NIST CSF Maturity Calculator
Score the six NIST CSF 2.0 functions on the 1–4 implementation tier scale, find the weakest function and the gap to your target tier.
Inputs
Average CSF Tier
2.50of 4
Maturity vs Target
83.3%
Gap to Target Tier
0.50tiers
Indicative Time to Target
2quarters
Current Tier
Tier 2 — Risk Informed: practices are approved but not organisation-wide
Weakest Function
Govern (GV)
Strongest Function
Identify (ID)
Governance Check
Govern is the weak link — CSF 2.0 added it precisely because the other five functions decay without it
Step by step
Values used
Govern (GV) = Tier 2 — Risk Informed; Identify (ID) = Tier 3 — Repeatable; Protect (PR) = Tier 3 — Repeatable; Detect (DE) = Tier 2 — Risk Informed; Respond (RS) = Tier 3 — Repeatable; Recover (RC) = Tier 2 — Risk Informed; Target tier = Tier 3 — Repeatable
NIST CSF Maturity
Average tier = mean of the six CSF 2.0 function tiers; maturity vs target = average tier ÷ target tier, and the gap is target − average.
Average CSF Tier
= 2.50 of 4
Maturity vs Target
= 83.3
Gap to Target Tier
= 0.50 tiers
Indicative Time to Target
= 2 quarters
Current Tier
= Tier 2 — Risk Informed: practices are approved but not organisation-wide
Weakest Function
= Govern (GV)
How it works
CSF 2.0 has six functions — Govern was added to the original five — and each is placed on the four implementation tiers that describe how rigorous and repeatable the practice is, not how many tools you own. The functions are averaged unweighted because the framework does not rank them, and the weakest one is called out separately since an organisation performs at its thinnest function during an incident. A single tier number is what a board and a cyber insurer both ask for, and the function breakdown tells you whether your next pound belongs in detection engineering or in governance. It is a self-assessed management estimate, not a NIST assessment or certification.
Formula
NIST CSF Maturity
Average tier = mean of the six CSF 2.0 function tiers; maturity vs target = average tier ÷ target tier, and the gap is target − average.
- 1–4
- Partial, Risk Informed, Repeatable, Adaptive
- tierScore
- Unweighted mean of the six function tiers
- targetGap
- Tiers still to climb
Frequently Asked Questions
How is NIST CSF Maturity calculated?
Average tier = mean of the six CSF 2.0 function tiers; maturity vs target = average tier ÷ target tier, and the gap is target − average. CSF 2.0 has six functions — Govern was added to the original five — and each is placed on the four implementation tiers that describe how rigorous and repeatable the practice is, not how many tools you own. The functions are averaged unweighted because the framework does not rank them, and the weakest one is called out separately since an organisation performs at its thinnest function during an incident.
Why does NIST CSF Maturity matter?
A single tier number is what a board and a cyber insurer both ask for, and the function breakdown tells you whether your next pound belongs in detection engineering or in governance. It is a self-assessed management estimate, not a NIST assessment or certification.
What values do I need to enter?
This calculator takes 7 inputs: Govern (GV), Identify (ID), Protect (PR), Detect (DE), Respond (RS), Recover (RC), Target tier. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Are CSF tiers maturity levels?
Not officially. NIST describes them as implementation tiers that characterise the rigour of your risk-management practices, and explicitly warns against treating them as a maturity ladder to be climbed for its own sake. Most organisations still use them as one, which is fine as long as the target tier is justified by risk rather than by ambition.
Should every function reach the same tier?
No. A regulated payments business will rationally run Detect and Respond higher than Recover, and a manufacturer will do the reverse. What matters is that the profile is deliberate and written down, which is exactly what the Govern function asks for.
You might also need
- ISO 27001 Compliance CalculatorCommonly used together
- Governance Maturity CalculatorCommonly used together
- CIS Controls Coverage CalculatorCommonly used together
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC
- Security Investment ROI CalculatorAlso in Compliance & GRC
- Residual Risk CalculatorAlso in Compliance & GRC