CSF 2.0 Organizational Profile: Current vs Target and gap analysis
An Organizational Profile is how CSF 2.0 turns its outcomes into a plan specific to your organization. The assistant walks you through the five-step process from NIST SP 1301 and the CSF itself, from scoping to updating the profile.
Ask your question
Free account requiredAnswers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.
The five-step profile process
The CSF describes five steps: scope the Organizational Profile, gather the information needed, create the profile, analyze the gaps between the Current and Target Profiles and create an action plan, then implement the plan and update the profile.
The scope records the high-level facts and assumptions behind the profile. You can have as many profiles as you like: one for the whole organization, one for financial systems, or one focused on ransomware affecting those systems. Scope can also follow technology (IT, OT), data types or users.
Current Profile, Target Profile and the action plan
A Current Profile shows which Core outcomes you achieve today and to what extent. A Target Profile lists the outcomes you have selected and prioritized, taking into account expected changes such as new requirements, new technology or threat trends.
The gap analysis compares current practices, across people, process and technology, with the CSF outcome descriptions, Informative References and Implementation Examples. The action plan then lists pending improvements, each with an action, priority, owner, deadline and resources.
NIST provides an Organizational Profile template as a spreadsheet on the CSF 2.0 website for side-by-side comparison of Current and Target Profiles.
Frequently asked questions
What is a Community Profile?
It is a baseline of CSF outcomes published for organizations that share interests, typically a sector, a technology or a threat type. You can copy it into your Organizational Profile as the basis of your Target Profile and adjust priorities or add your own Subcategories and guidance.
What are the four CSF Tiers?
Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3) and Adaptive (Tier 4). They describe how rigorous your risk governance and management practices are, from informal and ad hoc to agile and continuously improving.
Must every organization aim for Tier 4?
No. The CSF encourages moving to a higher Tier when risks or mandates are greater, or when a cost-benefit analysis shows a feasible and cost-effective reduction of risk. Tiers should complement your risk management methodology, not replace it.
Embed / API / MCP
Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.
MCP for your agents
This base's MCP server URL (tools ask_base and search_base):
https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurityClaude Code, Cursor and other clients
claude mcp add --transport http kopik-nist-csf-2-small-business-cybersecurity "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity" --header "Authorization: Bearer kpk_…"{
"mcpServers": {
"kopik-nist-csf-2-small-business-cybersecurity": {
"url": "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity",
"headers": {
"Authorization": "Bearer kpk_…"
}
}
}
}REST API for your apps
mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.
curl -X POST https://kopik.io/api/v1/bases/nist-csf-2-small-business-cybersecurity/query \
-H "Authorization: Bearer kpk_…" \
-H "Content-Type: application/json" \
-d '{"question": "Your question here", "mode": "answer"}'Getting started
- Create a key in your dashboard and top up your credit.
- Replace
kpk_…with your key. - Full details (responses, errors, JS and Python examples): developer docs.