Guide

CSF 2.0 implementation tiers: how to use them without overthinking

CSF 2.0's four implementation tiers — Partial (1), Risk Informed (2), Repeatable (3), Adaptive (4) — describe how rigorous your cybersecurity risk management is. They're a planning tool, not a report card.

What the tiers actually measure

Tiers characterize your risk management practices: whether risk decisions are ad hoc or informed, whether processes repeat reliably, whether you adapt based on lessons learned and threat intelligence. A Tier 1 organization can still have strong controls in spots — it just manages risk informally.

Picking a target tier

Using tiers in practice

Set a current profile (where you are) and a target profile (where you need to be) per Function — you can be Tier 3 on Protect and Tier 2 on Recover, and that's fine. The gap between profiles is your roadmap, and it's what you budget against in our cost guide.

Independent directory. CSFCompliance.com is an independent directory and quote-matching service.

Get quotes from verified firms

One brief, matched firms, competing quotes — free.

Get a free quote

← All guides