The maturity scale
Every answer in an assessment lands on a five-step scale, and everything the platform reports — category scores, your overall position, what counts as a gap — is built from those answers.
The five levels
The levels run from nothing in place at the bottom to continuously monitored and improved at the top. Their exact wording belongs to the question library you are assessing against, so it is set out on each question rather than fixed by the platform, and two libraries may name the same level differently.
What holds across all of them is the shape: the levels are cumulative. Each one assumes what the one below it describes, so a control cannot be optimised while it is undocumented or untrained. This is why reading the level descriptions matters more than picking the step that feels right — the ladder usually asks for more than the word alone suggests.
Policy and practice
Some libraries ask each control once. Others ask it twice:
- Policy — what your organisation has formally decided and written down. Answer on what the documentation requires, not on how consistently it is followed.
- Practice — what actually happens day to day. Answer on what is really done, even where no document requires it.
Where both are asked, the report shows both and the distance between them. A large gap either way is a finding in itself: policy far ahead of practice is a rulebook nobody follows; practice ahead of policy is competence that depends on individuals and disappears with them.
From answers to a score
Answers are scored on a 0–100 scale internally and translated back into 1–5 levels for display, using bands defined in the question library. Two consequences follow:
- A category score is usually not a whole number. 3.4 means the category sits between the third and fourth level, closer to the third.
- Questions can carry different weights within a category, and categories within the assessment, so a category score is not always the plain average of its answers.
Questions marked not applicable are removed from the calculation rather than scored as zero. Where a category has no scored answers at all, it reads as not scored rather than as a low score.
Acceptable, and target
Two lines are drawn against your scores, and they mean different things.
Acceptable is a fixed floor at level 3, the same for every organisation and every category. At or above it, a category is in reasonable shape. Below it, it needs action.
Target is the level a category is expected to reach, defined in the question library. It can sit above the floor, it can differ between categories, and some libraries set none — where a library has no targets, the report’s target-based views are unavailable rather than empty.
A category can be acceptable and still below target. Treat the floor as the line you must not sit under, and the target as where you have said you want to be.
Where the levels appear
The same 1–5 scale runs through the whole product: the answers you give, the category and overall scores on the report, the levels tasks are grouped under, and the maturity shown against objectives in your action plan. When a number appears anywhere against a 5, it is this scale.
Risk likelihood and consequence use their own 1–5 scales, with different meanings. They are documented with the risk register, not here.