Cybersecurity Maturity Assessment Tool

Score your security programme Level 1-5 across nine domains. Tier-weighted questions, peer benchmarking, risk quantification and a PDF roadmap. Free tool.

Advertisement

Cybersecurity Maturity Assessment Across Nine Security Domains

This cybersecurity maturity assessment scores your security programme from Level 1 (Initial) to Level 5 (Optimizing) across nine domains, benchmarks each domain against a peer average, and returns a roadmap to the next level with an investment range and timeline. It also quantifies current risk as a breach likelihood and an annual expected loss, so the output lands in a budget conversation rather than a slide deck.

It is built for IT directors, vCISOs, MSPs producing a client baseline, and leadership teams who need an evidence-backed answer to “where are we, actually?” The question bank holds around fifty questions, with conditional logic that skips branches your earlier answers make irrelevant. Progress saves automatically, results export to PDF, and nothing leaves your browser.

The Nine Domains

The assessment covers governance, asset management, identity and access, data protection, network security, vulnerability management, incident response, security training, and vendor risk. Each is scored independently, because a programme with excellent identity controls and no vendor risk management is a different problem from one that is uniformly mediocre — and a single overall number hides that distinction entirely.

How the Scoring Works

Every question offers five answers scored 0 to 4. Questions are not equal: each carries an intrinsic weight, and that weight is multiplied by a tier factor reflecting how foundational the control is.

Effective weight = question weight × tier multiplier, where tier 1 = 1.5, tier 2 = 1.0, tier 3 = 0.5.

Tier 1 covers the critical foundational controls aligned to CIS Implementation Group 1 — multi-factor authentication, backups, asset inventory, patching. Tier 3 covers advanced practices that only matter once the basics are in place. The bank is deliberately weighted toward the foundations: roughly half the questions are tier 1.

Domain score = Σ (answer score × effective weight) ÷ Σ (effective weight)

This produces a domain score on a 0–4 scale, mapped to a maturity level: below 0.5 is Level 1, below 1.5 is Level 2, below 2.5 is Level 3, below 3.5 is Level 4, and above that is Level 5. The overall score is the unweighted mean of the nine domain scores, mapped by the same thresholds.

One design decision matters more than it looks: answering “unknown” removes a question from both the numerator and the denominator. It does not score zero. If you do not know whether privileged access is reviewed quarterly, that is a governance finding, but the tool will not manufacture a false score from it. The practical consequence is that answering “unknown” to everything in a domain produces no score for that domain at all — so answer what you know and treat the gaps as their own action item.

A worked example

Suppose the identity and access domain has six questions. Three are tier 1 with weight 0.25 (effective weight 0.375 each), two are tier 2 with weight 0.20 (effective 0.20 each), one is tier 3 with weight 0.10 (effective 0.05).

  • Total effective weight: (3 × 0.375) + (2 × 0.20) + 0.05 = 1.575.
  • You score 3, 3, 2 on the tier 1 questions, 2 and 1 on tier 2, and 0 on tier 3.
  • Weighted total: (3×0.375) + (3×0.375) + (2×0.375) + (2×0.20) + (1×0.20) + (0×0.05) = 1.125 + 1.125 + 0.75 + 0.4 + 0.2 = 3.6.
  • Domain score = 3.6 ÷ 1.575 = 2.29 → Level 3 (Defined).

Note what the tier weighting did. Scoring zero on the advanced tier 3 question cost only 0.05 of weight — almost nothing. Dropping one tier 1 question from 3 to 2 cost 0.375. The model is telling you, correctly, that fixing a foundational gap moves your maturity far more than adding a sophisticated capability on top of a weak base.

Benchmarking and Percentiles

Each domain score is compared against a peer average and converted to a percentile using a normal approximation:

Percentile = 50 + ((your score − peer average) ÷ 0.8) × 34, clamped to 0–100.

The 0.8 is an assumed standard deviation across the peer population and 34 converts a standard deviation into percentile points. Be clear-eyed about what this is: a reasonable statistical approximation over a small internal benchmark set, not a survey of your actual competitors. Use the percentile to rank your own domains against each other — which is genuinely informative — rather than as a market position claim.

Risk Quantification and Roadmap

Maturity level is converted into a breach likelihood: 85% at Level 1, 55% at Level 2, 25% at Level 3, 10% at Level 4, 5% at Level 5. That likelihood is multiplied by a breach cost band scaled to your headcount to give an annual expected loss.

Annual expected loss = average breach cost for your size × breach likelihood

These likelihood figures are the model’s own risk-tiering, not published incidence rates, and should be read as relative rather than absolute — the useful signal is that moving from Level 2 to Level 3 more than halves modelled likelihood. For grounding on the cost side: IBM’s Cost of a Data Breach Report 2026, covering 602 breached organisations between March 2025 and February 2026, reported a global average breach cost of $4.99M and a US average of $11.5M, with healthcare highest at $6.64M. Verizon’s 2025 Data Breach Investigations Report, drawn from over 22,000 incidents and 12,195 confirmed breaches, found ransomware present in 88% of breaches at small and medium businesses.

The roadmap targets the next level up and attaches an investment range: roughly $25,000–$40,000 to move from Level 1 to 2, $50,000–$80,000 from Level 2 to 3, $45,000–$60,000 from 3 to 4, and $60,000–$100,000 from 4 to 5. Timelines run 3–6 months from Level 1, 6–12 months from Level 2, and 12–18 months above that. These are planning bands, not quotes.

How to Use It

  1. Set the company profile. Industry, size band, and regulatory obligations. Compliance selections drive the gap analysis — HIPAA flags domains below Level 2, SOC 2 flags domains below Level 3.
  2. Answer honestly, including “unknown”. An inflated score produces a roadmap for a programme you do not have.
  3. Read domain by domain. The lowest-scoring domains, particularly where tier 1 questions scored low, are where remediation returns the most maturity per dollar.
  4. Use the phased roadmap. Phase one addresses domains at Level 2 and below; phase two lifts domains between Level 2 and Level 4.
  5. Export the PDF for a board pack, and re-run the assessment after remediation to evidence movement.

Frequently Asked Questions

What do the five maturity levels mean?

Level 1 Initial is ad-hoc and reactive. Level 2 Developing has some documented policies. Level 3 Defined has standardised, consistent processes. Level 4 Managed measures and controls the programme. Level 5 Optimizing runs continuous improvement. Most organisations without a dedicated security function land at Level 2 or low Level 3.

How long does the assessment take?

Around 20 to 30 minutes if you know your environment. Progress saves automatically, so you can stop and resume, and conditional logic skips questions your earlier answers make irrelevant.

Should I answer “unknown” or guess?

Answer unknown. The question is excluded from scoring entirely rather than counted as zero, so an honest unknown will not unfairly depress your result — and the list of unknowns is itself a finding worth acting on.

Is this aligned to NIST CSF or CIS Controls?

It is a hybrid model. The domain structure follows familiar cybersecurity framework functions and the tier weighting is aligned to CIS Implementation Group 1 for foundational controls. It is not a certified assessment against any single framework. For explicit NIST CSF control mapping, use the NIST CSF mapper.

How accurate is the percentile?

It is a normal approximation against an internal benchmark set, not a survey of your peers. Use it to compare your own domains against each other rather than as a competitive position claim.

Why is my overall level lower than most domain levels?

Because the overall score averages the underlying 0–4 domain scores before mapping to a level, not the levels themselves. One very weak domain pulls the mean down and can drop the overall level even when most domains sit comfortably higher — which is the intended behaviour, since attackers target the weakest domain.

Are the investment ranges quotes?

No. They are planning bands based on typical effort to move between levels. Build a real figure with the cybersecurity budget calculator, which accounts for your industry, size, compliance obligations, and risk factors.

Is my data uploaded?

No. Answers and results stay in your browser’s local storage and the PDF is generated client-side.

What Is Cybersecurity Maturity Assessment

A cybersecurity maturity assessment evaluates an organization's security capabilities across multiple domains — from basic hygiene to advanced threat detection — using a structured maturity model. Rather than a binary pass/fail, maturity models rate capabilities on a scale (typically 1-5) that reflects the organization's progression from ad hoc practices to optimized, continuously improving security operations.

Maturity assessments provide a roadmap for security improvement by identifying where you are today, where you need to be, and which capabilities to prioritize. They are used for strategic planning, board reporting, compliance preparation, and benchmarking against industry peers.

Common Maturity Models

ModelLevelsPrimary UseFramework Basis
CMMC3 levels (1-3)DoD contractor requirementsNIST 800-171
NIST CSF Tiers4 tiers (Partial to Adaptive)General cybersecurity maturityNIST CSF
C2M24 levels (0-3)Critical infrastructureDoE Cybersecurity Capability Model
CIS Controls3 Implementation Groups (IG1-IG3)Prioritized security controlsCIS benchmarks
ISO 27001Certified/Not certifiedInformation security managementISO/IEC 27001
CustomTypically 5 levelsOrganization-specificVaries

Typical 5-Level Maturity Scale

LevelNameDescription
1InitialAd hoc, reactive, no formal processes
2DevelopingSome documented processes, inconsistently applied
3DefinedFormal policies and processes, consistently applied
4ManagedMeasured, monitored, and quantitatively managed
5OptimizingContinuous improvement, adaptive, industry-leading

Common Use Cases

  • Security program planning: Identify capability gaps and prioritize investments to systematically improve security maturity
  • Board reporting: Present security posture as a maturity score that executives can track over time and compare against targets
  • Compliance readiness: Assess readiness for frameworks like CMMC, SOC 2, or ISO 27001 before beginning formal certification
  • M&A due diligence: Evaluate the security maturity of acquisition targets to estimate integration costs and risk exposure
  • Industry benchmarking: Compare your maturity against industry averages to identify areas where you lag behind peers

Best Practices

  1. Assess honestly — Inflated maturity scores prevent improvement. Assess against actual practices, not aspirational policies. Evidence-based scoring (not self-reported) produces more accurate results.
  2. Prioritize based on risk — Not every domain needs to be at level 5. A financial institution needs mature data protection but may not need advanced IoT security. Align target maturity to business risk.
  3. Set incremental targets — Moving from level 1 to level 5 is unrealistic in one year. Set annual targets to advance 1 level per domain, focusing on the highest-risk gaps first.
  4. Reassess annually — Security maturity changes as threats evolve, staff turnover occurs, and technology changes. Annual reassessment tracks progress and identifies regression.
  5. Use assessment results to drive action — A maturity score without a remediation plan is just a report card. Convert findings into funded, prioritized, time-bound improvement projects.

Frequently Asked Questions

What is cybersecurity maturity assessment?+

Cybersecurity maturity assessment evaluates how well-developed your security capabilities are across people, process, and technology dimensions. It uses frameworks like CMMC (5 levels), NIST CSF (Tiers 1-4), or custom models to measure progression from ad-hoc reactive security to optimized, continuously improving programs. Assessment identifies current state, target state, and roadmap for improvement.

What are the CMMC maturity levels?+

CMMC has 5 levels: Level 1 (Basic Cyber Hygiene)—foundational practices; Level 2 (Intermediate Cyber Hygiene)—documented processes; Level 3 (Good Cyber Hygiene)—managed and measured; Level 4 (Proactive)—reviewed and controlled; Level 5 (Advanced/Progressive)—optimized. Each level builds on previous, with specific practice and process requirements. Defense contractors must achieve required levels.

How does NIST CSF maturity work?+

NIST CSF defines 4 Implementation Tiers: Tier 1 (Partial)—ad-hoc, reactive; Tier 2 (Risk Informed)—management awareness, repeatable; Tier 3 (Repeatable)—formalized policies, consistent; Tier 4 (Adaptive)—continuous improvement, threat-informed. Tiers reflect sophistication of risk management, integration with business, and security culture. Organizations progress through tiers as capabilities mature.

What domains are assessed in maturity models?+

Common domains include: Governance and Risk Management, Asset Management, Access Control, Threat Detection and Response, Vulnerability Management, Data Protection, Network Security, Security Awareness Training, Incident Response, Business Continuity, Third-Party Risk, Compliance and Audit, Security Architecture, and Security Operations. Each domain evaluates people, processes, and technology capabilities.

How do I improve cybersecurity maturity?+

Start with baseline assessment to identify current level. Prioritize improvements based on risk and compliance requirements. Develop roadmap with specific milestones and metrics. Focus on foundational controls first (asset inventory, access management, patching). Document processes and policies. Implement consistent practices across organization. Measure and track progress. Engage leadership for resources and accountability. Expect 2-3 years for significant advancement.

What are signs of low cybersecurity maturity?+

Indicators include: no documented security policies, reactive rather than proactive security, inconsistent security practices across teams, lack of asset inventory, manual security processes, no security metrics or reporting, limited security awareness, ad-hoc incident response, undefined roles and responsibilities, minimal third-party risk management, and compliance-driven only security. These suggest Maturity Level 1 requiring fundamental improvements.

How does maturity relate to compliance?+

Higher maturity significantly eases compliance. Level 1-2 organizations struggle with compliance, requiring extensive effort for each audit. Level 3-4 organizations have integrated compliance into operations with continuous controls monitoring. Mature programs maintain compliance as byproduct of strong security practices. Many frameworks (HIPAA, PCI-DSS, SOC 2) effectively require minimum Level 2-3 maturity.

What is the business value of security maturity?+

Mature security programs deliver measurable ROI: reduced breach likelihood (60-80% lower for Level 4 vs Level 1), faster incident detection and response (80% reduction in containment time), lower compliance costs, reduced cyber insurance premiums (20-40% savings), improved customer trust, competitive advantage in regulated markets, and operational efficiency. Maturity investment pays dividends in risk reduction and business enablement.

How often should I review and update risk assessments?+

Risk assessments should be reviewed at least annually, or whenever significant changes occur to your systems, processes, or threat landscape. Regular reviews ensure your security controls remain effective against evolving threats.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.