Specifications

IO Maturity Model, Specification

This is the canonical maturity definition for the current IO product. It supersedes the earlier staged formulation that used different level names and a 0–6 progression. That earlier structure must not be mixed with the levels below in product…

Pre-normative working specificationDocument v3.4Model v0.29 min read

This is pre-normative material. Values and definitions here are working values, they are published so the reasoning is inspectable, not because they are settled.

IO is the product. IO-HQ is the company that builds it. This document specifies how IO computes a maturity finding.

Status: pre-normative · model version 0.2. The gate values below are working values. They have not been calibrated against representative customer data and must not be cited as a standard. Nothing in this document changes without a version increment.

This is the canonical maturity definition for the current IO product. It supersedes the earlier staged formulation that used different level names and a 0–6 progression. That earlier structure must not be mixed with the levels below in product copy, reports or resource pages.

1. What maturity means here

Maturity is repeatability demonstrated by evidence. It is not a band on a performance score, and it is not an opinion collected from the organisation being assessed.

Every determination is computed from execution records already held: the signal that raised the work, the accountable owner, the rule that justified it, the disposition and its date, the baseline, and the post-intervention measurement.

Two rules govern everything below.

Weak evidence never raises maturity. Confidence and maturity are separate findings and are reported separately. A finding may be withheld or marked provisional on confidence grounds; it is never promoted on them.

Absence of evidence is never a low level. Not-yet-assessable is held apart from every level, is never rendered on the same scale, and always carries a reason.

2. Unit of assessment

Maturity is computed at the level of a security practice, access review, vulnerability remediation, phishing resilience, third-party review, detection response. It does not begin by assigning one unexplained number to an organisation.

Security practices sit inside IO's eight IO domains. A domain maturity result is the assured level, distribution and binding constraint across the material practices in that IO domain. An enterprise result applies the same roll-up across all material practices in scope, and is reported through assured level, distribution, evidence coverage and binding constraints, never as an averaged enterprise security score.

A domain performance score is not a maturity result. Performance scores may be weighted across measured dimensions. Maturity levels may not. Product surfaces must never label a domain performance band as a maturity band or present movement in the performance score as movement in maturity.

Domain performance, post-intervention verification, maturity, evidence confidence, evidence coverage, assurance and compliance are seven distinct reports and are never substituted for one another. No verification outcome proves causation, compliance or complete control effectiveness.

Scope is locked before the window opens. The practices, business units, systems and evidence sources that are material are declared in advance. A weak IO domain cannot be removed from scope once evidence arrives. Any scope change opens a new window under the model version then in force.

The programme roll-up reports three things, never one

FigureMeaning
Assured levelThe highest level sustained by every material, assessable practice in scope
DistributionHow many practices sit at each level
Binding constraintThe practice, gate, current measurement and remaining gap holding the assured level where it is

The assured level is deliberately a floor. An average would conceal the practice most likely to break the operating model. It is also slow to move, which is why the distribution is reported beside it rather than beneath it: a programme improving genuinely shows movement in the distribution long before the assured level changes. That is intended behaviour, not a defect.

3. The evidence chain

A valid maturity record preserves lineage across signal → rule → owner → action → measurement → adaptation, and carries its source system and identifier, timestamps for raise and disposition and measurement, the accountable owner or role, the disposition and its evidence, and its relationship to the practice being assessed.

Evidence that cannot be traced to its source may inform investigation. It does not advance maturity.

4. Observation windows

Continuity is judged against the practice's own expected cadence. A daily process and a quarterly control are not measured against the same clock.

Practice cadenceMinimum window
Daily or weeklyThree consecutive expected operating periods
MonthlyThree consecutive months
Quarterly or lowerTwo complete cycles, or the published minimum sample
Event-drivenThe published minimum sample of qualifying events

Until the window closes the practice is not yet assessable or provisional. It is never assigned a level on partial data.

5. The gates

LevelNameGate
0UnmanagedEvidence is assessable and one or more Level 1 gates are not met
1Accountable≥ 90% of eligible work has an accountable owner; ≥ 85% reaches a recorded disposition inside its required window
2SustainedLevel 1 holds; ≥ 80% cadence adherence sustained across the minimum window
3GovernedLower gates hold; ≥ 80% of eligible work links to a structured rule or threshold; every exception carries owner, rationale, approval and expiry or review date
4VerifiedLower gates hold; ≥ 70% of completed interventions record a valid baseline or first reliable observation, a stated expected outcome, a post-intervention measurement and a result
5AdaptiveLower gates hold; ≥ 80% of ineffective or regressed interventions are modified or retired within the next governance cycle; two complete learn-and-adjust cycles evidenced

Levels are all-or-nothing and are never averaged. The dimensions are not commensurable, ownership coverage and verification coverage do not sit on a common scale, and a mean of the two describes nothing. Averaging produces a grade; all-or-nothing produces a diagnosis. It also resists gaming, because a weighted model is optimised by lifting whichever dimension is cheapest, which is precisely the wrong behaviour to reward.

Levels do not skip. Failing a Level 1 gate caps the practice at 0 regardless of Level 4 evidence. Every result names its binding constraint.

For urgent incident response or a newly connected source, the first reliable observation may establish the baseline for future comparison. It does not create a verified or regressed outcome for work that already occurred. The affected record is normally inconclusive, confidence is reduced and the exception is named.

6. Eligible population

Excluded: test and synthetic records, duplicates, formally cancelled items.

Included: approved exceptions. They remain visible and governed and are never silently removed from the denominator. An organisation cannot improve its maturity by granting itself exceptions.

7. Confidence, reported separately

ConfidenceCondition
HighAll required sources connected, record completeness ≥ 90%, window and sample met
ModerateSources connected, completeness 70–89%, no gap large enough to reverse the finding
LimitedCompleteness 60–69%, or a material source gap. Result is provisional and the gap is named
Not yet assessableA critical source absent, completeness below 60%, or window or sample not met

Record completeness is the share of eligible records carrying every field the assessment requires, source and identifier, raise and disposition timestamps, accountable owner, disposition state, linkage to the practice. A record complete for its originating system may still be incomplete for assessment.

Source coverage and record completeness are reported separately, so a connected source is never mistaken for a complete record. A source can be fully connected and yield 40% completeness.

8. Not yet assessable

Held apart from every level. Never on the same scale, never an input to one, and always carrying one of: a critical source is not connected · coverage is below the published minimum · the window is incomplete · the minimum sample is not met · the dimension is not computable for this practice.

The count of not-yet-assessable practices is reported as a finding in its own right. "Four of eight domains cannot be assessed because evidence is not flowing" is the honest version of the coverage gap that is usually hidden behind an amber tile.

9. Change control

Thresholds are fixed, published and versioned, and are not set by the organisation being measured. Internal targets may be displayed alongside the IO level but never replace it and never affect the computed level. Threshold changes apply prospectively only, a prior finding is never restated under new thresholds, so apparent movement cannot be manufactured by moving the bar.

10. Relationship to published frameworks

Informed by, never aligned with, compliant or certified.

C2M2 Version 2.1 (US Department of Energy, June 2022) is the primary anchor for any crosswalk, suited to industrial and operational technology environments and publicly available. CMMI (ISACA, trademarked) is a reference point only: the progression is public, the practice text and appraisal are not ours to use. NIST CSF 2.0 Implementation Tiers are not crosswalked, because NIST states explicitly that Tiers are not intended to be maturity levels.

Direction of claim is always our evidence speaks to this practice, never you comply with this practice. Practice identifiers only; framework text is never reproduced.

Industry position and the IO position

The accepted models answer different questions, and IO preserves those differences rather than blending their labels into a proprietary score.

SourceAccepted industry useIO uses it forIO deliberately does not inherit
NIST CSF 2.0Organising cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond and RecoverOutcome coverage and vocabularyA maturity score; NIST says Implementation Tiers are not maturity levels
C2M2 v2.1Evaluating whether cybersecurity practices are implemented and institutionalised, using MIL0-MIL3 independently by domainThe primary maturity reference and a structure for evidence navigationA MIL conversion or C2M2 assessment result
ISO/IEC 27001:2022Establishing and continually improving an information security management systemGovernance, performance-evaluation and improvement contextConformity or certification
ISO/IEC 42001:2023Establishing and improving an AI management systemAI-governance evidence contextConformity or certification

IO agrees with the standards that maturity requires more than control presence, but takes a narrower and more testable stance on how progression is earned: repeatable ownership, disposition, governance, measurement and adaptation must appear in attributable execution records. A policy, dashboard, interview answer or automated control mapping can support the record; none can substitute for it.

That stance also addresses a growing industry concern: accelerating compliance documentation with AI can create the appearance of implementation without its operational reality. IO treats automation as a collection and analysis mechanism, not as accountability and not as assurance.

Primary references: NIST CSF 2.0 (opens in a new tab) · C2M2 v2.1 (opens in a new tab) · ISO/IEC 27001 (opens in a new tab) · ISO/IEC 42001 (opens in a new tab)

11. Not covered

Business continuity and disaster recovery planning. Personnel security and vetting. Any practice producing no execution record. These require assessment by other means, and naming them is what makes the covered practices credible.

Physical Security is a different case. IO can measure Physical Security domain performance where attributable evidence is available. This does not, by itself, establish a Physical Security maturity finding. The current IO Maturity Model requires defined material practices, attributable execution lineage, representative evidence coverage, a completed assessment window and calibrated maturity gates. Until those requirements are satisfied for the Physical Security practice set, IO reports domain performance, evidence coverage and verification outcomes without presenting them as maturity.

12. Open before normative release

#Item
1Gate values calibrated against representative data across two quarters, and not fitted to any single dataset, including our own demonstration tenant
2Cadence adherence where no schedule is declared is not currently computable
3Recurrence window per practice, required for the Level 5 gate
4Minimum sample by cadence, for event-driven practices
5Required field set per practice beyond the published minimum
6Level 5 evidence horizon for tenants under twelve months old

Appendix, a determination, worked

Practice: third-party access review Window: 1 April – 30 June, monthly cadence, three consecutive periods Confidence: moderate, completeness 82%, all required sources connected

Level 1, ownership 94% ✓ · disposition in window 88% ✓ Level 2, cadence adherence 91% ✓ Level 3, work linked to a structured rule 86% ✓ · exceptions governed ✓ Level 4, interventions with baseline, expectation, measurement and result: 41%

Result: Level 3, Governed. Binding constraint: verification coverage at 41% against a threshold of 70%. Gap: 29 points. Confidence: moderate. The finding is not provisional.

The last three lines are the point of the model. "Level 3" alone tells a reader nothing they can act on. The binding constraint tells them exactly what to do next, and how far away it is.

Next step

See it before you talk to anyone.

Two quarters of recorded activity across sixteen seats. One click, no install.