Score your security programme Level 1-5 across nine domains. Tier-weighted questions, peer benchmarking, risk quantification and a PDF roadmap. Free tool.
This cybersecurity maturity assessment scores your security programme from Level 1 (Initial) to Level 5 (Optimizing) across nine domains, benchmarks each domain against a peer average, and returns a roadmap to the next level with an investment range and timeline. It also quantifies current risk as a breach likelihood and an annual expected loss, so the output lands in a budget conversation rather than a slide deck.
It is built for IT directors, vCISOs, MSPs producing a client baseline, and leadership teams who need an evidence-backed answer to “where are we, actually?” The question bank holds around fifty questions, with conditional logic that skips branches your earlier answers make irrelevant. Progress saves automatically, results export to PDF, and nothing leaves your browser.
The assessment covers governance, asset management, identity and access, data protection, network security, vulnerability management, incident response, security training, and vendor risk. Each is scored independently, because a programme with excellent identity controls and no vendor risk management is a different problem from one that is uniformly mediocre — and a single overall number hides that distinction entirely.
Every question offers five answers scored 0 to 4. Questions are not equal: each carries an intrinsic weight, and that weight is multiplied by a tier factor reflecting how foundational the control is.
Effective weight = question weight × tier multiplier, where tier 1 = 1.5, tier 2 = 1.0, tier 3 = 0.5.
Tier 1 covers the critical foundational controls aligned to CIS Implementation Group 1 — multi-factor authentication, backups, asset inventory, patching. Tier 3 covers advanced practices that only matter once the basics are in place. The bank is deliberately weighted toward the foundations: roughly half the questions are tier 1.
Domain score = Σ (answer score × effective weight) ÷ Σ (effective weight)
This produces a domain score on a 0–4 scale, mapped to a maturity level: below 0.5 is Level 1, below 1.5 is Level 2, below 2.5 is Level 3, below 3.5 is Level 4, and above that is Level 5. The overall score is the unweighted mean of the nine domain scores, mapped by the same thresholds.
One design decision matters more than it looks: answering “unknown” removes a question from both the numerator and the denominator. It does not score zero. If you do not know whether privileged access is reviewed quarterly, that is a governance finding, but the tool will not manufacture a false score from it. The practical consequence is that answering “unknown” to everything in a domain produces no score for that domain at all — so answer what you know and treat the gaps as their own action item.
Suppose the identity and access domain has six questions. Three are tier 1 with weight 0.25 (effective weight 0.375 each), two are tier 2 with weight 0.20 (effective 0.20 each), one is tier 3 with weight 0.10 (effective 0.05).
Note what the tier weighting did. Scoring zero on the advanced tier 3 question cost only 0.05 of weight — almost nothing. Dropping one tier 1 question from 3 to 2 cost 0.375. The model is telling you, correctly, that fixing a foundational gap moves your maturity far more than adding a sophisticated capability on top of a weak base.
Each domain score is compared against a peer average and converted to a percentile using a normal approximation:
Percentile = 50 + ((your score − peer average) ÷ 0.8) × 34, clamped to 0–100.
The 0.8 is an assumed standard deviation across the peer population and 34 converts a standard deviation into percentile points. Be clear-eyed about what this is: a reasonable statistical approximation over a small internal benchmark set, not a survey of your actual competitors. Use the percentile to rank your own domains against each other — which is genuinely informative — rather than as a market position claim.
Maturity level is converted into a breach likelihood: 85% at Level 1, 55% at Level 2, 25% at Level 3, 10% at Level 4, 5% at Level 5. That likelihood is multiplied by a breach cost band scaled to your headcount to give an annual expected loss.
Annual expected loss = average breach cost for your size × breach likelihood
These likelihood figures are the model’s own risk-tiering, not published incidence rates, and should be read as relative rather than absolute — the useful signal is that moving from Level 2 to Level 3 more than halves modelled likelihood. For grounding on the cost side: IBM’s Cost of a Data Breach Report 2026, covering 602 breached organisations between March 2025 and February 2026, reported a global average breach cost of $4.99M and a US average of $11.5M, with healthcare highest at $6.64M. Verizon’s 2025 Data Breach Investigations Report, drawn from over 22,000 incidents and 12,195 confirmed breaches, found ransomware present in 88% of breaches at small and medium businesses.
The roadmap targets the next level up and attaches an investment range: roughly $25,000–$40,000 to move from Level 1 to 2, $50,000–$80,000 from Level 2 to 3, $45,000–$60,000 from 3 to 4, and $60,000–$100,000 from 4 to 5. Timelines run 3–6 months from Level 1, 6–12 months from Level 2, and 12–18 months above that. These are planning bands, not quotes.
Level 1 Initial is ad-hoc and reactive. Level 2 Developing has some documented policies. Level 3 Defined has standardised, consistent processes. Level 4 Managed measures and controls the programme. Level 5 Optimizing runs continuous improvement. Most organisations without a dedicated security function land at Level 2 or low Level 3.
Around 20 to 30 minutes if you know your environment. Progress saves automatically, so you can stop and resume, and conditional logic skips questions your earlier answers make irrelevant.
Answer unknown. The question is excluded from scoring entirely rather than counted as zero, so an honest unknown will not unfairly depress your result — and the list of unknowns is itself a finding worth acting on.
It is a hybrid model. The domain structure follows familiar cybersecurity framework functions and the tier weighting is aligned to CIS Implementation Group 1 for foundational controls. It is not a certified assessment against any single framework. For explicit NIST CSF control mapping, use the NIST CSF mapper.
It is a normal approximation against an internal benchmark set, not a survey of your peers. Use it to compare your own domains against each other rather than as a competitive position claim.
Because the overall score averages the underlying 0–4 domain scores before mapping to a level, not the levels themselves. One very weak domain pulls the mean down and can drop the overall level even when most domains sit comfortably higher — which is the intended behaviour, since attackers target the weakest domain.
No. They are planning bands based on typical effort to move between levels. Build a real figure with the cybersecurity budget calculator, which accounts for your industry, size, compliance obligations, and risk factors.
No. Answers and results stay in your browser’s local storage and the PDF is generated client-side.
A cybersecurity maturity assessment evaluates an organization's security capabilities across multiple domains — from basic hygiene to advanced threat detection — using a structured maturity model. Rather than a binary pass/fail, maturity models rate capabilities on a scale (typically 1-5) that reflects the organization's progression from ad hoc practices to optimized, continuously improving security operations.
Maturity assessments provide a roadmap for security improvement by identifying where you are today, where you need to be, and which capabilities to prioritize. They are used for strategic planning, board reporting, compliance preparation, and benchmarking against industry peers.
| Model | Levels | Primary Use | Framework Basis |
|---|---|---|---|
| CMMC | 3 levels (1-3) | DoD contractor requirements | NIST 800-171 |
| NIST CSF Tiers | 4 tiers (Partial to Adaptive) | General cybersecurity maturity | NIST CSF |
| C2M2 | 4 levels (0-3) | Critical infrastructure | DoE Cybersecurity Capability Model |
| CIS Controls | 3 Implementation Groups (IG1-IG3) | Prioritized security controls | CIS benchmarks |
| ISO 27001 | Certified/Not certified | Information security management | ISO/IEC 27001 |
| Custom | Typically 5 levels | Organization-specific | Varies |
| Level | Name | Description |
|---|---|---|
| 1 | Initial | Ad hoc, reactive, no formal processes |
| 2 | Developing | Some documented processes, inconsistently applied |
| 3 | Defined | Formal policies and processes, consistently applied |
| 4 | Managed | Measured, monitored, and quantitatively managed |
| 5 | Optimizing | Continuous improvement, adaptive, industry-leading |
Cybersecurity maturity assessment evaluates how well-developed your security capabilities are across people, process, and technology dimensions. It uses frameworks like CMMC (5 levels), NIST CSF (Tiers 1-4), or custom models to measure progression from ad-hoc reactive security to optimized, continuously improving programs. Assessment identifies current state, target state, and roadmap for improvement.
CMMC has 5 levels: Level 1 (Basic Cyber Hygiene)—foundational practices; Level 2 (Intermediate Cyber Hygiene)—documented processes; Level 3 (Good Cyber Hygiene)—managed and measured; Level 4 (Proactive)—reviewed and controlled; Level 5 (Advanced/Progressive)—optimized. Each level builds on previous, with specific practice and process requirements. Defense contractors must achieve required levels.
NIST CSF defines 4 Implementation Tiers: Tier 1 (Partial)—ad-hoc, reactive; Tier 2 (Risk Informed)—management awareness, repeatable; Tier 3 (Repeatable)—formalized policies, consistent; Tier 4 (Adaptive)—continuous improvement, threat-informed. Tiers reflect sophistication of risk management, integration with business, and security culture. Organizations progress through tiers as capabilities mature.
Common domains include: Governance and Risk Management, Asset Management, Access Control, Threat Detection and Response, Vulnerability Management, Data Protection, Network Security, Security Awareness Training, Incident Response, Business Continuity, Third-Party Risk, Compliance and Audit, Security Architecture, and Security Operations. Each domain evaluates people, processes, and technology capabilities.
Start with baseline assessment to identify current level. Prioritize improvements based on risk and compliance requirements. Develop roadmap with specific milestones and metrics. Focus on foundational controls first (asset inventory, access management, patching). Document processes and policies. Implement consistent practices across organization. Measure and track progress. Engage leadership for resources and accountability. Expect 2-3 years for significant advancement.
Indicators include: no documented security policies, reactive rather than proactive security, inconsistent security practices across teams, lack of asset inventory, manual security processes, no security metrics or reporting, limited security awareness, ad-hoc incident response, undefined roles and responsibilities, minimal third-party risk management, and compliance-driven only security. These suggest Maturity Level 1 requiring fundamental improvements.
Higher maturity significantly eases compliance. Level 1-2 organizations struggle with compliance, requiring extensive effort for each audit. Level 3-4 organizations have integrated compliance into operations with continuous controls monitoring. Mature programs maintain compliance as byproduct of strong security practices. Many frameworks (HIPAA, PCI-DSS, SOC 2) effectively require minimum Level 2-3 maturity.
Mature security programs deliver measurable ROI: reduced breach likelihood (60-80% lower for Level 4 vs Level 1), faster incident detection and response (80% reduction in containment time), lower compliance costs, reduced cyber insurance premiums (20-40% savings), improved customer trust, competitive advantage in regulated markets, and operational efficiency. Maturity investment pays dividends in risk reduction and business enablement.
Risk assessments should be reviewed at least annually, or whenever significant changes occur to your systems, processes, or threat landscape. Regular reviews ensure your security controls remain effective against evolving threats.