Risk & Leadership

Current and Target: Using NIST CSF 2.0 Organizational Profiles

A useful security update does more than list activity. It describes where the organization is, where it intends to be, which gap matters most, and who will review the move.

Part of the seriesSecurity Guidance, Applied

The value of a CSF Organizational Profile is the comparison. A Current Profile describes the cybersecurity outcomes an organization is achieving now; a Target Profile describes the outcomes it wants to achieve. Comparing the two makes gaps easier to discuss and assign.

What NIST provides

NIST's CSF 2.0 Profiles page provides a customizable Organizational Profile template. NIST describes the template as a spreadsheet that organizations can use to create Current and Target Profiles and compare them side by side to identify and analyze gaps.

The template is a structured way to communicate cybersecurity outcomes. It does not remove the need to decide what matters to the organization, which outcomes are appropriate, what evidence exists, or who owns follow-up.

From profile comparison to a reviewable decision
1. Describe currentRecord outcomes honestly, including unknowns and evidence boundaries.
2. Set targetDescribe desired outcomes in business and security terms, not product names.
3. Close the gapPrioritize, assign ownership and set a review date for the next decision.
This is ByteDefender's practical application sequence, not a replacement for NIST's template or guidance.
The LinkedIn visual for this edition
ByteDefender infographic carrying the signature Security Guidance, Applied 02. It presents four practical interpretation points for current and target CSF 2.0 Organizational Profiles: describe the current state honestly, describe the target state in outcomes, name the gap that matters most, and give each gap an owner and review date. A limitation states that a profile does not measure effectiveness and is not an assessment or audit.
The companion visual separates the NIST source from ByteDefender's practical interpretation.

Four practices that make a profile useful

1. Describe the current state honestly

A current profile is most useful when it makes uncertainty visible. Record the outcomes the organization can support today, the evidence behind that view, and the areas that are unknown. An unknown is not a failure; it is a signal that verification or a better owner is needed.

Avoid converting activity into an outcome automatically. “We have a security tool” does not, by itself, show that the relevant outcome is achieved or consistently operated.

2. Describe the target state in outcomes, not products

A target profile should describe the security result the organization needs. Product names may appear in an implementation plan, but they should not substitute for the outcome. This keeps the discussion open to proportionate people, process and technology options.

For example, a target can describe reliable detection and response for important services. The implementation may involve logging, ownership, playbooks, training or technology—but the profile should preserve the outcome being pursued.

3. Name the gap that matters most

A comparison can surface many differences. Leadership usually needs a sequence, not an undifferentiated list. Use business service importance, potential impact, exposure, dependencies and available capacity to identify the gap that deserves attention first.

This is a prioritization decision, not a claim that every other gap is safe to ignore. Record the rationale, assumptions and any accepted residual risk.

4. Give each gap an owner and a review date

A profile becomes actionable when each priority gap has a named decision owner, an implementation owner and a review point. The owner should have enough authority to coordinate work, resolve dependencies and explain what evidence will show progress.

A review date also prevents a profile from becoming a static presentation. Revisit it when important services, suppliers, threats, obligations or operating assumptions change.

A compact working record for one prioritized gap
Profile questionRecordUseful evidence
Where are we now?Current outcome, confidence and unknowns.Configuration, test result, exercise record or review artifact.
Where do we want to be?Target outcome and reason it matters.Approved objective, service requirement or risk decision.
What matters first?Priority gap, dependencies and assumptions.Impact rationale, exposure context and decision record.
Who will move it?Accountable leader, action owner and review date.Named owner, plan, status evidence and next review.

What a profile does not establish

A profile describes an organization's position and intent in relation to cybersecurity outcomes. It does not measure effectiveness, prove that controls operate as intended, or replace a security assessment or audit.

Where a decision depends on actual exposure or control performance, use the appropriate evidence: an assessment, configuration review, test, exercise, audit or other verification activity. The profile can help define what that work should answer.

A practical first working session

Bring together the person accountable for security decisions, the people who understand important services and the owners of relevant systems or providers. Start with one business service or risk theme rather than trying to complete the entire framework at once.

  1. Write the current outcome in plain language and mark what is unknown.
  2. Write the target outcome and why it matters to the service or organization.
  3. Compare the two and select one gap that deserves the next decision.
  4. Name the accountable leader, action owner, evidence expected and review date.
  5. Record dependencies, assumptions and any risk accepted while work proceeds.

The result is a short, reviewable decision record. It can support a board conversation, a client assurance discussion, a risk-assessment plan or a technical work queue without pretending to be any of those things on its own.

Where to begin

Download NIST's Organizational Profile template, choose one meaningful service or risk theme, and write the current state before debating solutions. Then describe the target state, select the most consequential gap and assign a review date.

If the organization cannot describe its current position in writing, that is useful information. It may indicate that the next step is evidence gathering, scope clarification or a focused risk assessment—not another product purchase.

Primary source

  1. NIST, CSF 2.0 Profiles — includes the customizable Organizational Profile template and explains its Current/Target comparison purpose.
  2. NIST Cybersecurity Framework 2.0 — framework context for communicating and managing cybersecurity risk.

Source status checked 6 September 2026. The NIST Profiles page was updated 16 June 2026 and remains the authoritative source for the template link. The four practices and working record in this article are ByteDefender's interpretation; they are not presented as NIST's complete assessment method.

Need a clearer current-to-target view?

ByteDefender can help define scope, gather evidence and turn priority gaps into an owned, reviewable improvement plan.

Explore risk assessment