How to run a cybersecurity maturity assessment for a client

Updated

A cybersecurity maturity assessment scores how developed each security practice is, not only whether it exists. For a consultant, it is the part of the engagement that turns a list of gaps into a roadmap: which practices are only written down, which work but depend on one person, and which are measured and improving. The score is only as credible as the evidence behind it, so the work is mostly in collecting the right proof and scoring it consistently.

Choose the scale before the first interview

Agree on the scale with the client before collecting evidence, and write its definitions into the report. Changing the scale between cycles makes year-over-year comparison meaningless.

Scale Unit scored Good fit
A 0 to 5 control maturity scale Each control or requirement Most consulting engagements; works with ISO 27001, NIST CSF, CIS Controls, SOC 2 and CPCSC
C2M2 maturity indicator levels (MIL0 to MIL3) Practices within C2M2 domains Energy and operational technology clients already using C2M2
NIST CSF 2.0 Tiers (1 to 4) The organization’s risk governance and management as a whole Executive summaries; not designed as a per-control score
CIS Implementation Groups (IG1 to IG3) Which Safeguards apply to the organization Scoping a CIS assessment; pair with a maturity scale for scoring

A 0 to 5 scale that holds up

Each level should require specific evidence, and each level should include the one below it. This is the scale Control+s applies to every control:

Level Name Evidence required
0 Not implemented Evidence shows no adopted intent or implementation
1 Intent An adopted policy, plan or stated expectation, without demonstrated implementation
2 Partial Implementation is visible but narrow, one-off or not clearly repeatable
3 Defined and repeatable A documented expectation plus evidence that the practice is followed across the scope
4 Managed Level 3 plus monitoring, review, metrics or exception handling
5 Optimized Level 4 plus improvement over time or a closed review cycle

A worked example for quarterly access reviews: a policy requiring them is a 1. One completed review in a spreadsheet is a 2. Policy plus signed reviews for each quarter in scope is a 3. Add tracked removals and an exception log, and it becomes a 4. Changes to the review process that follow from findings make it a 5.

Scoring mistakes that weaken a maturity report

  • Scoring documents as practice. A well-written policy is level 1 until something shows it operating.
  • Treating missing evidence as a zero. No evidence means the control is not yet assessed. Zero means the evidence shows it is absent. Report the two separately so the client knows whether to collect or to fix.
  • Rounding up. When the evidence sits between two levels, choose the lower one and name what would move it up.
  • Averaging away the story. A domain average of 2.8 hides the one control at 0 that matters most. Show the distribution and call out the outliers.
  • Ignoring scope and period. Evidence from one business unit or last year supports a score for that unit or year only.

How Control+s runs a maturity assessment

  • The client uploads evidence once, and each file is mapped to the relevant controls across every framework in scope.
  • Each control receives a draft 0 to 5 score with a rationale that cites the evidence, the gaps that hold it at that level and recommendations to reach the next.
  • You review every score, add observations and override where your judgment differs. Overrides stay in place when new evidence arrives.
  • ISO 27001 assessments show maturity and conformity side by side, so the certification view and the improvement view do not get mixed up.
  • The report includes the maturity distribution, a gap register and remediation guidance, and the next cycle can be compared against it.

Frequently asked questions

What is the difference between a maturity assessment and a gap assessment?

A gap assessment asks whether each requirement is met and lists what is missing. A maturity assessment asks how far each practice has developed, from intent on paper to a managed and improving process. Most client engagements combine both, a conformity view for the framework and a maturity view for the improvement roadmap.

Are NIST CSF tiers a maturity scale?

Not exactly. NIST describes CSF 2.0 Tiers as characterizing the rigor of an organization's cybersecurity risk governance and management practices, applied to the organization as a whole. Consultants who need a per-control score usually pair the CSF Functions and Categories with a separate 0 to 5 maturity scale and say so in the report.

Can a policy alone earn a high maturity score?

No. A policy shows intent. A defined, repeatable practice also needs evidence that it is followed, such as tickets, exports or review records for the period in scope. Scoring documentation as practice is the most common way maturity reports overstate a client's position.

How often should a maturity assessment be repeated?

Annually is common, with a lighter check after major remediation. Keep the same scale, scope and framework version between cycles so that a score change reflects the client's practice rather than a change in method.

Sources

  1. NIST: CSF 2.0 (CSWP 29)
  2. U.S. Department of Energy: Cybersecurity Capability Maturity Model (C2M2)
  3. CIS: Critical Security Controls v8.1
  4. ISO: ISO/IEC 27001:2022

Bring your next assessment to Control+s.

Start free with two frameworks and five evidence files. Use your own material to inspect the mapping, reasoning, and results, and see how Control+s fits your engagements.

Help shape the product around real consulting work. We welcome teams who want to build their assessment workflow with us.

Running a larger program? .