Skip to content

Readiness practice

Maturity assessment: judging how consistently something actually operates

Maturity grading exists to answer one question that a yes/no checklist cannot: is this practice a habit, or does it depend on a particular person remembering? Used well, it makes prioritisation defensible. Used badly, it becomes an argument about whether something is a two or a three.

Last updated 28 July 2026 · ISAREADY Editorial Team

Why a graded scale beats yes/no

Most honest answers to “do you do this?” are “partly”. A binary scale forces that answer into either a yes that overstates or a no that understates, and both distort the plan.

A graded scale also makes progress visible between passes. Moving a theme from partially implemented to implemented is real progress that a yes/no scale cannot record.

The scale we use

Our self-assessment uses four scoring levels plus an exclusion. The definitions matter more than the labels.

  • Implemented — in place, operating across the whole scope, and you could produce a recent record without preparation.
  • Partially implemented — real but uneven. Defined but not applied everywhere, or applied but not recorded.
  • Planned — agreed and scheduled, not yet operating. Intention, correctly scored as almost nothing.
  • Not implemented — not in place today.
  • Not applicable — genuinely outside scope. Excluded from the calculation entirely rather than scored as zero.

ISAREADY recommendation This scale and its point values are ISAREADY methodology. They are not derived from, and are not comparable to, any official assessment scale.

Handling “not applicable” correctly

This is where most scoring models quietly go wrong. If a not-applicable answer scores zero, an organisation is penalised for scope it does not have. If it scores full marks, declaring things out of scope becomes a way to inflate the result.

The correct treatment is to remove it from both sides of the ratio: the earned points and the maximum applicable points. The score then describes only what actually applies.

The corollary is that not-applicable must be used honestly. It means “this genuinely does not exist in our organisation”, not “we would rather not answer”.

Keeping grading honest

Four habits that do most of the work:

  • Write the level definitions down, with an example from your own organisation next to each.
  • Grade in pairs — process owner plus someone from outside the area.
  • Require a record reference for anything graded as fully implemented. If nobody can name the record, it is partial.
  • Keep the previous pass visible during the re-assessment, and require a reason for every change in either direction.

What a maturity score is not

It is not a prediction. A high indicator means your practices look established and recordable to you; it says nothing about how a specific assessment against a specific catalogue will go.

It is also not a target in itself. The number exists to help you decide where to spend the next quarter. Once it starts being managed for its own sake, it stops being informative — which is the usual fate of any metric that becomes a goal.

Ready to see an indicative view? Take the free self-assessment.

Frequently asked questions

Is the ISAREADY Readiness Indicator a maturity score?
It is a readiness indicator built from a graded self-assessment. It is not an official maturity level, it is not comparable to any published assessment scale, and it does not predict an assessment outcome. We deliberately avoid calling it a maturity level for that reason.
How do we stop grading from drifting between reviews?
Write down what each level means in your own words, with an example from your organisation, and keep that definition with the assessment. Drift almost always comes from the definition living in someone’s head rather than in the document.
Should every theme reach the top level?
No. Effort should follow risk and scope. A theme that is genuinely peripheral to your operation does not need the same investment as one central to it — and forcing everything to the top level is how programmes become expensive without becoming safer.
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.