Skip to content

No. The NIST privacy framework recommends that companies summarize their maturity with respect to each category by using four “Tiers.” The Tiers are intended to describe whether the current practices of the company with respect to the domain are partially in place (Tier 1), risk informed (Tier 2), repeatable (Tier 3), or adaptive (Tier 4). While the NIST privacy framework contemplates that a maturity assignment using the tiering system will help a company “communicate internally about resource allocations necessary to progress to a higher Tier or as general benchmarks to gauge progress in its capability to manage privacy risks,” the privacy framework does not mandate that companies assign a tier to each subcategory, nor does the privacy framework mandate that companies achieve a certain tier level.[1] The net result is that the tiers are designed to be a tool to help companies conceptualize their maturity in relationship to specific privacy issues.

[1] NIST, NIST Privacy Framework: A Tool for Improving Privacy Through Enterprise Risk Management, Version 1.0 at 9 (Jan. 16, 2020).

About Greenberg Traurig

Greenberg Traurig, LLP has more than 3,200 lawyers across 51 locations in the United States, Europe, the Middle East, Latin America, and Asia. The firm’s broad geographic and practice range enables the delivery of innovative and strategic legal services across borders and industries. Recognized as a 2025 BTI “Best of the Best Recommended Law Firm” by general counsel for trust and relationship management, Greenberg Traurig is consistently ranked among the top firms on the Am Law Global 100, NLJ 500, and Law360 400. Greenberg Traurig is also known for its philanthropic giving, culture, innovation, and pro bono work. Web: www.gtlaw.com.

Law blog design & platform by LexBlog