Tech & product

CSF 2.0 Organizational Profile: Current vs Target and gap analysis

An Organizational Profile is how CSF 2.0 turns its outcomes into a plan specific to your organization. The assistant walks you through the five-step process from NIST SP 1301 and the CSF itself, from scoping to updating the profile.

Ask your question

Free account required

Each question stands alone · 1 free a month, then with a subscription.

Answers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.

The five-step profile process

The CSF describes five steps: scope the Organizational Profile, gather the information needed, create the profile, analyze the gaps between the Current and Target Profiles and create an action plan, then implement the plan and update the profile.

The scope records the high-level facts and assumptions behind the profile. You can have as many profiles as you like: one for the whole organization, one for financial systems, or one focused on ransomware affecting those systems. Scope can also follow technology (IT, OT), data types or users.

Current Profile, Target Profile and the action plan

A Current Profile shows which Core outcomes you achieve today and to what extent. A Target Profile lists the outcomes you have selected and prioritized, taking into account expected changes such as new requirements, new technology or threat trends.

The gap analysis compares current practices, across people, process and technology, with the CSF outcome descriptions, Informative References and Implementation Examples. The action plan then lists pending improvements, each with an action, priority, owner, deadline and resources.

NIST provides an Organizational Profile template as a spreadsheet on the CSF 2.0 website for side-by-side comparison of Current and Target Profiles.

Frequently asked questions

What is a Community Profile?

It is a baseline of CSF outcomes published for organizations that share interests, typically a sector, a technology or a threat type. You can copy it into your Organizational Profile as the basis of your Target Profile and adjust priorities or add your own Subcategories and guidance.

What are the four CSF Tiers?

Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3) and Adaptive (Tier 4). They describe how rigorous your risk governance and management practices are, from informal and ad hoc to agile and continuously improving.

Must every organization aim for Tier 4?

No. The CSF encourages moving to a higher Tier when risks or mandates are greater, or when a cost-benefit analysis shows a feasible and cost-effective reduction of risk. Tiers should complement your risk management methodology, not replace it.

For developers and agents

Embed / API / MCP

Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.

MCP for your agents

This base's MCP server URL (tools ask_base and search_base):

MCP URL
https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity
Claude Code, Cursor and other clients
Claude Code
claude mcp add --transport http kopik-nist-csf-2-small-business-cybersecurity "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity" --header "Authorization: Bearer kpk_…"
JSON config (mcpServers)
{
  "mcpServers": {
    "kopik-nist-csf-2-small-business-cybersecurity": {
      "url": "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

REST API for your apps

mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.

curl
curl -X POST https://kopik.io/api/v1/bases/nist-csf-2-small-business-cybersecurity/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Your question here", "mode": "answer"}'

Getting started

  1. Create a key in your dashboard and top up your credit.
  2. Replace kpk_… with your key.
  3. Full details (responses, errors, JS and Python examples): developer docs.