid-market companies reasonably target Tier 2–3: risk-informed decisions, repeatable processes.
- Regulated / critical-infrastructure organizations typically need Tier 3, pushing toward 4 in their highest-risk areas.
- Don't target Tier 4 everywhere — adaptive, intelligence-driven management is expensive and only pays off where the risk justifies it.
Using tiers in practice
Set a current profile (where you are) and a target profile (where you need to be) per Function — you can be Tier 3 on Protect and Tier 2 on Recover, and that's fine. The gap between profiles is your roadmap, and it's what you budget against in our cost guide.
Get quotes from verified firms
One brief, matched firms, competing quotes — free.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.