Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Gap assessment maturity levels scale from initial and repeatable to defined, managed and optimised with evidence examples

Gap Assessment Maturity Levels: A 2026 Guide

Gap assessment maturity levels give a simple answer to a difficult question: how far along is each control or process, and how far does it still have to go? A yes-or-no compliance check hides the difference between something that exists on paper and something that works every day. A maturity scale shows that difference and makes it easy to compare areas, track progress and decide where to invest.

This guide explains how to build a maturity scale, how to define each level in a way that assessors can apply consistently, what evidence supports each rating, how to set targets and how to turn the scores into a roadmap. It is general guidance, and you should adapt the scale to your framework and size.

Why use gap assessment maturity levels

Compliance is rarely a binary condition. A company can have a written access control policy that nobody follows, or a well-run process with no documentation. Simple pass or fail results treat both as the same failure, which leads to poor priorities. Gap assessment maturity levels separate the questions of design and operation and give each a score.

A scale also improves communication. Leaders understand “we are at level two and need level three by year end” more quickly than a list of forty findings. It supports budgeting, shows progress over time and lets you compare departments or sites on a common basis. You can pair it with the scoring approach in gap assessment scoring to combine maturity and severity.

Choosing a scale for gap assessment maturity levels

Most practitioners use four to six levels. Fewer than four gives little insight, and more than six invites arguments about small differences. Many models follow the pattern of the Capability Maturity Model: initial, repeatable, defined, managed and optimising. You do not need to copy any particular model. Choose a scale that suits your framework and that your assessors can apply consistently.

Keep the names simple and avoid jargon. Every level needs a plain definition, a short list of characteristics and example evidence. Test the scale on two or three controls before you roll it out, and refine any wording that produces disagreement.

LevelNameWhat it looks likeTypical evidence
0AbsentNo control or processNothing found
1InitialAd hoc, depends on individualsInformal emails, personal notes
2RepeatableBasic process exists but is inconsistentDraft procedure, some records
3DefinedDocumented, approved and followedApproved policy, consistent records
4ManagedMeasured, reviewed and improvedMetrics, review minutes, corrective actions
5OptimisedContinuously improved and embeddedTrend data, lessons learned, benchmarking

Defining each level with evidence

The key discipline is tying each level to observable evidence rather than opinion. A level three rating should mean you can show an approved procedure, records of it being followed and named owners. A level four rating should add measurement, such as metrics and review outcomes.

Write the evidence expectations into the scale. For example, for access reviews: level two might mean reviews happen occasionally with no record; level three means quarterly reviews with signed records; level four means review results are tracked, exceptions are trended and the process is improved. This is the same approach auditors use, as described in ISO 19011:2018 on auditing management systems, where conclusions rest on evidence that can be verified.

Rating controls with gap assessment maturity levels

Different assessors will rate the same control differently unless you calibrate them. Before you begin, run a short session in which everyone scores the same three or four examples, then compare and discuss. Agree how to treat partial evidence and edge cases, and add the agreed rules to the guidance.

Apply a “lowest credible level” rule when evidence is mixed: if the policy is level three but records show level two practice, the rating is level two. Record the reasoning next to each score. A second reviewer can check a sample of ratings for consistency, especially for the highest and lowest scores.

  • Score design and operation separately if you can
  • Base every rating on evidence you have seen
  • Use the lowest credible level when evidence is mixed
  • Have a second person review a sample

Setting targets and finding the gap

A gap only exists relative to a target. Decide the level you need for each area, based on risk, legal duty and cost. A critical control such as backup and recovery may need level four, while a minor administrative process may be fine at level two. Do not set level five everywhere: it is expensive and rarely necessary.

The gap is the difference between current and target level. Rank the gaps by size and by the importance of the area. Our guide to gap assessment prioritization explains how to combine them into an ordered list, and the gap analysis remediation plan shows how to turn them into actions.

Turning maturity scores into a roadmap

A roadmap groups actions into phases, usually quick wins in the first three months, structural improvements over the following year and longer-term optimisation. Moving one level is a reasonable goal for a year for most controls. Trying to jump from level one to level four in a single step rarely works.

Assign each action an owner, a date and a measure of success. Tie the measure to the maturity definition: “reach level three by producing an approved procedure and three months of records”. Then reassess after the actions are complete to confirm the level was really achieved.

Presenting gap assessment maturity levels

A radar chart or heat map by domain is an effective summary: current level, target level and the gap for each area. Add a short narrative on the biggest gaps and the plan. Avoid overloading leaders with detail; keep the working scores in the workbook for those who want to drill down.

Be frank about limitations. A maturity score is a judgement supported by evidence, not a measurement with decimals. Say how the assessment was done, what evidence was reviewed and what was not covered. That honesty builds trust in the results and in the plan.

Common mistakes with gap assessment maturity levels

Common errors include rating by opinion without evidence, inflating scores because a policy exists, using scales with vague labels, setting the same target everywhere, mixing design and operation in a single score and never reassessing. Another is treating the score as a competition between departments, which encourages defensive behaviour and hides real problems.

Avoid these by tying every rating to evidence, calibrating assessors, agreeing risk-based targets and repeating the assessment on a schedule. Interviews can help test claims; see gap assessment interviews for a method.

Fitting the scale to your framework

The same scale can serve different frameworks, but the evidence expectations should reflect each one. For an information security standard, see how the scale works in an ISO 27001 gap assessment. Decide what the assessment covers before you rate anything, using the approach in gap assessment scoping, and store the evidence in an organised way, as described in gap assessment evidence, so ratings can be checked later.

Reassessing to show progress

A maturity scale earns its keep when you repeat it. Reassess after each round of remediation using the same definitions and the same evidence rules, so scores are comparable. Show the movement for each area, explain any rating that fell and note what evidence supported each rise. Progress that can be demonstrated builds confidence with leadership and auditors alike.

A short worked example

A logistics company assesses its business continuity controls against a five-level scale. Backup exists and is tested twice a year with records, so it is level four. Incident response has a documented plan but no exercises, so it is level three on design and level two on operation, giving an overall level two by the lowest credible level rule. Supplier resilience is ad hoc, so it is level one.

The targets are level four for backup, level three for incident response and level three for suppliers. The roadmap schedules an exercise within three months, a supplier questionnaire within six and a review of the results at nine months. After the next assessment, incident response reaches level three, and the company sets new targets.

Using a ready structure

If you want a report and workbook that carry the scale, evidence, targets and roadmap together, the Gap Assessment Report and Workbook provides a structured layout you can adapt to your framework. Whichever tool you use, sound gap assessment maturity levels rest on clear definitions, evidence-based ratings and targets that reflect risk.

Gap assessment maturity levels FAQ

How many maturity levels should we use?

Four to six is typical. Fewer gives little insight and more creates debate over small differences. Choose a scale your assessors can apply consistently.

Should the target always be the highest level?

No. Set targets by risk and legal need. Critical controls may need a high level, while minor processes are often fine at a lower one.

How do we handle mixed evidence?

Use the lowest credible level supported by evidence, record the reasoning and identify what would be needed to reach the next level.

Can maturity scores replace compliance findings?

No. They complement them. Findings identify specific requirements that are not met, while maturity shows how well processes are established and improving.

How often should we reassess?

At least annually, and after major changes or completion of significant remediation, so you can confirm improvements and reset targets.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.