Maturity

What Is a Cybersecurity Maturity Score?

XR
Xcigence Research
Cyber Risk Intelligence Team
9 min read

A cybersecurity maturity score expresses how repeatable, governed, measured and effective an organization's security capabilities are. It is not a measure of how exposed the organization is today — that is a cyber risk score. The two are complementary, and the most useful maturity scores are the ones built from verified evidence rather than self-reported answers.

Definition

Maturity models describe the progression of a capability from ad hoc to optimized. The idea entered cybersecurity through models such as the U.S. Department of Energy's C2M2, which grades practices by Maturity Indicator Level[2], and the Department of Defense's CMMC, which defines assessment levels for defence contractors.[3] A cybersecurity maturity score normalizes that idea into a single number — typically 0–100 — accompanied by a small number of named levels that executives can interpret without reading the methodology.

The question a maturity score answers is: how sophisticated, consistent and well-governed is this organization's ability to manage cyber risk? A well-built score should also tell you why each level was assigned, what evidence supports it, and what prevents the next level.

The 0–5 maturity levels

LevelNameWhat it means
0Not EstablishedPractices are absent, materially incomplete or unsupported by evidence.
1InitialActivities occur inconsistently, reactively or informally.
2DevelopingProcesses exist but are incomplete, inconsistently applied or not institutionalized.
3DefinedProcesses, responsibilities and controls are documented, implemented and consistently applied.
4ManagedCapabilities are measured, governed and monitored with metrics and defined accountability.
5Adaptive / OptimizedCapabilities are continuously measured, tested, automated where appropriate and adjusted to threat and business change.
The Xcigence normalized maturity model. The 0–100 score provides granularity; the level provides interpretability.

What is actually measured

A questionnaire average measures how confidently people answer. A maturity score should measure the capability itself, across several dimensions for every domain — identity, vulnerability management, incident response, third-party risk and so on:

  • Implementation and coverage — Is the control in place, and across how much of the applicable environment? MFA on 95% of accounts is a different fact from MFA for administrators only.
  • Documentation and repeatability — Are policies, procedures and owners defined, and is the capability executed consistently?
  • Governance and measurement — Are accountability, oversight and KPIs/KRIs established and reviewed?
  • Effectiveness and testing — Is there evidence the control works, and is it periodically validated — penetration tests, exercises, audits?
  • Automation and continuous improvement — Is enforcement automated, and does evidence show performance being reviewed and improved?

Control frameworks such as CIS Controls v8.1[4] and ISO/IEC 27001:2022[5] supply the control inventory these dimensions are assessed against; NIST CSF 2.0 supplies the outcome taxonomy most organizations use to organize them.[1]

Evidence and confidence

Every maturity conclusion should carry an evidence-confidence score. Machine-generated evidence collected through an integration is very high confidence; a recently validated audit artifact is high; a screenshot requiring interpretation is medium; a management attestation is low; an unverified questionnaire answer is very low. Evidence also ages: configuration evidence may be trusted for weeks, a penetration test for twelve months. When evidence expires, the affected controls and domains should recalculate.

Key point
"Maturity 74/100 — confidence 91%" and "Maturity 74/100 on unverified answers" are not the same statement. A result without adequate evidence should be labelled provisional.

Why averages are not enough

Averaging lets strong scores in several controls offset a critical missing capability. Serious maturity engines apply level gates: to reach Level 4, a domain must clear minimum implementation thresholds, critical controls cannot sit below defined floors, and governance, measurement and testing must exist. The result can therefore be "calculated score 82, maximum defensible maturity Level 3 — incident-response exercises have not been validated in the required period." That sentence is worth more than the number.

How organizations use it

  • Board and executive reporting — Maturity, cyber-risk score and financial exposure presented together, with progress against a target.
  • Prioritization — Ranking actions by maturity gain, risk reduction and effort rather than by control number.
  • Framework alignment — Reporting NIST CSF Tiers, CIS Implementation Groups, ISO coverage and CMMC readiness in each framework's own terms — see NIST CSF Tiers vs maturity levels.
  • Vendors and transactions — Assessing supplier and acquisition-target maturity alongside their third-party risk score.

How Xcigence implements this — including the simulator that estimates the effect of selected actions — is described on Cybersecurity Maturity Intelligence.

Part of our guide to
Cybersecurity Maturity Intelligence

Evidence-driven 0–100 maturity scoring, framework alignment and next-best-action planning.

References

  1. [1]NIST. Cybersecurity Framework (CSF) 2.0 — NIST CSWP 29
  2. [2]U.S. Department of Energy. Cybersecurity Capability Maturity Model (C2M2)
  3. [3]U.S. Department of Defense. Cybersecurity Maturity Model Certification (CMMC)
  4. [4]Center for Internet Security. CIS Critical Security Controls v8.1
  5. [5]ISO. ISO/IEC 27001:2022 — Information security management systems

See your own cyber risk score

Xcigence computes a standardized 300–850 cyber risk score for your organization and every vendor in your ecosystem — no agents, no questionnaires.

We use cookies to improve your experience on our site, analyze site traffic, and assist in our marketing efforts. By clicking "Accept All", you consent to our use of cookies in accordance with GDPR, CCPA, and ISO27001 privacy standards.