What Is a Cybersecurity Maturity Score?
A cybersecurity maturity score expresses how repeatable, governed, measured and effective an organization's security capabilities are. It is not a measure of how exposed the organization is today — that is a cyber risk score. The two are complementary, and the most useful maturity scores are the ones built from verified evidence rather than self-reported answers.
Definition
Maturity models describe the progression of a capability from ad hoc to optimized. The idea entered cybersecurity through models such as the U.S. Department of Energy's C2M2, which grades practices by Maturity Indicator Level[2], and the Department of Defense's CMMC, which defines assessment levels for defence contractors.[3] A cybersecurity maturity score normalizes that idea into a single number — typically 0–100 — accompanied by a small number of named levels that executives can interpret without reading the methodology.
The question a maturity score answers is: how sophisticated, consistent and well-governed is this organization's ability to manage cyber risk? A well-built score should also tell you why each level was assigned, what evidence supports it, and what prevents the next level.
The 0–5 maturity levels
| Level | Name | What it means |
|---|---|---|
| 0 | Not Established | Practices are absent, materially incomplete or unsupported by evidence. |
| 1 | Initial | Activities occur inconsistently, reactively or informally. |
| 2 | Developing | Processes exist but are incomplete, inconsistently applied or not institutionalized. |
| 3 | Defined | Processes, responsibilities and controls are documented, implemented and consistently applied. |
| 4 | Managed | Capabilities are measured, governed and monitored with metrics and defined accountability. |
| 5 | Adaptive / Optimized | Capabilities are continuously measured, tested, automated where appropriate and adjusted to threat and business change. |
What is actually measured
A questionnaire average measures how confidently people answer. A maturity score should measure the capability itself, across several dimensions for every domain — identity, vulnerability management, incident response, third-party risk and so on:
- Implementation and coverage — Is the control in place, and across how much of the applicable environment? MFA on 95% of accounts is a different fact from MFA for administrators only.
- Documentation and repeatability — Are policies, procedures and owners defined, and is the capability executed consistently?
- Governance and measurement — Are accountability, oversight and KPIs/KRIs established and reviewed?
- Effectiveness and testing — Is there evidence the control works, and is it periodically validated — penetration tests, exercises, audits?
- Automation and continuous improvement — Is enforcement automated, and does evidence show performance being reviewed and improved?
Control frameworks such as CIS Controls v8.1[4] and ISO/IEC 27001:2022[5] supply the control inventory these dimensions are assessed against; NIST CSF 2.0 supplies the outcome taxonomy most organizations use to organize them.[1]
Evidence and confidence
Every maturity conclusion should carry an evidence-confidence score. Machine-generated evidence collected through an integration is very high confidence; a recently validated audit artifact is high; a screenshot requiring interpretation is medium; a management attestation is low; an unverified questionnaire answer is very low. Evidence also ages: configuration evidence may be trusted for weeks, a penetration test for twelve months. When evidence expires, the affected controls and domains should recalculate.
Why averages are not enough
Averaging lets strong scores in several controls offset a critical missing capability. Serious maturity engines apply level gates: to reach Level 4, a domain must clear minimum implementation thresholds, critical controls cannot sit below defined floors, and governance, measurement and testing must exist. The result can therefore be "calculated score 82, maximum defensible maturity Level 3 — incident-response exercises have not been validated in the required period." That sentence is worth more than the number.
How organizations use it
- Board and executive reporting — Maturity, cyber-risk score and financial exposure presented together, with progress against a target.
- Prioritization — Ranking actions by maturity gain, risk reduction and effort rather than by control number.
- Framework alignment — Reporting NIST CSF Tiers, CIS Implementation Groups, ISO coverage and CMMC readiness in each framework's own terms — see NIST CSF Tiers vs maturity levels.
- Vendors and transactions — Assessing supplier and acquisition-target maturity alongside their third-party risk score.
How Xcigence implements this — including the simulator that estimates the effect of selected actions — is described on Cybersecurity Maturity Intelligence.
Evidence-driven 0–100 maturity scoring, framework alignment and next-best-action planning.
References
- [1]NIST. Cybersecurity Framework (CSF) 2.0 — NIST CSWP 29
- [2]U.S. Department of Energy. Cybersecurity Capability Maturity Model (C2M2)
- [3]U.S. Department of Defense. Cybersecurity Maturity Model Certification (CMMC)
- [4]Center for Internet Security. CIS Critical Security Controls v8.1
- [5]ISO. ISO/IEC 27001:2022 — Information security management systems
Continue reading
Maturity asks how capable your program is. Risk asks how much exposure you carry right now. An organization can be high on one and low on the other — and the four combinations each call for a different response.
NIST is explicit that CSF Tiers are not maturity levels. What the four Tiers actually describe, how they relate to C2M2 and CMMC, and how a normalized 0–5 maturity model keeps each framework in its own terms.
A cybersecurity risk score turns observable security evidence into a standardized number decision-makers can compare, price, and act on. Here is what goes into one and what makes it defensible.
See your own cyber risk score
Xcigence computes a standardized 300–850 cyber risk score for your organization and every vendor in your ecosystem — no agents, no questionnaires.