Compyl
GRC Your Way

NIST CSF Tiers Explained: What Levels 1, 2, 3 and 4 Require

By Compyl Research · Last reviewed September 2026

The four NIST Cybersecurity Framework Tiers — Partial, Risk Informed, Repeatable and Adaptive — describe how rigorous an organization’s cybersecurity risk governance and risk management practices are. Tier 3, “Repeatable”, is the level at which risk management stops being a set of individual good decisions and becomes formally approved policy applied consistently across the whole organization. It is where most mid-sized companies should be aiming, and it is a bigger jump than the one above it.

Key takeaways

  • Tiers are not maturity levels. NIST is explicit: they characterize the rigor of cybersecurity risk governance and management practices, and are meant to complement a risk management methodology, not replace it. Nobody is “NIST Level 3 certified” — there is no certification.
  • Tier 4 is not the goal for everyone. NIST recommends moving up a tier only when doing so reduces risk in a cost-effective way. A Tier 4 program in a company whose risk profile justifies Tier 2 is money spent badly.
  • The decisive step is 2 to 3. Tier 2 means someone senior approves good practices; Tier 3 means those practices are written policy, applied the same way in every department, and updated as requirements and threats change.
  • CSF 2.0 made governance half the score. Since the 2024 revision the Tiers are assessed across two dimensions — cybersecurity risk governance and cybersecurity risk management — and the new Govern function sits alongside Identify, Protect, Detect, Respond and Recover.
  • NIST CSF Tiers are not CMMC levels. They share the word “level” in common usage and nothing else: different framework, different purpose, different assessment regime.

What are the NIST CSF Tiers?

The Tiers are a way of describing where an organization currently sits, expressed across two dimensions. Cybersecurity risk governance covers how risk decisions get made, approved and turned into policy. Cybersecurity risk management covers how those decisions are carried out day to day, including with suppliers.

Tier Risk governance Risk management
Tier 1 — Partial Risk management is ad hoc and reactive. Prioritization is not informed by organizational risk objectives, the threat environment or business requirements. Limited awareness of cyber risk. Risk management is applied irregularly, case by case. Little or no internal information sharing; typically no coordination with third parties on supply chain risk.
Tier 2 — Risk Informed Management approves risk management practices, but they may not be established as organization-wide policy. Prioritization is informed by risk objectives, threat environment and business requirements. Awareness exists but there is no organization-wide approach. Some risk-informed policies and processes exist. Information is shared informally. Supply chain risk is considered but acted on inconsistently.
Tier 3 — Repeatable Risk management practices are formally approved and expressed as policy, and are updated as requirements and the threat and technology landscape change. An organization-wide approach with consistent methods for responding to changes in risk. Personnel have the knowledge and skills to perform their roles. Senior leadership communicates about cyber risk regularly. Supplier decisions are governed by policy.
Tier 4 — Adaptive An organization-wide approach informed by past and current activity and by predictive indicators, with continuous improvement. Cybersecurity is built into budgeting, hiring and technology decisions. Practices adapt from lessons learned and predictive indicators. Real-time or near-real-time understanding of risk. Organization-wide information sharing, including receiving, generating and disseminating supply chain risk information.

Read the two columns together. A company can have excellent technical controls and still sit at Tier 2 because nothing is written down as policy — and, less often, have thorough policy with weak execution. The Tier is set by the weaker of the two.

Are NIST Tiers maturity levels?

No, and the distinction matters more than it sounds.

NIST’s own framing is that the Tiers “characterize the rigor of an organization’s cybersecurity risk governance and management practices” and provide context for how it views cyber risk and the processes it uses to manage it. They are descriptive, not prescriptive, and they are explicitly meant to complement a risk management methodology rather than replace one.

Three consequences follow directly:

  • There is no assessment, audit or certificate. Nobody issues a NIST CSF Tier. If a vendor claims to be “NIST Level 3 certified”, they are describing a self-assessment or confusing the CSF with something else.
  • Higher is not automatically better. NIST’s guidance is that organizations should move to a higher Tier when a cost-benefit analysis shows it would reduce cyber risk in a feasible, cost-effective way. Otherwise the correct decision is to stay put and spend the budget elsewhere.
  • The Tier is not a score to optimize. A Tier is useful as a shared vocabulary for a board conversation — “we make good decisions but they are not written down anywhere” — not as a number to raise for its own sake.

This is why the language of “NIST maturity levels”, common across the industry and in a good deal of published content, is misleading. A maturity model implies a ladder every organization should climb. The Tiers describe a fit between an organization’s risk profile and the rigor of its practices.

What changed in CSF 2.0?

The 2024 revision was the first substantive change to the framework since 2014, and three things about it affect how Tiers are used.

Govern became a function. CSF 2.0 added Govern to the original five — Identify, Protect, Detect, Respond, Recover — and positioned it as the function that informs all the others. Risk strategy, roles and responsibilities, policy, oversight and supply chain risk management sit here. In practice this made explicit what Tier 3 always implied: the difference between tiers is largely a governance difference.

Scope widened beyond critical infrastructure. CSF 2.0 is written for organizations of any size and sector, which removed the awkwardness of a mid-sized SaaS company using a framework nominally aimed at power grids.

Tiers were reframed around governance and management. Rather than a single characterization, each Tier is now described across the two dimensions in the table above, and applied to Organizational Profiles — the Current Profile describing what you do today and the Target Profile describing where you intend to be.

If your program documentation still refers to the five functions or treats Tiers as a single-axis maturity score, it predates the current framework.

What does Tier 1 (Partial) look like in practice?

Security exists but nobody owns it. Antivirus is installed, backups probably run, and someone in IT handles incidents when they surface. What is missing is any connection between security activity and business risk: no one has decided what the organization is protecting, from whom, or what it is willing to lose.

The tell-tale signs are an absence of artefacts rather than an absence of tools — no risk register, no asset inventory, no incident response plan, no named owner, and no way to answer a customer questionnaire without inventing the answers.

Tier 1 is a legitimate place to start and a poor place to stay if you hold customer data. The first moves out of it are cheap: inventory your assets and data, name an owner, write down your top ten risks, and get a basic incident response plan on paper.

What does Tier 2 (Risk Informed) look like?

Risk decisions are now deliberate. Management has approved a set of practices, prioritization reflects actual business objectives and the threat environment, and someone can explain why the organization invests in the controls it does.

What is still missing is reach and permanence. The practices are approved but not established as organization-wide policy, so engineering may do things one way and finance another. Information moves informally — the security lead knows what happened, the wider organization does not. Third-party risk gets attention on important deals and is skipped on the rest.

Most companies that have never been through a formal audit sit here. It is a genuinely defensible position for a business with a modest risk profile, and it is the level at which enterprise procurement starts to notice the gaps.

What does Tier 3 (Repeatable) look like?

Tier 3 is where cybersecurity becomes an organizational property rather than a set of individual competencies. Five things distinguish it.

Formally approved policy

Risk management practices are not merely endorsed by management, they are expressed as policy. That means a document with an owner, an approval record, a review cycle and a defined process for changing it. The practical test: if the security lead left tomorrow, would the organization still do the same things next quarter?

Executive ownership

Only senior decision-makers have the authority to enforce a program that crosses every department, and at Tier 3 they exercise it. Cybersecurity risk is discussed by leadership on a regular cadence, not only after an incident, and budget and priority decisions reflect the risk register.

Consistency across the organization

The same method is applied everywhere. Definitions, risk tolerance, escalation paths, response playbooks and target metrics are standardized, so two teams facing the same situation take the same action. This is the single largest practical difference from Tier 2, where the same situation might be handled well in one department and improvised in another.

Competent people in defined roles

Roles and responsibilities are documented, and the people holding them have the knowledge and skills to do the work. Tier 3 fails quietly when a policy assigns a control to a role that has neither the time nor the expertise to run it.

Practices that get updated

Policies are revised in response to changes in business requirements and in the threat and technology landscape — not on a calendar alone. Regular risk assessments feed those revisions, and the revision history is itself evidence.

Tier 3 is also, not coincidentally, roughly the operating posture a SOC 2 Type II examination or an ISO 27001 certification audit assumes. Neither framework references CSF Tiers, but both require documented, approved, consistently applied and periodically reviewed practices — the same four properties.

What does Tier 4 (Adaptive) look like?

Tier 4 adds two things to Tier 3: prediction and speed.

The program adapts on the basis of lessons learned and predictive indicators rather than only on completed reviews. Understanding of risk is real-time or near-real-time rather than point-in-time. Cybersecurity considerations are embedded in budgeting, hiring and technology selection as a matter of course rather than as a review gate. Supply chain risk information flows both ways: the organization receives it, generates it and disseminates it to partners.

The honest assessment is that Tier 4 costs a great deal and pays back only where the risk profile justifies it — organizations holding very large volumes of sensitive data, operating critical services, or facing sophisticated and persistent adversaries. For a 200- to 1,000-person software company, the marginal risk reduction from Tier 3 to Tier 4 is usually smaller than the same budget spent on closing Tier 3 gaps that were never fully closed.

Which tier should your organization target?

Work from risk, not ambition. The questions that actually determine the answer:

  • What would a serious incident cost you? Not just remediation — contractual penalties, customer churn, regulatory exposure and the deals you would not close during the aftermath.
  • What do your customers require? Enterprise procurement and security questionnaires impose an effective floor. If you sell to regulated industries, that floor is Tier 3 in all but name.
  • What is your regulatory exposure? Sectoral rules and state privacy laws raise the cost of informality independently of any customer requirement.
  • Can you sustain the tier you reach? A program that reaches Tier 3 during an audit push and drifts back to Tier 2 afterwards is a Tier 2 program with an expensive spike in it.

For most mid-market companies handling customer data, Tier 3 across the board is the right target, with Tier 4 characteriztics adopted selectively in the areas of highest risk — continuous monitoring on production systems, for instance, without rebuilding the entire program around real-time telemetry.

How do you move from Tier 2 to Tier 3?

  1. Convert approved practice into written policy. Start with what you already do well. Each policy needs an owner, an approver, a review cadence and a change process — the governance wrapper is the thing that is missing, not the content.
  2. Fix the scope gaps. List every department and every system. Anywhere a practice applies to some but not all is a Tier 2 remnant. Shadow IT and recently acquired teams are the usual offenders.
  3. Standardize the vocabulary. Agree definitions, risk categories, severity levels, risk tolerance and target metrics, and publish them. Consistent action is impossible without shared terms.
  4. Put risk on the leadership agenda on a schedule. A standing item with a short, honest report beats an annual deep dive nobody reads.
  5. Extend the approach to suppliers. Governed, policy-based third-party decisions are part of the Tier 3 description, not an optional extra.
  6. Make the evidence continuous. Tier 3 is a claim about what happens every day. Evidence gathered once a year describes a week, not a year — which is also why audit preparation is painful for organizations that operate this way.
  7. Re-assess against both dimensions. Score governance and management separately. The lower one is your Tier, and it tells you where the next quarter’s work is.

How do Tiers relate to Profiles, and to other frameworks?

Tiers describe rigor; Profiles describe content. An Organizational Profile records which CSF outcomes you are pursuing, in what priority — a Current Profile for today and a Target Profile for where you intend to be. Tiers then characterize how rigorously you govern and manage the work of closing the gap between them. The two are designed to be used together: the Profile says what, the Tier says how well.

Against other standards, the useful comparisons are these. SOC 2 and ISO 27001 are attestation and certification regimes with auditors and reports; the CSF has neither, and a Tier is self-assessed. NIST SP 800-53 and SP 800-171 are control catalogs — specific requirements you implement — where the CSF is an organising structure that sits above them. And CMMC, whose levels are frequently confused with CSF Tiers because both use ordinal numbers, is a separate Department of Defense program with its own assessment requirements; a CSF Tier says nothing about CMMC status and vice versa.

How Compyl helps you reach and hold Tier 3

Most of the distance between Tier 2 and Tier 3 is administrative rather than technical: policies that exist but are not owned, controls applied in some teams and not others, evidence that has to be reassembled by hand each audit cycle. Compyl holds policies, owners, review cycles and control evidence in one place, maps a single control set across the frameworks a business is actually subject to, and collects evidence continuously so that the consistency Tier 3 requires is demonstrable rather than asserted.

Book a demo to see how Compyl supports NIST CSF alongside SOC 2, ISO 27001 and the rest of your program.

NIST CSF Tier FAQs

What are the four NIST CSF Tiers?

Tier 1 Partial, Tier 2 Risk Informed, Tier 3 Repeatable and Tier 4 Adaptive. Each is described across two dimensions — cybersecurity risk governance and cybersecurity risk management — and characterizes how rigorous an organization’s practices are, not how many controls it has implemented.

Is NIST Level 3 a certification?

No. There is no NIST CSF certification, audit or assessment body. Tiers are self-assessed and used internally to describe current and target states. Any claim of being “NIST Level 3 certified” is either a self-assessment described loosely or a confusion with a different framework.

What is the difference between NIST Tier 2 and Tier 3?

Scope and permanence. At Tier 2 management has approved risk management practices, but they may not be organization-wide policy and are applied inconsistently between teams. At Tier 3 those practices are formally approved policy, applied the same way across the organization, and updated as requirements and threats change.

Should every organization aim for Tier 4?

No. NIST’s guidance is to move to a higher Tier only when a cost-benefit analysis shows it would reduce cyber risk feasibly and cost-effectively. For many mid-sized organizations, closing the remaining gaps at Tier 3 delivers more risk reduction per dollar than pursuing Tier 4.

Are NIST CSF Tiers the same as CMMC levels?

No. They belong to different frameworks with different purposes. CMMC is a Department of Defense program with its own levels and assessment requirements for defense contractors. A CSF Tier is a self-assessed characterization under a voluntary framework and carries no CMMC standing.

How long does it take to move from Tier 2 to Tier 3?

For a mid-sized organization with an existing security function, six to twelve months is typical, and most of that time goes on documentation, ownership and consistency rather than new tooling. The variable that drives the timeline is how many separate teams and systems have to be brought under the same approach.

Does CSF 2.0 change the Tiers?

The four Tiers remain, but CSF 2.0 describes each of them across cybersecurity risk governance and cybersecurity risk management rather than as a single characterization, and it added Govern as a sixth function informing the other five. It also broadened the framework’s stated audience from critical infrastructure to organizations of all sizes and sectors.

Do SOC 2 or ISO 27001 require a particular NIST Tier?

Neither references CSF Tiers. In practice both assume the properties that define Tier 3 — documented, approved, consistently applied and periodically reviewed practices — so organizations preparing for either usually find they are doing Tier 3 work under a different name.

How do you assess your current Tier?

Score governance and management separately against the Tier descriptions, using evidence rather than intent: does the policy exist, who approved it, when was it last reviewed, and does every team follow it? Your Tier is the lower of the two scores, and the gap between them is usually the most useful output of the exercise.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies