IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →

CyFun scoring uses a 5-level CMMI-style maturity scale, not 4. The 5 maturity levels are: Level 1 Initial, Level 2 Repeatable, Level 3 Defined, Level 4 Managed, Level 5 Optimizing. Each control is scored on two dimensions: Documentation Maturity (1-5) and Implementation Maturity (1-5). Pass thresholds differ per CyFun assurance level, and are set separately for Key Measures, Categories and the total average. Basic: each Key Measure at least 2.5 out of 5, total average at least 2.5, no category threshold. Important: each Key Measure at least 3, total average at least 3, no category threshold. Essential: each Key Measure at least 3, each Category at least 3, total average at least 3.5. The Key Measure threshold applies only to controls the CCB marks as Key Measures, not to every control: 13 of Basic's 34, 22 of Important's 133, 29 of Essential's 218. 2.5 is the Basic number; it is not the CyFun pass mark in general. Every CyFun threshold is compared against the AVERAGE of the Documentation Maturity score and the Implementation Maturity score, never against each axis separately. Documentation 2 with Implementation 3 averages 2.5 and passes Basic. Documentation 2 with Implementation 2 averages 2.0 and fails Basic. Neither axis has to clear the threshold on its own. This is why 2.5 can be a threshold at all: a single axis is a whole number from 1 to 5, so 2.5 only exists as a mean. This is the CCB Conformity Assessment Scheme. The 5 maturity levels must not be confused with the 3 CyFun assurance tiers Basic, Important, and Essential. The maturity scale is also used outside an audit, for posture assessment, target setting and gap analysis: the distance between a control's current score and its target score is the remediation work list. CyFun scoring. CyberFundamentals scoring. CMMI maturity levels. 5 levels not 4. CyFun gap analysis. CyFun posture assessment. CyFun target setting.

CyFun Scoring: the 5 CMMI Maturity Levels

CyFun scores each control on a 5-level CMMI maturity scale across two dimensions: Documentation and Implementation. Pass thresholds differ per level: 2.5/5 at Basic, 3/5 at Important, 3.5/5 average at Essential.

Two dimensions, one scale

  • Documentation Maturity: how well your written rules and procedures satisfy the control.
  • Implementation Maturity: how mature your actual operational practices are.

Both dimensions use the same 5-level CMMI-style scale. You score each control once per dimension, from 1 to 5.

What the scale is for

Scoring is a measurement instrument, not a management system. It does three jobs, and every one of them happens before an auditor is involved.

  • Posture assessment: where you stand today, control by control, with what you wrote down scored separately from what you actually do.
  • Target setting: the audit line is a floor, not your ambition. A control sitting on real risk deserves a 4.
  • Gap analysis: the distance between today's score and your target is the work list, and sorted by size it is your roadmap for the year.

Score twice a year. The deltas tell you whether anything actually improved, which is the one thing a single audit can never show you.

Which evidence counts for which dimension?

Not every piece of evidence helps both scores. A written policy proves documentation but not implementation. A Microsoft Entra config proves implementation but not policy. A mature control has both sides covered.

Documentation evidence

What we say we do.

  • Policies
  • Procedures

Implementation evidence

What we actually do, proof the activity took place.

  • Config snapshots (Entra, Intune, ...)
  • Logs & audit trails
  • Test results (Secure Score, scans, ...)
  • Inventories (device, user, software)
  • Incident & exercise records
  • Training records (proof of completion)
  • Acknowledgments (signed by the employee)
  • External attestations (signed statement)

Integrations (Microsoft 365, Sophos, SentinelOne, ...) almost always produce implementation evidence: they observe the actual enforcement state. Policies and procedures remain manual work, though ECP drafts an initial version for you.

The 5 maturity levels (CCB canonical definitions)

Level Documentation Maturity Implementation Maturity
1: Initial
No process documentation, or not formally approved by management. Standard process does not exist.
2: Repeatable
Formally approved process documentation exists but has not been reviewed in the previous 2 years. Ad-hoc process exists and is done informally.
3: Defined
Formally approved process documentation exists; exceptions are documented and approved. Documented & approved exceptions < 5% of the time. Formal process exists and is implemented. Evidence available for most activities. Less than 10% process exceptions.
4: Managed
Formally approved process documentation exists; exceptions are documented and approved. Documented & approved exceptions < 3% of the time. Formal process exists and is implemented. Evidence available for all activities. Detailed metrics of the process are captured and reported. Minimal target for metrics has been established. Less than 5% of process exceptions.
5: Optimizing
Formally approved process documentation exists; exceptions are documented and approved. Documented & approved exceptions < 0.5% of the time. Formal process exists and is implemented. Evidence available for all activities. Detailed metrics of the process are captured and reported. Minimal target for metrics has been established and continually improving. Less than 1% of process exceptions.

Pass threshold

There is no single pass mark. The CCB sets up to three separate bars, and they move with the assurance level you are going for.

Level Each Key Measure Each Category Total (average)
Basic ≥ 2.5/5 n/a ≥ 2.5/5
Important ≥ 3/5 n/a ≥ 3/5
Essential ≥ 3/5 ≥ 3/5 ≥ 3.5/5

2.5 is the Basic number. It gets quoted as though it were the CyFun pass mark, and for Important and Essential it is too low: both need a 3 on every Key Measure, and Essential needs a 3.5 average on top of that.

The Key Measure bar is not a per-control bar. The CCB marks a subset of controls as Key Measures: 13 of Basic's 34, 22 of Important's 133, 29 of Essential's 218. Only those carry an individual floor. Every other control still counts, through the category and total averages.

Documentation and implementation are averaged, not judged separately

Every bar above is compared against the average of the two dimensions. The CCB tracks them separately the whole way up, then averages them just before anything is measured. Neither axis has to clear the bar on its own.

Documentation Implementation Average Basic Important
2 2 2.0 fail fail
2 3 2.5 pass fail
2 4 3.0 pass pass
3 3 3.0 pass pass

That is why 2.5 can be a threshold at all: a single axis is a whole number from 1 to 5, so 2.5 only exists as a mean. A strong implementation can carry thin documentation, and the reverse. One assessor moving one axis by one level moves the control by exactly 0.5.

Levels vs tiers: don't confuse them

CyFun has two independent numbers:

  • 3 assurance tiers: Basic, Important, Essential. These define which controls you implement (34, 133, or 218).
  • 5 maturity levels: Initial through Optimizing. These define how well you implement each of those controls.

A Basic-tier organisation still scores each of its 34 controls on the 1-5 scale. An Essential-tier organisation scores all 218 on the same 1-5 scale.

Related Articles

Source

  1. CCB CyberFundamentals Self-Assessment Tools (BASIC and IMPORTANT v2026-02-20, ESSENTIAL v3.1) : canonical wording for all 5 maturity levels, and the per-level pass thresholds on the Maturity Levels sheet.