Score the six NIST CSF 2.0 functions on the 1–4 implementation tier scale, find the weakest function and the gap to your target tier.
CSF 2.0 has six functions — Govern was added to the original five — and each is placed on the four implementation tiers that describe how rigorous and repeatable the practice is, not how many tools you own. The functions are averaged unweighted because the framework does not rank them, and the weakest one is called out separately since an organisation performs at its thinnest function during an incident. A single tier number is what a board and a cyber insurer both ask for, and the function breakdown tells you whether your next pound belongs in detection engineering or in governance. It is a self-assessed management estimate, not a NIST assessment or certification.
NIST CSF Maturity
Average tier = mean of the six CSF 2.0 function tiers; maturity vs target = average tier ÷ target tier, and the gap is target − average.
Average tier = mean of the six CSF 2.0 function tiers; maturity vs target = average tier ÷ target tier, and the gap is target − average. CSF 2.0 has six functions — Govern was added to the original five — and each is placed on the four implementation tiers that describe how rigorous and repeatable the practice is, not how many tools you own. The functions are averaged unweighted because the framework does not rank them, and the weakest one is called out separately since an organisation performs at its thinnest function during an incident.
A single tier number is what a board and a cyber insurer both ask for, and the function breakdown tells you whether your next pound belongs in detection engineering or in governance. It is a self-assessed management estimate, not a NIST assessment or certification.
This calculator takes 7 inputs: Govern (GV), Identify (ID), Protect (PR), Detect (DE), Respond (RS), Recover (RC), Target tier. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Not officially. NIST describes them as implementation tiers that characterise the rigour of your risk-management practices, and explicitly warns against treating them as a maturity ladder to be climbed for its own sake. Most organisations still use them as one, which is fine as long as the target tier is justified by risk rather than by ambition.
No. A regulated payments business will rationally run Detect and Respond higher than Recover, and a manufacturer will do the reverse. What matters is that the profile is deliberate and written down, which is exactly what the Govern function asks for.