Join our Newsletter — 33% off our NHI Course
Home FAQ Architecture & Implementation What is the difference between the Current Profile…
Architecture & Implementation

What is the difference between the Current Profile and the Target Profile in NIST CSF 2.0?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 1, 2026 Domain: Architecture & Implementation

The Current Profile describes the cybersecurity outcomes an organisation is achieving now, or trying to achieve at present. The Target Profile defines the outcomes it wants to reach based on risk, mission needs, and planned changes. Comparing the two exposes gaps, helps prioritise remediation, and gives security teams a practical roadmap for maturity improvements.

Why This Matters for Security Teams

The difference between Current and Target Profiles is practical, not academic: it turns a broad framework into a gap analysis that can be funded, tracked, and verified. Current Profile captures what outcomes are actually being achieved today, while Target Profile expresses the outcomes the organisation needs based on risk, mission priorities, and planned change. Without both, CSF 2.0 becomes a static checklist instead of a management tool.

This distinction matters even more when non-human identities are in scope. NHIMG research shows that only 5.7% of organisations have full visibility into their service accounts, which means the real Current Profile is often weaker than leaders assume. That is why NIST positions the NIST Cybersecurity Framework 2.0 as an outcomes-based model rather than a maturity slogan, and why practitioners should read NHIMG’s Ultimate Guide to NHIs — What are Non-Human Identities alongside profile work when service accounts, API keys, and automation are part of the risk picture. In practice, many security teams discover profile gaps only after a breach review exposes what was never measured.

How It Works in Practice

A Current Profile should describe the outcomes the organisation can demonstrate today, not the controls it hopes are working. That means basing it on evidence: asset coverage, identity inventories, logging quality, recovery testing, access review cadence, and exception handling. A Target Profile then defines the desired state for each relevant outcome, with risk-based priority and timing. The comparison between them is the roadmap.

For NIST CSF 2.0, security teams usually map both profiles to the same outcome language so the gap is obvious. The process often looks like this:

  • Identify the CSF outcomes most relevant to the business unit, system, or regulated environment.
  • Document current performance using measurable evidence, not policy statements.
  • Set target outcomes based on mission impact, threat exposure, and dependency on critical identities.
  • Rank gaps by risk, then assign owners, deadlines, and acceptance criteria.
  • Reassess after remediation or major architectural change.

For identity-heavy environments, this is where NHIs often change the answer. An organisation may have a reasonable Current Profile for human access while still being weak on machine identities, which inflates the gap between stated policy and actual practice. The Ultimate Guide to NHIs — Standards is useful here because it frames lifecycle, rotation, and visibility expectations in operational terms, while NIST AI 600-1 GenAI Profile helps teams see how profile-based governance extends to AI-enabled workflows. These controls tend to break down when organisations treat profile scoring as a one-time assessment, because the Current Profile drifts as systems, identities, and dependencies change.

Common Variations and Edge Cases

Tighter profile management often increases assessment overhead, requiring organisations to balance better risk visibility against the effort needed to collect and validate evidence. That tradeoff becomes sharper in fast-changing environments, especially where NHIs, CI/CD pipelines, or AI agents create frequent access changes.

There is no universal standard for how detailed a Current Profile must be. Some teams keep it at the enterprise level, while others maintain separate profiles by business service, platform, or regulated system. Best practice is evolving, but the key is consistency: the Current Profile should be honest about what is achieved now, and the Target Profile should be specific enough to drive action. For example, a target may require stronger secret rotation or more complete visibility into service accounts, but the profile should avoid vague statements like “improve identity hygiene.”

Edge cases often appear during mergers, cloud migrations, or AI rollout. In those situations, the Current Profile may reflect inherited risk that no longer matches the organisation’s intended operating model. NIST IR 8596 is helpful when AI systems introduce new operational dependencies, because it reinforces that governance must keep pace with technical change. Practitioners should treat profile comparison as a living control loop, not a compliance artifact, and revisit the Target Profile whenever risk appetite, architecture, or identity sprawl changes materially.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF, NIST IR 8596 and NIST AI 600-1 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OCProfiles connect current state to mission and risk context.
OWASP Non-Human Identity Top 10NHI-01Identity visibility gaps often distort the Current Profile for NHIs.
NIST AI RMFGOVERNAI-driven workflows can shift the profile baseline over time.
NIST IR 8596AI system dependencies can create new risk gaps between profiles.
NIST AI 600-1Generative AI profiles illustrate how target outcomes are set for changing systems.

Define Current and Target Profiles against mission outcomes, then use the gap to drive remediation priorities.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 1, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org