Security Program Maturity Assessment: How to Know Where You Stand and What to Fix Next

Retool's new app builder is where AI-generated code ships safely
Building apps with AI is easy. Getting them to production safely is another story.
A security program without a maturity baseline is flying blind. Budget decisions get made based on what the CISO read last week, what a vendor pitched last quarter, or what the board heard about after a competitor's breach. Controls that are partially implemented get counted as complete. Gaps in fundamental capabilities go unaddressed while resources flow to advanced detection tooling that requires the foundational controls to be effective. The result is a security program that is expensive but not measurably improving the organization's risk position. The maturity assessment process described in this guide is not a compliance exercise and does not require a consultant. It is a structured self-evaluation that produces a baseline, a gap list, and a prioritized roadmap that a security leader can present to executive leadership with dollar amounts attached.
Why Maturity Assessment Matters: The Baseline Problem
Every security investment decision is implicitly a comparison: should we spend this budget on endpoint detection, cloud security tooling, identity controls, or security awareness training? Without a baseline that shows where the current program stands across all of these categories, the comparison has no foundation. The default that fills this vacuum is vendor influence: the tool that has the best sales relationship, the control category that was in the last breach headline, or the framework compliance gap that a recent audit surfaced. These inputs are all real, but they are not prioritized against the actual risk profile of the organization.
A maturity assessment creates a common language for talking about security investment across the security team, IT, engineering, and executive leadership. Instead of debating whether to buy product A or product B, the conversation becomes: our asset inventory capability (CIS Control 1) is at IG1 level, our privileged access management (CIS Control 5) is not implemented, and our data protection program (CIS Control 3) has documentation but no enforcement. Given these gaps, the highest risk-reduction per dollar is in PAM, followed by data classification enforcement. This framing makes security investment decisions legible to non-security stakeholders and gives the security program a measurable improvement trajectory.
The baseline also provides historical accountability that is otherwise absent. A security program that completed a maturity assessment in 2024 and is re-assessing in 2025 can answer the question of whether the program improved, held steady, or regressed. Without this comparison, a security leader cannot demonstrate that a year of budget and team effort produced measurable risk reduction. Boards and executive leadership are increasingly asking for this kind of evidence, and the maturity assessment framework provides the structure to produce it.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
NIST CSF 2.0: The Six Functions and Tiers vs. Profiles
NIST Cybersecurity Framework 2.0, released in 2024, restructured the original five functions (Identify, Protect, Detect, Respond, Recover) by adding a sixth: Govern. The Govern function addresses organizational context, risk management strategy, cybersecurity policy, oversight, and supply chain risk management. Its addition at the top of the framework reflects the recognition that cybersecurity is an enterprise risk management discipline, not only a technical one, and that the governance structures that direct and oversee the security program are as important as the technical controls.
For self-assessment purposes, the six functions provide a comprehensive coverage map. Identify covers asset management, business environment, risk assessment, and supply chain risk. Protect covers identity management and access control, awareness and training, data security, platform security, and technology infrastructure resilience. Detect covers continuous monitoring and adverse event analysis. Respond covers incident management, incident analysis, incident response reporting, communication, and mitigation. Recover covers incident recovery plan execution, restoration and recovery communication, and recovery communication. Govern covers organizational context, risk management strategy, roles and responsibilities, policies, oversight, and supply chain risk management.
The NIST CSF distinguishes between Tiers and Profiles. Tiers (1 through 4: Partial, Risk Informed, Repeatable, Adaptive) describe the rigor and sophistication of an organization's cybersecurity risk management practices overall. They are not a maturity score for specific controls but a characterization of how the organization approaches cybersecurity risk management as a discipline. Profiles describe the outcomes the organization has chosen to prioritize given its business requirements, risk tolerance, and resources. A Current Profile documents what the organization is achieving today. A Target Profile documents what it aims to achieve. The gap between Current and Target Profile is the input to the roadmap. For self-assessment, the most useful approach is to score each Subcategory outcome (the CSF has 106 Subcategories in version 2.0) as currently implemented, partially implemented, or not implemented, weighted by the organization's risk context.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
CIS Controls v8: Implementation Groups as a Maturity Ladder
CIS Controls v8 provides a more operationally concrete alternative to NIST CSF for organizations that want to self-assess against specific technical controls rather than outcome-based categories. The 18 control families cover: Inventory and Control of Enterprise Assets, Inventory and Control of Software Assets, Data Protection, Secure Configuration of Enterprise Assets and Software, Account Management, Access Control Management, Continuous Vulnerability Management, Audit Log Management, Email and Web Browser Protections, Malware Defenses, Data Recovery, Network Infrastructure Management, Network Monitoring and Defense, Security Awareness and Skills Training, Service Provider Management, Application Software Security, Incident Response Management, and Penetration Testing.
The Implementation Group structure is the key feature for maturity assessment purposes. Implementation Group 1 (IG1) contains 56 safeguards that constitute basic cyber hygiene, described as essential for every organization regardless of size or sophistication. IG1 controls include establishing an asset inventory, enforcing MFA, deploying endpoint protection software, maintaining secure configurations, managing accounts and privileges, and implementing basic log collection. IG2 adds 74 more safeguards appropriate for organizations with dedicated security staff and more complex IT environments. IG3 adds 23 additional safeguards for organizations handling sensitive data or operating critical infrastructure. This tiered structure makes the framework self-scaling: a 50-person organization should achieve IG1 completely before worrying about IG2, while a 5,000-person enterprise with a dedicated security team should be assessing against IG2 or IG3 as the baseline.
For self-assessment against CIS Controls, each safeguard should be scored on a simple scale: not implemented (0), partially implemented (the control exists in some form but is not complete, enforced, or consistently applied), implemented (the control is fully deployed and enforced), and implemented with verification (the control is deployed, enforced, and its effectiveness is periodically tested or validated). The difference between the second and fourth levels is the difference between a control that is documented and one that actually works. Many programs score themselves at implemented when the honest score is partially implemented or implemented without verification.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Self-Assessment Methodology: Scoring Honestly
The most common failure mode in security maturity self-assessment is aspirational scoring: marking a control as implemented because the intention is to implement it, because a policy document exists that describes how it should be implemented, or because it was implemented for one team or system and the assessor rounds up to enterprise-wide. Aspirational scoring produces a maturity score that reflects the program as it was designed rather than as it actually functions, which defeats the purpose of the assessment.
Evidence-based scoring requires that each control score be backed by a specific artifact: a screenshot, a configuration export, a tool report, a log sample, or a tested procedure result. For CIS Control 1.1 (Establish and Maintain Detailed Enterprise Asset Inventory), a score of implemented requires producing an actual asset inventory that covers the scope claimed. If the inventory covers managed endpoints but not cloud resources, IoT devices, or third-party SaaS applications, the honest score is partially implemented, not implemented. The evidence requirement disciplines the assessment process against aspirational scoring.
Common overscoring traps appear repeatedly across maturity assessments and are worth flagging explicitly. Documenting a policy is not the same as enforcing it: a vulnerability management policy that requires patching within 30 days does not score as implemented unless actual patch data shows that vulnerabilities are being closed within 30 days in practice. Purchasing a tool is not the same as using it effectively: a SIEM license that is deployed but has no detection rules and no analyst reviewing alerts does not score the logging and monitoring controls as implemented. Completing a control for one environment or business unit is not the same as enterprise-wide implementation: MFA enforced for 60% of users is partial implementation.
The scoring session for a self-assessment works best when it involves at least two participants: the person responsible for the control (who has the most accurate operational knowledge of how it actually works) and a second reviewer who challenges aspirational claims and asks for evidence. For each control, the review asks: what exactly is in scope, what is out of scope, what evidence do we have that it is working, and when was it last tested. The conversation surfaces gaps that neither participant would have identified alone.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Gap Analysis: From Scores to a Prioritized Roadmap
The output of the self-assessment is a scored list of controls, each with an evidence note and a gap description. Gap analysis converts this list into a prioritized roadmap by weighting each gap by two factors: risk reduction potential (how much does implementing this control reduce the organization's likelihood of a significant incident or impact of a breach if it occurs) and implementation cost (how much effort, time, and budget does implementing this control require given the organization's current environment).
Controls with high risk reduction and low implementation cost are the immediate priorities. CIS IG1 controls tend to cluster in this quadrant: asset inventory, MFA for all users, endpoint protection software deployment, and basic log collection are all high-impact controls that most organizations can implement using existing tools and staff. Controls with high risk reduction but high implementation cost (a full PAM deployment, an enterprise-wide data classification and DLP program) belong in the medium-term roadmap and require dedicated budget and project planning. Controls with low risk reduction and low implementation cost are quick wins that build momentum. Controls with low risk reduction and high implementation cost are deferred.
The 12-month roadmap should sequence improvements across the four quadrants. Months one through three: complete all IG1 gaps that can be closed with existing tools and no new budget. Months four through six: address the highest-priority IG1 gaps that require procurement or configuration work, and begin planning for the first high-cost high-impact gap. Months seven through twelve: execute the first major investment from the roadmap while maintaining progress on IG2 controls. This sequencing produces visible progress in the first quarter (morale and momentum), addresses the highest-risk gaps before the end of the year (risk reduction), and creates a realistic budget request for major investments (leadership credibility).
The gap analysis document that results from this process is also the input to the security budget request. Each roadmap item should include: the control being addressed, the current score, the target score, the risk reduction rationale (what attack path does this close or significantly impair), the implementation approach (what tools or processes are required), and a cost estimate. This format gives finance and executive leadership the information they need to evaluate security investment in the same terms as other business investments.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
CMMC for Defense Contractors and Reporting to Leadership
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense framework that defense contractors must comply with to be eligible for contracts involving Controlled Unclassified Information (CUI). CMMC has three levels. Level 1 (Foundational) requires annual self-assessment against 17 practices derived from FAR 52.204-21 basic safeguarding requirements. Level 2 (Advanced) requires assessment against 110 practices from NIST SP 800-171 and applies to organizations that handle CUI; it requires either an annual self-assessment (for non-prioritized acquisitions) or a triennial assessment by a CMMC Third-Party Assessment Organization (C3PAO). Level 3 (Expert) requires government-led assessment against 134 practices including a subset of NIST SP 800-172 requirements.
The connection between CIS Controls and CMMC is direct and practically useful for defense contractors. CIS Implementation Group 2 maps closely to CMMC Level 2 requirements from NIST SP 800-171. A defense contractor that completes a CIS IG2 self-assessment and closes identified gaps is well-positioned for CMMC Level 2 assessment. The CIS Controls to NIST SP 800-171 mapping document (available from CIS) provides a control-by-control crosswalk that identifies which CIS safeguards satisfy which 800-171 requirements. Using this mapping, a CMMC-bound organization can use the CIS self-assessment as the primary tool and generate CMMC compliance evidence as a byproduct.
Reporting maturity assessment results to leadership requires translating control scores into business risk statements. A board member does not need to know that CIS Control 5.4 (Restrict Administrator Privileges to Dedicated Administrator Accounts) is not implemented; they need to know that privileged access management gaps mean that a compromised employee account can provide an attacker with administrative control over the entire enterprise network, representing a full business disruption risk. The one-page maturity dashboard that works for leadership typically shows: an overall maturity score by framework function or control family (represented visually, not as a raw number), three to five highest-risk gaps with a plain-English description of the business risk each gap creates, the 12-month roadmap with budget requirements, and the year-over-year comparison if a prior baseline exists. This format drives investment decisions by connecting control gaps to business outcomes rather than technical details.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
External Validation: When to Bring In a Third Party
Self-assessment is appropriate for establishing a baseline and conducting annual reviews when the organization has experienced security staff who can evaluate evidence objectively. The limitations of self-assessment are well-documented: assessors may have blind spots about their own program, they may not know what they do not know about specific control domains, and there is an inherent conflict of interest when the people responsible for controls are also the ones scoring them. External validation addresses these limitations and provides an independent perspective that carries weight with audit committees, boards, and regulators.
The right trigger for a third-party maturity assessment is one or more of the following: preparing for a compliance audit that requires independent assessment (CMMC Level 2 with a C3PAO, SOC 2 Type II, ISO 27001 certification), responding to a significant security incident that revealed gaps the self-assessment did not capture, entering a material contract where the customer requires independent security assurance, or when the self-assessment results are being questioned by executive leadership or the board. A third-party assessment does not need to cover the entire framework; a gap assessment against specific high-priority control domains (identity and access management, endpoint security, cloud security posture) scoped to two to four weeks of work produces actionable results at a fraction of the cost of a full-framework engagement.
What to expect from a gap assessment engagement: the assessor will request evidence packages for each control in scope (configuration exports, policy documents, tool screenshots, log samples), conduct interviews with control owners, and produce a findings report that scores each control and describes the gap. The interview component is where the most value comes from an external assessor, because experienced assessors ask questions that expose the difference between documented controls and enforced controls that internal teams may not think to ask. The output should include a prioritized remediation roadmap in the same format as the self-assessment roadmap, enabling direct comparison to the internal baseline.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
The bottom line
A security maturity assessment is most valuable when it is honest, evidence-based, and connected to a actionable roadmap. The frameworks (NIST CSF 2.0 for outcome-based assessment, CIS Controls v8 for technical control benchmarking) provide the structure, but the value comes from the discipline of requiring evidence for every implemented score and the gap analysis that converts scores into budget-ready investment cases. For most organizations, completing CIS IG1 fully and honestly is a more significant security improvement than any new tool purchase, because IG1 represents the foundational controls that every other security capability depends on. The maturity dashboard that results from this process is also the security leadership communication tool that turns ambiguous security spending into defensible risk reduction investments.
Frequently asked questions
How long does a security maturity self-assessment take?
A CIS Controls v8 self-assessment covering all 18 control families typically takes two to four weeks of elapsed time for a team of two to three people, including evidence gathering, control scoring sessions, and gap analysis. The elapsed time is longer than the actual work time because evidence gathering requires coordination with IT operations, cloud teams, and application owners. Scoping the initial assessment to IG1 controls only (56 safeguards) reduces the effort to one to two weeks and is the recommended starting point for organizations conducting their first assessment.
What is the difference between NIST CSF Tiers and a maturity score?
NIST CSF Tiers describe the organizational approach to cybersecurity risk management, from Partial (Tier 1, ad hoc and reactive) to Adaptive (Tier 4, proactive and continuously improving). Tiers are a qualitative characterization of how the organization manages cybersecurity as a discipline, not a score for specific technical controls. A maturity score, as used in CIS Controls Implementation Groups or capability maturity models, rates specific controls on a scale from not implemented to optimized. Tiers and maturity scores measure different things and are both useful: Tiers describe organizational culture and process maturity, while control-level scores describe the actual state of security capabilities.
How often should a security maturity assessment be conducted?
A full maturity assessment should be conducted annually, timed to inform the annual budget cycle. This allows the year-over-year comparison to demonstrate program progress and gives the gap analysis output enough lead time to become a funded budget request. In addition to the annual full assessment, quarterly check-ins on specific high-priority control domains (the controls that had the largest gaps in the annual assessment) ensure that remediation work is progressing on schedule. Major events (a significant breach, a new compliance requirement, a material acquisition) should trigger an out-of-cycle assessment for the affected control areas.
Can we use the same assessment to satisfy both NIST CSF and CIS Controls requirements?
Yes, with some additional mapping work. CIS has published crosswalk documents that map each CIS Control safeguard to NIST CSF categories and subcategories. A CIS Controls self-assessment can be translated to NIST CSF scores using these crosswalks, providing dual-framework output from a single evidence collection effort. This is particularly useful for organizations that need to report in NIST CSF terms to one audience (federal customers, regulators) and CIS Controls terms to another (technical staff, peer organizations). The CIS to NIST CSF mapping is available at cisecurity.org and is maintained with each major version update.
How do we present security maturity scores to a board that does not have technical security expertise?
Translate control gaps into business risk consequences. Instead of reporting that CIS Control 11 (Data Recovery) is at 40% implementation, report that the organization cannot reliably recover from a ransomware attack within a business-acceptable timeframe because backup coverage is incomplete and recovery procedures have not been tested. Use a visual dashboard that shows red, yellow, green status by function rather than numeric scores. Attach a dollar estimate to each major gap (business interruption cost for a ransomware incident that hits unprotected systems, cost of a data breach from an unencrypted database). Connect each roadmap investment to the specific business risk it addresses. Boards respond to business impact framing, not technical control taxonomy.
Sources & references
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
Win a $2,495 Black Hat pass.
Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.
