Skip to content
Calcrivo

NIST CSF Maturity Calculator

Score the six NIST CSF 2.0 functions on the 1–4 implementation tier scale, find the weakest function and the gap to your target tier.

Inputs

Average CSF Tier

2.50of 4

Maturity vs Target

83.3%

Gap to Target Tier

0.50tiers

Indicative Time to Target

2quarters

Current Tier

Tier 2 — Risk Informed: practices are approved but not organisation-wide

Weakest Function

Govern (GV)

Strongest Function

Identify (ID)

Governance Check

Govern is the weak link — CSF 2.0 added it precisely because the other five functions decay without it

Step by step

  1. Values used

    Govern (GV) = Tier 2 — Risk Informed; Identify (ID) = Tier 3 — Repeatable; Protect (PR) = Tier 3 — Repeatable; Detect (DE) = Tier 2 — Risk Informed; Respond (RS) = Tier 3 — Repeatable; Recover (RC) = Tier 2 — Risk Informed; Target tier = Tier 3 — Repeatable

  2. NIST CSF Maturity

    Average tier = mean of the six CSF 2.0 function tiers; maturity vs target = average tier ÷ target tier, and the gap is target − average.

  3. Average CSF Tier

    = 2.50 of 4

  4. Maturity vs Target

    = 83.3

  5. Gap to Target Tier

    = 0.50 tiers

  6. Indicative Time to Target

    = 2 quarters

  7. Current Tier

    = Tier 2 — Risk Informed: practices are approved but not organisation-wide

  8. Weakest Function

    = Govern (GV)

How it works

CSF 2.0 has six functions — Govern was added to the original five — and each is placed on the four implementation tiers that describe how rigorous and repeatable the practice is, not how many tools you own. The functions are averaged unweighted because the framework does not rank them, and the weakest one is called out separately since an organisation performs at its thinnest function during an incident. A single tier number is what a board and a cyber insurer both ask for, and the function breakdown tells you whether your next pound belongs in detection engineering or in governance. It is a self-assessed management estimate, not a NIST assessment or certification.

Formula

NIST CSF Maturity

Average tier = mean of the six CSF 2.0 function tiers; maturity vs target = average tier ÷ target tier, and the gap is target − average.

1–4
Partial, Risk Informed, Repeatable, Adaptive
tierScore
Unweighted mean of the six function tiers
targetGap
Tiers still to climb

Frequently Asked Questions

How is NIST CSF Maturity calculated?

Average tier = mean of the six CSF 2.0 function tiers; maturity vs target = average tier ÷ target tier, and the gap is target − average. CSF 2.0 has six functions — Govern was added to the original five — and each is placed on the four implementation tiers that describe how rigorous and repeatable the practice is, not how many tools you own. The functions are averaged unweighted because the framework does not rank them, and the weakest one is called out separately since an organisation performs at its thinnest function during an incident.

Why does NIST CSF Maturity matter?

A single tier number is what a board and a cyber insurer both ask for, and the function breakdown tells you whether your next pound belongs in detection engineering or in governance. It is a self-assessed management estimate, not a NIST assessment or certification.

What values do I need to enter?

This calculator takes 7 inputs: Govern (GV), Identify (ID), Protect (PR), Detect (DE), Respond (RS), Recover (RC), Target tier. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Are CSF tiers maturity levels?

Not officially. NIST describes them as implementation tiers that characterise the rigour of your risk-management practices, and explicitly warns against treating them as a maturity ladder to be climbed for its own sake. Most organisations still use them as one, which is fine as long as the target tier is justified by risk rather than by ambition.

Should every function reach the same tier?

No. A regulated payments business will rationally run Detect and Respond higher than Recover, and a manufacturer will do the reverse. What matters is that the profile is deliberate and written down, which is exactly what the Govern function asks for.

You might also need