Skip to main content
Category: Metrics & Reporting

Capability Maturity Model

Also known as: CMM, Maturity Model, Capability Maturity Framework
Simply put

A Capability Maturity Model is a structured way to measure how developed and consistent an organization's processes are, usually by placing them along a scale from ad hoc and unpredictable to well-defined and continuously improving. In security leadership, it helps an organization understand where its practices stand today and what steps could raise them to a more reliable, repeatable state. It is a benchmarking and planning tool rather than a guarantee of any particular outcome.

Formal definition

A Capability Maturity Model is a tiered assessment framework that characterizes the maturity of an organization's processes across defined levels, typically progressing from initial or ad hoc, through repeatable and defined, to managed and optimizing states. In a virtual or fractional CISO engagement, it is often applied to evaluate the current-state maturity of a security program's governance, risk management, and process areas, to establish a baseline, and to inform a prioritized roadmap toward target-state maturity. The specific level definitions, domains assessed, and scoring approach vary by the model adopted and by provider, and a maturity rating reflects process consistency and formalization rather than compliance status, certification, or assurance against specific threats. Its value depends on organizational maturity, stakeholder input, defined scope, and honest self-assessment, and results should not be conflated with certification or audited attestation.

Why it matters

A Capability Maturity Model gives security leaders a shared language for describing where a program actually stands, rather than relying on subjective impressions of whether an organization is doing well or poorly. This matters because security is fundamentally a governance and business risk function, not merely a technical one, and boards and executives need a defensible way to understand whether their processes are ad hoc, repeatable, or consistently managed. A maturity assessment translates a sprawling set of practices into a structured baseline that stakeholders across technical and non-technical roles can discuss and act on.

For organizations engaging a virtual or fractional CISO, a maturity model is often one of the first tools applied because it establishes a current-state picture and informs a prioritized roadmap toward a defined target state. Without such a baseline, investment decisions tend to be reactive and difficult to justify, and progress becomes hard to demonstrate over time. Because the model measures process consistency and formalization rather than certification or assurance against specific threats, it helps organizations avoid the common mistake of assuming that acquiring tools equals a mature program.

It is important to be clear about what a maturity rating does not provide. A high maturity score reflects how defined and repeatable processes are; it is not a guarantee against breaches, and it should never be conflated with a certification, an audited attestation, or a compliance status. Its usefulness depends heavily on honest self-assessment, adequate stakeholder input, and a defined scope, so results are only as reliable as the organizational cooperation behind them.

Who it's relevant to

Virtual and Fractional CISOs
Security leaders delivering vCISO or fractional engagements often use a maturity model early to establish a baseline and build a prioritized roadmap. It helps them frame recommendations in terms of process improvement and business risk rather than isolated technical fixes, while making clear that a maturity rating is a planning tool, not a certification or a guarantee of security outcomes.
Boards and Executive Leadership
Directors and officers who retain accountability for security decisions benefit from a maturity model because it converts complex practices into a structured, comparable view they can reason about. It supports investment prioritization and progress tracking over time, though leaders should understand that a score reflects process formalization and does not by itself demonstrate compliance or protect against specific threats.
Organizations Assessing Program Readiness
Companies evaluating how developed their security processes are can use a maturity model to identify gaps and sequence improvements. Its value depends on the organization's willingness to self-assess honestly and provide stakeholder access, and results should not be treated as an audited attestation or as evidence of framework certification.
Buyers of Security Leadership Services
Organizations selecting a vCISO or advisory provider should recognize that maturity model definitions, assessed domains, and scoring methods vary by provider. Understanding this helps buyers set expectations, compare offerings on scope rather than headline scores, and avoid conflating a maturity engagement with managed security operations or with replacing an entire security team.

Inside CMM

Maturity Levels
A tiered scale, often five levels ranging from initial or ad hoc through repeatable, defined, managed, and optimizing, used to characterize how consistently and effectively an organization performs a given process or capability. In security leadership engagements, a virtual CISO may use these levels to describe the current and target state of a security program rather than to assign a definitive score.
Capability or Process Areas
The specific domains being assessed, such as governance, risk management, incident readiness, identity management, or vendor risk. A virtual CISO typically maps these areas to a framework the client already uses, such as NIST CSF or ISO 27001, so the maturity view supports rather than replaces those frameworks.
Current State Assessment
A qualitative evaluation of where the organization stands today across the chosen capability areas. This depends heavily on client cooperation and access to stakeholders and documentation, and a virtual CISO advises on the findings rather than assuming accountability for the underlying decisions.
Target State and Roadmap
A defined future maturity level appropriate to the organization's risk appetite, business objectives, and resources, along with prioritized steps to reach it. The realistic target often depends on organizational maturity and available budget, and outcomes may vary by provider and engagement scope.
Gap Analysis
A comparison between current and target states that identifies where improvement is needed. A virtual CISO typically produces this as governance and strategy guidance; execution of the identified remediation is generally out of scope unless explicitly contracted.

Common questions

Answers to the questions practitioners most commonly ask about CMM.

Does a higher maturity level always mean better security?
Not necessarily. A capability maturity model measures how consistently and repeatably processes are defined, managed, and improved, not whether a given control is optimally suited to your specific risk profile. An organization can reach a higher maturity tier for a process that is well-documented and measured yet still misaligned with its actual threat landscape or business priorities. Maturity indicates process discipline, not a guarantee of reduced risk. A virtual CISO typically uses maturity ratings as one input into risk-based prioritization rather than treating the top tier as a universal goal.
Should every organization aim for the highest maturity level across all capabilities?
Generally no. Pursuing the highest maturity tier everywhere is often inefficient and may not be justified by the organization's risk tolerance, resources, or regulatory obligations. In many engagements, the appropriate target maturity varies by capability, with some areas warranting stronger investment than others. A virtual CISO commonly helps define target maturity levels that reflect business risk and cost-benefit considerations rather than assuming uniform advancement. Accountability for approving those target levels typically remains with the client organization's leadership.
How does a virtual CISO typically use a capability maturity model in an engagement?
In many engagements, a virtual CISO uses a maturity model to establish a baseline assessment of current-state capabilities, define target-state maturity aligned to business risk, and build a prioritized roadmap to close gaps. This is generally a governance and strategy activity rather than a hands-on operational one. The vCISO advises and directs, while responsibility for executing remediation and accountability for decisions usually stay with the client. The value of this approach often depends on organizational maturity, stakeholder access, and the accuracy of the input data provided.
What organizational conditions affect whether a maturity assessment produces useful results?
Results often depend heavily on client cooperation, honest self-reporting, access to relevant stakeholders and evidence, and a clearly defined scope. In lower-maturity organizations, processes may be informal or undocumented, which can make accurate ratings harder to establish. A virtual CISO can facilitate the assessment, but the quality of the outcome typically reflects the quality of information available. Where access or engagement from stakeholders is limited, the assessment may capture perception rather than verified practice, a limitation that should be stated explicitly.
How does a capability maturity model relate to frameworks like NIST CSF or ISO 27001?
A capability maturity model measures process consistency and improvement, while frameworks such as NIST CSF or ISO 27001 describe control objectives and requirements. They are often used together: an organization may assess the maturity of the capabilities it uses to meet a framework's objectives. Using a maturity model to support readiness for a standard is not the same as achieving certification. A virtual CISO can help support readiness and improvement, but assertions of certification generally require independent assessment or audit by an authorized party.
How often should maturity be reassessed, and who owns follow-through?
Reassessment cadence may vary by provider and organization, but maturity is typically reviewed periodically or after significant changes such as growth, new regulatory obligations, or major incidents, so progress against the roadmap can be tracked. A virtual CISO commonly advises on cadence and helps interpret changes over time. However, ownership of follow-through and accountability for acting on findings usually remains with the client organization and its officers, since the vCISO directs and advises rather than assuming organizational accountability unless a contract specifies otherwise.

Common misconceptions

A higher maturity score means the organization is compliant or certified against a standard such as ISO 27001, SOC 2, or HIPAA.
A maturity model describes how consistently processes are performed; it does not by itself assert certification or compliance. A virtual CISO may support readiness using a maturity view, but achieving certification requires separate audit or attestation processes and remains distinct from maturity ratings.
Reaching the highest maturity level should always be the goal, and a virtual CISO guarantees that outcome.
The appropriate target level typically depends on the organization's risk appetite, resources, and business context, and the highest level is not always cost-justified. A virtual CISO advises on a suitable target and roadmap, but outcomes depend on client cooperation, defined scope, and organizational maturity, and are not guaranteed.
A maturity model measures the effectiveness of security tools and technical controls.
A capability maturity model primarily assesses processes, governance, and consistency of practice, which is a business and governance function rather than a purely technical one. Tool administration and hands-on operational tasks are generally outside a virtual CISO's typical scope.

Best practices

Align the maturity model with a framework the organization already uses, such as NIST CSF or ISO 27001, so the assessment reinforces existing governance rather than introducing a competing structure.
Set a target maturity level based on the organization's risk appetite, business objectives, and available resources rather than defaulting to the highest possible level.
Secure stakeholder access and documentation before beginning, since the accuracy of a current state assessment depends heavily on client cooperation and organizational maturity.
Use the maturity view to inform a prioritized roadmap, and clearly define whether remediation execution is in scope, since a virtual CISO typically advises rather than performs hands-on operational work.
Distinguish maturity progress from compliance or certification, and communicate to stakeholders that improved maturity supports readiness but does not by itself assert certification.
Document that the virtual CISO advises and directs while legal and organizational accountability for security decisions remains with the client organization and its officers unless a contract specifies otherwise.