Assessment FAQ · the maturity deliverable
A level you can’t re-derive is a mood, not a level.
The second artefact of the diagnostic is a maturity placement for every AI Security Maturity Model (AISMM) category in scope — a specific level on the Initial → Efficient scale (5 levels × 12 categories), with the evidence and reasoning that justify it. Not a workshop vote, not a self-reported score.
The scorecard grades the checklist — never the other way round.
The discipline
A placement is justified in writing and moved one defensible rung at a time. If you can’t re-derive the level from the evidence, it isn’t a level.
“What level is this function really at — and can I show my working?”
The answer
A level per category, bounded by evidence and justified in writing.
Each category carries its own bespoke L1–L5 rubric — CSA’s own text — so a placement is defensible: you can hand the rubric to the person being graded. The gate then reads this against autonomy, so a function can’t run ahead of what its maturity supports.
The full per-rung rubric (and the paired AI Cyber Maturity Model (AI-CMM) autonomy ladder) lives on the method page; a measured placement on your own function comes from the diagnostic.