Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

The ISO 27001 maturity assessment explained

ISO 27001 Maturity Assessment: A Clear Guide to 6 Levels

An ISO 27001 maturity assessment answers a question the certification audit never asks: not does this control exist, but how well does it work, and would it survive the person who runs it leaving. ISO 27001 conformity is binary — you meet a requirement or you do not. Maturity is a scale, and the two are measuring different things.

This guide covers what an ISO 27001 maturity assessment scores, the levels most models use, and where the exercise stops being useful.

ISO 27001 maturity assessment: the six levels and what evidence each one needs
Six levels, and the evidence that moves a control from one to the next.

Maturity is not conformity

A certification auditor asks whether the requirement is met and whether you can show it. A control performed inconsistently by one overloaded person, with no measurement and no improvement, can still pass. That is not a flaw in the standard — clause-by-clause conformity is what a certificate attests to.

An ISO 27001 maturity assessment exists because that answer is not enough to run a programme with. Boards ask where the money should go next; a conformity result cannot tell them, because everything in scope is already “conforming”. A maturity score can, because it distinguishes the control that works because it is designed to from the one that works because somebody remembers.

The six levels an ISO 27001 maturity assessment usually scores

Level What it means Evidence you would expect
0 — Non-existent The control is not performed Nothing
1 — Ad hoc It happens when somebody thinks of it Isolated examples, no procedure
2 — Repeatable Consistent in practice, dependent on individuals Records over time, informal method
3 — Defined Documented, owned, trained, performed as written Procedure, owner, training records, output
4 — Measured Performance is measured against a target Metrics with thresholds, trend, exception handling
5 — Optimising The measurement changes the control Changes traceable to measurement or incidents

Level 3 is where most certified organizations sit for most controls, and it is a respectable place to be. The jump that matters is 3 to 4, because that is where you stop asserting the control works and start knowing.

What to score, and what not to

Score the Annex A controls you have declared applicable, plus the clause 4–10 management system activities: risk assessment, internal audit, management review, incident management, supplier management, improvement. Do not score controls you have excluded — the Statement of Applicability already records that decision, and re-litigating it inside a maturity exercise confuses two different conversations.

Running an ISO 27001 maturity assessment that survives challenge

  1. Write level descriptors per control, not in general. “Level 3” means something different for access reviews than for cryptography. Generic descriptors produce scores nobody trusts, because every assessor reads them differently.
  2. Score on evidence, not on interview. Ask for the artifact that a level implies. Level 4 without a metric is level 3 with optimism.
  3. Score current state only. Planned improvements belong in the target column. Mixing them produces a picture of the ISMS you intend to have.
  4. Set a target level per control, and justify it. Not everything needs level 4. A control protecting your crown-jewel system might; the clear desk policy almost certainly does not, and pretending otherwise is how maturity programmes lose credibility.
  5. Keep the same scale between rounds. Movement is the output. A rescored scale makes the second assessment incomparable with the first, which is the only thing anyone actually wanted.

Where an ISO 27001 maturity assessment goes wrong

Documents get scored instead of practice. A polished procedure nobody follows is level 1 with good typography. The test is what happened last quarter, not what the document says should happen.

Averages hide the risk. An overall “3.4” is a number for a slide. A control at level 1 protecting a critical asset is the finding, and it disappears into the mean. Report the distribution and the outliers, never the average alone.

The scale becomes a target in itself. Once teams are measured on their maturity number, scores rise without anything changing. Independent verification of a sample — by internal audit, or by whoever did not do the scoring — is what keeps the exercise honest.

How it fits with the assessments you already run

A gap analysis and a maturity assessment answer different questions and are often confused. A gap analysis asks what is missing before certification. A readiness assessment asks whether you would pass next month. An ISO 27001 maturity assessment asks how good the system is once all three of those have been satisfied — which is why it is most valuable after certification, not before it.

Frequently asked questions

Does ISO 27001 require a maturity assessment?
No. The standard requires conformity, risk assessment, internal audit and management review. An ISO 27001 maturity assessment is a management choice, not a requirement, and no certificate depends on it.

Which maturity model should we use?
Any consistent scale works, provided the descriptors are written for your controls. Five- and six-level scales derived from process-capability models are the common choice; what matters is that two assessors reading the same evidence would land on the same level.

Can a maturity score replace an internal audit?
No. Internal audit tests conformity against the standard and is required by clause 9.2. A maturity assessment is an additional lens over the same evidence.

How often should we run one?
Annually is enough for most organizations, timed so the result reaches management review while there is still budget to act on it. More often than that and nothing has had time to move.

Should we publish maturity scores to customers?
Be careful. A score is an internal management instrument with no external definition behind it, and a customer who reads “level 2” against a control they care about will not accept the explanation that level 2 is perfectly acceptable for that control.

Where this leaves you

Treat the ISO 27001 maturity assessment as the thing that tells you where to spend next, and keep it separate from conformity work. Write descriptors per control, score on artifacts, set justified target levels rather than aiming everything at 5, and report the distribution instead of an average. Run it after certification, once a year, and use the movement between rounds — that is the only number in the exercise that means anything.

References

  • ISO/IEC 27001 — the information security management system requirements the assessment sits over.
  • NIST SP 800-55 Volume 1 — measurement guidance for security programmes, useful when defining level 4 metrics.

More on assessing an ISMS

Scored control checklists, evidence prompts and a reportable output are in the ISO 27001 Assessment Tool, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.