Regulatory
Why self-assessed cyber maturity scores are almost always too high
The pattern is consistent across maturity-scored frameworks: controls rated mature on the basis of a policy and a deployed tool, with no evidence of consistent operation, measurement or review.
Published · 6 min read · Regulatory
In short
- Over-scoring is usually not dishonesty — control owners assess against intent, not against what an assessor could evidence.
- The near-universal pattern: claiming the measured and reviewed levels on the strength of a policy plus a deployed tool.
- An inflated score that is later found is a governance failure, and a more serious finding than the original control weakness.
- Two fixes close most of the gap: require an artefact for every score, and have someone outside the owning function review them.
The structural problem
Maturity models score a control on a scale rather than as pass or fail. That is a genuine improvement over binary compliance — partial implementation is real and worth recognising. But it introduces a judgement call, and judgement made by the person who owns the control tends in one direction.
This is not usually dishonesty. It is that control owners assess against their intent and their knowledge of the environment, rather than against what an assessor could evidence. They know the process works. They have not asked whether they could prove it.
The specific inflation pattern
Higher maturity levels in most frameworks require, in ascending order: the control is defined; it is implemented consistently across the scope; it is measured; and it is reviewed and improved. The near-universal over-score is rating a control at the higher levels on the strength of the first two.
A worked example. Privileged access management: a policy exists requiring approval and periodic review, and a PAM tool is deployed. Self-assessed as mature. On assessment: the tool covers sixty percent of privileged accounts, there is no metric tracking coverage, and no review of the process has ever occurred. That is defined and partially implemented — not measured, not reviewed.
Where the inflation happens
What assessors actually look for
- Defined — a document exists, it is current, and it has been approved by someone with authority.
- Implemented — the control operates across the full scope, not a subset, and there is evidence from more than one point in time.
- Measured — there is a metric, someone receives it, and there is a threshold that triggers action.
- Reviewed and improved — the process has been assessed, findings were raised, and something changed as a result.
Why it matters commercially
An inflated self-assessment submitted to a supervisor creates a worse position than an honest low score with a credible roadmap. The low score is a known gap being managed. The inflated score, once found, is a governance failure — because it means management reporting cannot be relied upon, which is a considerably more serious finding than the original control weakness.
This is the most common reason organisations engage us for an independent maturity assessment: a self-assessed score did not survive scrutiny, and the question shifted from the control to the reporting.
How to self-assess more accurately
Two changes help substantially. First, require evidence for every score at the point of scoring — if there is no artefact, the level is not met, regardless of what everyone knows to be true. Second, have someone outside the owning function review the scores. Neither requires an external firm, and both close most of the gap.
An honest low score with a credible roadmap is a considerably better position than an inflated one that does not survive scrutiny.
Related pages
Want your maturity scores independently recalibrated?
We evidence every score and show precisely which criterion is unmet for each one we revise.
Request a proposal