An ISO 27001 maturity assessment answers a question the certification audit never asks: not does this control exist, but how well does it work, and would it survive the person who runs it leaving. ISO 27001 conformity is binary — you meet a requirement or you do not. Maturity is a scale, and the two are measuring different things.
This guide covers what an ISO 27001 maturity assessment scores, the levels most models use, and where the exercise stops being useful.

Maturity is not conformity
A certification auditor asks whether the requirement is met and whether you can show it. A control performed inconsistently by one overloaded person, with no measurement and no improvement, can still pass. That is not a flaw in the standard — clause-by-clause conformity is what a certificate attests to.
An ISO 27001 maturity assessment exists because that answer is not enough to run a programme with. Boards ask where the money should go next; a conformity result cannot tell them, because everything in scope is already “conforming”. A maturity score can, because it distinguishes the control that works because it is designed to from the one that works because somebody remembers.
The six levels an ISO 27001 maturity assessment usually scores
| Level | What it means | Evidence you would expect |
|---|---|---|
| 0 — Non-existent | The control is not performed | Nothing |
| 1 — Ad hoc | It happens when somebody thinks of it | Isolated examples, no procedure |
| 2 — Repeatable | Consistent in practice, dependent on individuals | Records over time, informal method |
| 3 — Defined | Documented, owned, trained, performed as written | Procedure, owner, training records, output |
| 4 — Measured | Performance is measured against a target | Metrics with thresholds, trend, exception handling |
| 5 — Optimising | The measurement changes the control | Changes traceable to measurement or incidents |
Level 3 is where most certified organizations sit for most controls, and it is a respectable place to be. The jump that matters is 3 to 4, because that is where you stop asserting the control works and start knowing.
What to score, and what not to
Score the Annex A controls you have declared applicable, plus the clause 4–10 management system activities: risk assessment, internal audit, management review, incident management, supplier management, improvement. Do not score controls you have excluded — the Statement of Applicability already records that decision, and re-litigating it inside a maturity exercise confuses two different conversations.
Running an ISO 27001 maturity assessment that survives challenge
- Write level descriptors per control, not in general. “Level 3” means something different for access reviews than for cryptography. Generic descriptors produce scores nobody trusts, because every assessor reads them differently.
- Score on evidence, not on interview. Ask for the artifact that a level implies. Level 4 without a metric is level 3 with optimism.
- Score current state only. Planned improvements belong in the target column. Mixing them produces a picture of the ISMS you intend to have.
- Set a target level per control, and justify it. Not everything needs level 4. A control protecting your crown-jewel system might; the clear desk policy almost certainly does not, and pretending otherwise is how maturity programmes lose credibility.
- Keep the same scale between rounds. Movement is the output. A rescored scale makes the second assessment incomparable with the first, which is the only thing anyone actually wanted.
Where an ISO 27001 maturity assessment goes wrong
Documents get scored instead of practice. A polished procedure nobody follows is level 1 with good typography. The test is what happened last quarter, not what the document says should happen.
Averages hide the risk. An overall “3.4” is a number for a slide. A control at level 1 protecting a critical asset is the finding, and it disappears into the mean. Report the distribution and the outliers, never the average alone.
The scale becomes a target in itself. Once teams are measured on their maturity number, scores rise without anything changing. Independent verification of a sample — by internal audit, or by whoever did not do the scoring — is what keeps the exercise honest.
How it fits with the assessments you already run
A gap analysis and a maturity assessment answer different questions and are often confused. A gap analysis asks what is missing before certification. A readiness assessment asks whether you would pass next month. An ISO 27001 maturity assessment asks how good the system is once all three of those have been satisfied — which is why it is most valuable after certification, not before it.
Frequently asked questions
Does ISO 27001 require a maturity assessment?
No. The standard requires conformity, risk assessment, internal audit and management review. An ISO 27001 maturity assessment is a management choice, not a requirement, and no certificate depends on it.
Which maturity model should we use?
Any consistent scale works, provided the descriptors are written for your controls. Five- and six-level scales derived from process-capability models are the common choice; what matters is that two assessors reading the same evidence would land on the same level.
Can a maturity score replace an internal audit?
No. Internal audit tests conformity against the standard and is required by clause 9.2. A maturity assessment is an additional lens over the same evidence.
How often should we run one?
Annually is enough for most organizations, timed so the result reaches management review while there is still budget to act on it. More often than that and nothing has had time to move.
Should we publish maturity scores to customers?
Be careful. A score is an internal management instrument with no external definition behind it, and a customer who reads “level 2” against a control they care about will not accept the explanation that level 2 is perfectly acceptable for that control.
Where this leaves you
Treat the ISO 27001 maturity assessment as the thing that tells you where to spend next, and keep it separate from conformity work. Write descriptors per control, score on artifacts, set justified target levels rather than aiming everything at 5, and report the distribution instead of an average. Run it after certification, once a year, and use the movement between rounds — that is the only number in the exercise that means anything.
References
- ISO/IEC 27001 — the information security management system requirements the assessment sits over.
- NIST SP 800-55 Volume 1 — measurement guidance for security programmes, useful when defining level 4 metrics.
More on assessing an ISMS
- The ISO 27001 maturity assessment — you are here
- The ISO 27001 readiness assessment
- The ISO 27001 gap analysis
- ISO 27001 tools, by category
Scored control checklists, evidence prompts and a reportable output are in the ISO 27001 Assessment Tool, or start with the free ISO templates.