The Current State Profile is the organization’s structured, evidence-based assessment of where its cybersecurity program stands today across all six functions of the NIST CSF 2.0 framework. For every function, category, and subcategory of the framework, it records the current implementation tier, the evidence that supports that assessment, and the gaps and weaknesses that the assessment reveals. It is the honest baseline: the document that establishes where the organization actually is, as distinct from where it assumes it is or where it intends to be.
This is one of the two most analytically demanding documents in the lab. The Current State Profile requires you to evaluate the organization’s cybersecurity posture systematically and honestly across the full breadth of the framework, supported by objective evidence rather than subjective impression. The quality of this assessment directly determines the quality of everything that follows: the Target State Profile, the Gap Analysis, the Risk Assessment, and ultimately the Implementation Roadmap all depend on the accuracy of the baseline you establish here.
Organizations routinely overestimate the maturity of their cybersecurity programs. This is not dishonesty: it is the natural consequence of evaluating a program from the inside, where familiarity with the intent of controls creates a tendency to assume their effectiveness. The security policy exists, so the organization assumes it is being followed. The firewall is in place, so the organization assumes it is correctly configured. The incident response plan was written two years ago, so the organization assumes it is still current and actionable. These assumptions, unchallenged by structured assessment, accumulate into a picture of the program that is systematically more optimistic than the evidence would support.
For organizations pursuing maturity improvement, the Current State Profile also establishes the baseline against which progress will be measured. Without an accurate starting point, it is impossible to demonstrate improvement credibly, to prioritize investment in the areas of greatest gap, or to show stakeholders that the program is moving in the right direction. The baseline you establish here is the reference point for every future assessment of the program’s development.
The Current State Profile is not a specific deliverable mandated by a particular category of NIST CSF 2.0: it is the mechanism through which the framework’s profiling methodology is applied. NIST CSF 2.0 introduces the concept of CSF Profiles as a core implementation tool, defining them as a representation of the outcomes that are important to the organization and the current or target state of those outcomes.
GV.OV: Oversight requires that results of cybersecurity risk management activities, including assessments of program performance, be used to inform and improve the cybersecurity program. The Current State Profile is the primary input to this oversight function.
GV.RM: Risk Management Strategy requires that the organization’s risk posture be understood and communicated to leadership. The Current State Profile provides the evidence base for communicating the organization’s actual risk posture.
ID.RA: Risk Assessment in the Identify function requires that risks to the organization be identified and analyzed. The Current State Profile’s assessment of control gaps and weaknesses is a direct input to the risk assessment process in Task 5.
The profile assessment uses NIST CSF 2.0’s four implementation tiers as the scoring mechanism. Understanding these tiers is essential before you begin the assessment.
The four implementation tiers: NIST CSF 2.0 defines four implementation tiers that describe the degree to which an organization’s cybersecurity risk management practices are characterized by rigor, repeatability, and integration with business risk decisions. The tiers are not maturity levels in the sense of a progressive scale that every organization must climb sequentially: they are descriptors of the current state of practice that help the organization understand where it is and where it needs to be given its risk environment and business objectives.
Tier 1: Partial describes a state where cybersecurity risk management practices are ad hoc and reactive. There is limited awareness of cybersecurity risk at the organizational level, risk management is not formalized, and cybersecurity activities are performed irregularly without defined processes.
Tier 2: Risk Informed describes a state where risk management practices exist but are not formally established as organizational policy. Cybersecurity activities are informed by risk, but implementation is inconsistent across the organization and may not be integrated with broader organizational risk management.
Tier 3: Repeatable describes a state where risk management practices are formally approved, expressed as policy, and consistently implemented across the organization. Cybersecurity activities are regularly updated based on changes in business requirements and the threat landscape.
Tier 4: Adaptive describes a state where the organization adapts its cybersecurity practices based on lessons learned, predictive indicators, and integration with organizational risk management decisions. Cybersecurity is considered a core element of organizational culture and is continuously improving.
Evidence-based assessment: Every tier rating in the Current State Profile must be supported by evidence. A rating is not a judgment or an aspiration: it is a conclusion drawn from observable, verifiable evidence of what the organization actually does. Evidence may take the form of documented policies and procedures, system configurations and logs, assessment results, training records, incident reports, third-party audit findings, or direct observation of operational practices. Where evidence is absent, the rating should reflect the absence of evidence, not the assumption that controls are in place.
Functional coverage: The Current State Profile must assess all six functions of the NIST CSF 2.0 framework: Govern, Identify, Protect, Detect, Respond, and Recover. A profile that assesses some functions thoroughly and skips others produces an incomplete picture of the organization’s security posture. The functions that are most likely to be underassessed are Govern, because it requires honest evaluation of leadership accountability and decision-making processes, and Recover, because recovery capabilities are rarely tested until they are needed.
The relationship between tiers and gaps: The tier rating for each category is not the end of the assessment: it is the starting point for gap identification. A Tier 1 or Tier 2 rating in a category tells you where the organization is. The gap analysis requires you to also assess where the organization needs to be given its risk environment, and the distance between those two points is the gap that the Target State Profile and the Implementation Roadmap will address.
Honest assessment under pressure: There is consistent pressure in first-time assessments to rate the organization more favorably than the evidence supports. This pressure comes from multiple directions: from leadership who do not want to see their program described as immature, from technical teams who feel that low ratings reflect poorly on their work, and from the natural human reluctance to document inadequacy formally. Resist this pressure. A Current State Profile that overstates maturity produces a Target State Profile that is too optimistic, a Gap Analysis that misses critical gaps, and an Implementation Roadmap that is built on a false foundation. The assessment is only valuable if it is honest.
Documenting the post-incident starting position: The organization is conducting this assessment in the aftermath of a significant security incident. That context must be reflected in the assessment. Some categories of the framework will have already been affected by the incident response: detective controls that failed to identify the attack, protective controls that were bypassed, recover capabilities that were activated and found to be inadequate. The Current State Profile must capture the pre-incident state of controls as the baseline, with the incident itself documented as evidence of the gaps the assessment reveals.
A strong Current State Profile is:
A weak Current State Profile assigns uniformly optimistic tier ratings without supporting evidence, skips categories that are difficult to assess honestly, fails to connect the incident’s occurrence to specific gaps in the framework’s control categories, and provides no basis for prioritizing the improvements that follow.
The most important discipline in completing a Current State Profile honestly is separating the existence of a control from its effectiveness. Most organizations have some form of most controls: a firewall, an antivirus product, a password policy, a backup system, an incident response plan. The question the Current State Profile must answer is not whether these things exist but whether they are working as intended, consistently applied, regularly reviewed, and integrated into the organization’s broader risk management decision-making.
A password policy that exists in a document but is not technically enforced is not a Tier 3 control. An incident response plan that was written three years ago, has never been tested, and lists three people who have since left the organization is not a Tier 2 control. A backup system that runs nightly but whose restoration has never been verified is not a recovery capability that belongs above Tier 1. Apply this discipline consistently across every category in the assessment and the profile will reveal the genuine starting position: which is the only starting position from which meaningful improvement can be built.