IronSights

Compliance & governance

Maturity model

A framework for assessing the sophistication and completeness of an organisation's security controls across defined levels, typically from 0 (not implemented) to 3 or 5 (fully optimised).

Also known asmaturity levelmaturity assessmentcapability maturity

In plain English

A maturity model gives organisations a consistent way to measure how well their security controls are implemented — not just whether a control exists, but whether it's implemented consistently, monitored, tested, and embedded in business processes. The Essential Eight uses a four-level maturity model (0–3) that lets organisations set realistic improvement targets.

Keep learning

More terms in the IronSights Glossary.