Tier 1/2/3 Risk Management
Tier 1/2/3 Risk Management refers to a three-level model, defined in NIST SP 800-39, for organizing how an organization manages cybersecurity and related risk. The tiers move from the highest, organization-wide level down through the mission and business process level to the individual system level, so that risk decisions at the top inform activities further down. This layered structure is intended to help leadership align risk decisions across the whole organization rather than treating each system in isolation.
As defined in NIST SP 800-39, the three-tiered risk management approach establishes three organizational levels: Level (Tier) 1 is the organizational level, where senior leadership addresses risk from a governance and enterprise-wide perspective; Level (Tier) 2 is the mission/business process level, where risk is considered in the context of the processes that support the organization's mission; and Level (Tier) 3 is the information system level, where risk is managed for individual systems. The model is intended to be hierarchical and interrelated, with risk-related decisions and guidance flowing between tiers. Note that this NIST SP 800-39 tiering is distinct from other tiering schemes (for example, vendor or assessment tiering models) that use similar 'Tier 1/2/3' terminology; readers should confirm which framework is being referenced and verify the current authoritative text, as specific guidance may be updated across revisions.
Why it matters
Managing cybersecurity risk one system at a time tends to produce inconsistent decisions, duplicated effort, and blind spots at the enterprise level. The Tier 1/2/3 model in NIST SP 800-39 addresses this by connecting risk decisions across three organizational levels, so that governance priorities set by senior leadership flow down into how mission and business processes are structured and, ultimately, into how individual systems are secured. For defense and public sector organizations, this alignment matters because system-level authorization decisions should reflect an organization's broader risk tolerance and mission needs rather than being made in isolation.
The tiered approach also clarifies where accountability sits. When risk is treated purely as a system-level or technical concern, senior leadership can be disconnected from decisions that carry enterprise-wide consequences. By placing organization-wide governance at Tier 1, the model is intended to ensure that risk decisions are informed by leadership priorities and that guidance is communicated consistently across the mission/business process and system tiers.
A common point of confusion is that the phrase 'Tier 1/2/3' appears in several unrelated contexts, such as vendor or assessment tiering schemes. These use similar terminology but describe different concepts. Practitioners should confirm which framework a document is referencing before applying it, and should verify the current authoritative text, since NIST guidance may be updated across revisions.
Who it's relevant to
Inside Tier 1/2/3 Risk Management
Common questions
Answers to the questions practitioners most commonly ask about Tier 1/2/3 Risk Management.