Grundlagen
8 Min. Lesezeit

Reproducible ISO 27001 Maturity Assessments Across 14 Domains

support@ismscalculator.com|

Assessor reviewing ISO 27001 maturity domains

ISO 27001 maturity levels measure how consistently, and how well, an organization has embedded its security controls, not just whether documentation exists. Most frameworks use a five-point scale from ad hoc to optimized, or the cumulative MIL0 through MIL3 structure from C2M2. The practical move is to assess maturity per domain, set targets based on actual risk rather than a blanket “high everywhere,” and run the assessment through structured questionnaires with evidence requirements, not open-ended interviews.


TL;DR:

  • Using a domain-based, fixed-response questionnaire ensures consistent scoring and reliable assessment of maturity levels across different evaluators and time periods.
  • Target maturity levels should align with the actual risk profile of each domain, rather than aiming for universally high levels that may waste resources on low-risk areas.
  • Evidence requirements, such as logs and documented reviews, are crucial for validating maturity scores above the most basic level and reducing subjective judgment.
  • A maturity score is only meaningful if different assessors arrive at similar results, which is achieved through calibration, clear thresholds, and voting on disagreements.
  • The most common assessment mistakes include ignoring evidence, cherry-picking practices, and conflating control existence with implementation quality.

Table of Contents

What are the common ISO 27001 maturity scales?

Two scales dominate practitioner conversations, and they solve slightly different problems.

The first is a five-level spectrum familiar from CMMI-style models and echoed in federal guidance: ad hoc, defined, consistently implemented, managed and measurable, and optimized. The FY 2024 IG FISMA Metrics Evaluation Guide uses exactly this structure and treats level 4, “managed and measurable,” as the point where security typically becomes effective rather than merely documented.

What are the common ISO 27001 maturity scales? — overview diagram

The second is the Cybersecurity Capability Maturity Model, or C2M2, which uses Maturity Indicator Levels from MIL0 to MIL3. Each MIL applies per domain, and the levels are cumulative: you cannot claim MIL2 in a domain without first satisfying every MIL1 practice in that same domain, according to the C2M2 Version 2.1 documentation published by the Department of Energy. That cumulative rule matters because it stops organizations from cherry-picking advanced practices while skipping the fundamentals underneath them.

Which one should you use? The five-level model is easier to explain to executives and works well for high-level program reporting. C2M2’s MIL structure gives sharper resolution when domains vary wildly in capability, which is common in organizations that grew through acquisition.

Scale Levels Best for
Five-level (FISMA-style) Ad hoc, Defined, Consistently Implemented, Managed & Measurable, Optimized Executive reporting, cross-framework comparison
C2M2 MIL MIL0, MIL1, MIL2, MIL3 (cumulative per domain) Domain-by-domain granularity, uneven capability
COBIT/CMMI-style Level 0 through Level 5 Building custom scoring rubrics

How does maturity map to ISO 27001 Annex A controls?

Compliance and maturity are not the same measurement, and conflating them is the most common mistake in first-year ISMS programs. Compliance asks whether a control exists and satisfies the ISO/IEC 27001 requirement. Maturity asks whether that control is consistently executed, monitored, and improved over time.

This creates two separate metrics worth tracking side by side: program breadth, meaning how many Annex A controls and domains you’ve actually covered, and implementation depth, meaning how well each covered control performs in practice. A program can look complete on paper while several controls sit at MIL1 depth.

Take access review as an example. A control might exist as a written policy (compliant on paper) while quarterly reviews happen inconsistently and nobody logs exceptions (low maturity in execution). Evidence at a higher maturity level would include review logs, ticket trails showing remediation timing, and a documented escalation path.

Grouping controls by domain, rather than scoring each of the roughly 93 Annex A controls in isolation, keeps scoring consistent and manageable:

  • Group access control, authentication, and identity management controls together for one domain score.
  • Group incident response, logging, and monitoring controls into a single operations domain.
  • Group vendor risk, contracts, and third-party audits into a supplier domain, since evidence types overlap heavily.

Reviewing Annex A controls in detail before you build domain groupings prevents inconsistent scoring later.

How do you run a reproducible ISO 27001 maturity assessment?

A maturity score only means something if a different assessor, six months later, would land on roughly the same number. Here’s the method that gets you there.

  1. Define scope and domains. Group your Annex A controls into 10 to 14 working domains, mirroring the structure used in tools like ISMS Calculator’s domain-by-domain assessment, so scoring stays consistent across teams and audit cycles.
  2. Build fixed-choice questionnaire items. Avoid open text. Use response options like “Not performed,” “Partially implemented,” “Largely implemented,” and “Fully implemented, measured,” so two assessors answering the same question land close together.
  3. Set scoring rules with cumulative thresholds. Decide upfront that a domain cannot score MIL2 or Level 3 until every lower-level practice in that domain is satisfied. Write the threshold rule down before scoring starts, not after.
  4. Require evidence for every response above the lowest tier. A claim of “fully implemented” needs a log export, a signed policy with a review date, or a ticketing report attached. Log assessor notes alongside each score so reviewers can trace the reasoning later.
  5. Use peer review on disagreement. When two assessors score the same control more than one level apart, bring in a third reviewer and record the final consensus score along with why the disagreement happened.

Pro Tip: Before running the full assessment, calibrate your assessors on 2 to 3 sample controls together. Compare scores, discuss the gaps out loud, and adjust the questionnaire wording where people interpreted it differently. Skipping calibration is the single fastest way to end up with a maturity report nobody trusts.

How do you interpret maturity results and set realistic targets?

A maturity report is only useful once someone decides what to do with the numbers, and the instinct to chase Level 5 everywhere is usually wrong. The FY 2024 IG FISMA Metrics Evaluation Guide notes that “managed and measurable,” level 4 on its five-point scale, typically already represents effective security for federal agencies. Pushing every domain to “optimized” burns budget on controls that carry low risk to begin with.

Target maturity should track the actual risk a domain carries, not a uniform aspiration:

  • Low-risk domains (say, internal wiki access controls): Level 2 to 3 target, reviewed annually.
  • Medium-risk domains (vendor management, HR offboarding): Level 3 to 4 target, reviewed semi-annually.
  • High-risk domains (privileged access, incident response, customer data handling): Level 4 to 5 target, reviewed quarterly.

Aligning targets to business objectives and actual exposure, rather than a flat maturity goal, is the approach the CRF’s maturity model research recommends, and it tends to hold up better under audit scrutiny than a one-size-fits-all target. Building this rubric into your implementation timeline also gives you a natural review cadence to track against.

How do you keep maturity scores from becoming a guessing game?

Subjectivity is the quiet failure mode of every maturity program. Ask five people to eyeball a control’s maturity without a rubric, and you’ll get five different scores. Empirical research on practitioner assessments found consistent variance in self-scoring, and identified structured questionnaires and assessor calibration as the fix that actually moves the needle, according to a study on practitioner assessment capabilities published on assessing information security controls.

Four practices reduce that variance in real assessments:

  • Write questionnaire statements as precise, testable claims rather than vague prompts like “is access managed well?”
  • Require documented evidence for any score above the lowest tier, not just for the top tier.
  • Route disputed or borderline scores through a second assessor before finalizing.
  • Version-control the questionnaire itself so scores from different quarters are actually comparable.

Structured tools add value on top of a good questionnaire: industry benchmarks that show where similar-sized organizations land, consistent domain coverage across assessment cycles, and exportable reports that survive an auditor’s scrutiny. This is the gap ISMS Calculator’s maturity assessment was built to close: it scores 14 ISO domains against fixed criteria, compares your results to sector benchmarks, and exports the findings as a shareable report instead of a spreadsheet only you understand.

What actually goes wrong when teams use maturity models

Most maturity programs fail quietly, not loudly. Teams inflate scores because nobody asked for evidence, or they chase Level 5 in domains where the actual risk barely justifies Level 3. My honest read: measure what carries real risk, demand evidence before accepting any score above “partially implemented,” and always report program breadth and control depth as separate numbers. If you take one action after reading this, run a domain-by-domain readiness check before your next audit cycle, not after.

— Martin

Get a benchmarked maturity score in minutes

Guessing where your ISMS stands against similar organizations wastes time you don’t have before an audit. ISMS Calculator’s free 2-minute readiness check gives you an instant score mapped to a maturity level, based on your answers to a short set of fixed-choice questions, no account required to see where you land.

Ismscalculator

For teams that need domain-by-domain depth, the full ISO 27001 readiness assessment scores all 14 ISO domains against sector benchmarks, builds a Gantt-style implementation timeline from your gaps, and exports the whole thing as a shareable PDF your auditor can actually use. Run the mini check first, then decide if the full assessment is worth the deeper dive.

Sources

Bereit, Ihre ISO 27001-Kosten zu schätzen?

Nutzen Sie unseren kostenlosen Rechner für eine maßgeschneiderte Kosten-, Aufwands- und Zeitplanschätzung basierend auf Ihrem Unternehmensprofil.

Zurück zu allen Artikeln