ai · security · skills

Assessment FAQ · the maturity deliverable

A level you can’t re-derive is a mood, not a level.

The second artefact of the diagnostic is a maturity placement for every AI Security Maturity Model (AISMM) category in scope — a specific level on the InitialEfficient scale (5 levels × 12 categories), with the evidence and reasoning that justify it. Not a workshop vote, not a self-reported score.

MATURITY LADDER — capped by evidenceL1InitialL2RepeatableL3DefinedL4CapableL5EfficientEvidence supports L3 — so the ceiling is L3.Claiming L4 without the coverage to back it is exactly the opinion the diagnostic exists to prevent.

The scorecard grades the checklist — never the other way round.

The discipline

A placement is justified in writing and moved one defensible rung at a time. If you can’t re-derive the level from the evidence, it isn’t a level.

“What level is this function really at — and can I show my working?”

The answer

A level per category, bounded by evidence and justified in writing.

Each category carries its own bespoke L1–L5 rubric — CSA’s own text — so a placement is defensible: you can hand the rubric to the person being graded. The gate then reads this against autonomy, so a function can’t run ahead of what its maturity supports.

The full per-rung rubric (and the paired AI Cyber Maturity Model (AI-CMM) autonomy ladder) lives on the method page; a measured placement on your own function comes from the diagnostic.

The per-rung rubric, level by level →

Place a function on the scale →
← Back to Insights

Subscribe for the next essay.