The Current Profile describes the cybersecurity outcomes an organisation is achieving now, or trying to achieve at present. The Target Profile defines the outcomes it wants to reach based on risk, mission needs, and planned changes. Comparing the two exposes gaps, helps prioritise remediation, and gives security teams a practical roadmap for maturity improvements.
Why This Matters for Security Teams
The difference between Current and Target Profiles is practical, not academic: it turns a broad framework into a gap analysis that can be funded, tracked, and verified. Current Profile captures what outcomes are actually being achieved today, while Target Profile expresses the outcomes the organisation needs based on risk, mission priorities, and planned change. Without both, CSF 2.0 becomes a static checklist instead of a management tool.
This distinction matters even more when non-human identities are in scope. NHIMG research shows that only 5.7% of organisations have full visibility into their service accounts, which means the real Current Profile is often weaker than leaders assume. That is why NIST positions the NIST Cybersecurity Framework 2.0 as an outcomes-based model rather than a maturity slogan, and why practitioners should read NHIMG’s Ultimate Guide to NHIs — What are Non-Human Identities alongside profile work when service accounts, API keys, and automation are part of the risk picture. In practice, many security teams discover profile gaps only after a breach review exposes what was never measured.
How It Works in Practice
A Current Profile should describe the outcomes the organisation can demonstrate today, not the controls it hopes are working. That means basing it on evidence: asset coverage, identity inventories, logging quality, recovery testing, access review cadence, and exception handling. A Target Profile then defines the desired state for each relevant outcome, with risk-based priority and timing. The comparison between them is the roadmap.
For NIST CSF 2.0, security teams usually map both profiles to the same outcome language so the gap is obvious. The process often looks like this:
- Identify the CSF outcomes most relevant to the business unit, system, or regulated environment.
- Document current performance using measurable evidence, not policy statements.
- Set target outcomes based on mission impact, threat exposure, and dependency on critical identities.
- Rank gaps by risk, then assign owners, deadlines, and acceptance criteria.
- Reassess after remediation or major architectural change.
For identity-heavy environments, this is where NHIs often change the answer. An organisation may have a reasonable Current Profile for human access while still being weak on machine identities, which inflates the gap between stated policy and actual practice. The Ultimate Guide to NHIs — Standards is useful here because it frames lifecycle, rotation, and visibility expectations in operational terms, while NIST AI 600-1 GenAI Profile helps teams see how profile-based governance extends to AI-enabled workflows. These controls tend to break down when organisations treat profile scoring as a one-time assessment, because the Current Profile drifts as systems, identities, and dependencies change.
Common Variations and Edge Cases
Tighter profile management often increases assessment overhead, requiring organisations to balance better risk visibility against the effort needed to collect and validate evidence. That tradeoff becomes sharper in fast-changing environments, especially where NHIs, CI/CD pipelines, or AI agents create frequent access changes.
There is no universal standard for how detailed a Current Profile must be. Some teams keep it at the enterprise level, while others maintain separate profiles by business service, platform, or regulated system. Best practice is evolving, but the key is consistency: the Current Profile should be honest about what is achieved now, and the Target Profile should be specific enough to drive action. For example, a target may require stronger secret rotation or more complete visibility into service accounts, but the profile should avoid vague statements like “improve identity hygiene.”
Edge cases often appear during mergers, cloud migrations, or AI rollout. In those situations, the Current Profile may reflect inherited risk that no longer matches the organisation’s intended operating model. NIST IR 8596 is helpful when AI systems introduce new operational dependencies, because it reinforces that governance must keep pace with technical change. Practitioners should treat profile comparison as a living control loop, not a compliance artifact, and revisit the Target Profile whenever risk appetite, architecture, or identity sprawl changes materially.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF, NIST IR 8596 and NIST AI 600-1 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC | Profiles connect current state to mission and risk context. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity visibility gaps often distort the Current Profile for NHIs. |
| NIST AI RMF | GOVERN | AI-driven workflows can shift the profile baseline over time. |
| NIST IR 8596 | AI system dependencies can create new risk gaps between profiles. | |
| NIST AI 600-1 | Generative AI profiles illustrate how target outcomes are set for changing systems. |
Define Current and Target Profiles against mission outcomes, then use the gap to drive remediation priorities.
Related resources from NHI Mgmt Group
- What is the difference between NIST CSF 2.0 and a point-in-time security checklist?
- What is the difference between IGA and the Detect and Respond functions in NIST CSF 2.0?
- What is the difference between NIST 800-53 and ISO 27001 for access control programmes?
- What is the difference between privilege reduction and secret rotation?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org