Join our Newsletter — 33% off our NHI Course

Capability Level

A capability level describes how far a single practice area has progressed within a maturity model. It usually reflects whether the activity is ad hoc, documented, managed, or governed, depending on the model. The level says more about repeatability and control than about performance quality in any one moment.

What Capability Level Means in a Maturity Model

A capability level is the maturity-model lens on a single practice area. It describes how consistently the practice is performed, how well it is defined, and how much control exists around it, rather than how “good” the outcome looks in one moment.

That distinction matters because a team can deliver acceptable results occasionally while still operating at a low capability level. In practice, capability levels are used to compare process stability, repeatability, and governance across assessments or over time.

How Capability Level Differs from Performance

Capability levels are about the maturity of the practice itself, not just the output. A high-performing team may still have a weak capability if results depend on heroics, informal knowledge, or inconsistent execution. Conversely, a controlled and repeatable practice can sit at a lower output level while it is being improved.

This is why maturity models often separate capability from outcome quality. Capability asks whether the process is defined, managed, measured, and governed; performance asks whether the current result is effective. Mixing the two can hide whether a strength is durable or only temporary.

How Capability Levels Are Typically Interpreted

Although models vary, capability levels usually progress from ad hoc activity toward documented, managed, and governed practice. The key signal is increasing repeatability: fewer steps depend on memory, individual judgment, or undocumented exceptions.

Because different maturity models use different labels and scoring schemes, the exact meaning of a level is always model-specific. A level in one framework should not be treated as directly equivalent to the same number in another framework without checking the model’s definitions and scoring rules.

When capability is assessed well, the level gives stakeholders a compact way to discuss operating discipline, not just whether a control exists on paper. That makes it useful for prioritising improvement work, benchmarking similar teams, and tracking whether governance is becoming more consistent.

Why Capability Level Matters in Security and Governance

In cybersecurity, capability level helps explain whether a practice can be relied on under stress, audit, or scale. A control that works only when specific people are available, or only for a subset of cases, may not be mature enough to support sustained risk reduction.

Capability levels are especially useful when the question is whether a process can be repeated, evidenced, and overseen consistently. For example, NIST Cybersecurity Framework 2.0 and OWASP SAMM both use maturity-style thinking to show whether security work is becoming more disciplined over time.

For control-heavy environments, capability level also aligns with how organisations think about policy, ownership, evidence, and repeatable execution. A practice area with a stronger capability level is usually easier to audit, easier to improve, and less dependent on informal workarounds.

Risk and Threat Considerations

A low or overstated capability level can create false confidence. The main risk is that leaders treat an immature practice as if it were reliable, while hidden inconsistency, weak governance, or undocumented exceptions leave gaps in resilience and control.

Failure mechanism: The practice appears effective in isolated examples but fails when scale, personnel changes, exceptions, or pressure expose the lack of repeatable process, measurement, or ownership.

Impact: Security decisions, audit conclusions, and remediation priorities can be based on a maturity score that does not reflect actual operational control, increasing exposure to control failure and uneven risk management.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, OWASP SAMM and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Capability level reflects how a practice is governed and improved over time.
Recommendation — Use GV.RM-01 to track whether the practice is being managed as a repeatable risk-reduction capability.
OWASP SAMM Software Assurance Maturity Model SAMM is a maturity model whose levels describe how security practices progress and stabilize.
Recommendation — Use SAMM to assess whether the practice is moving from ad hoc execution to managed and optimized operation.
NIST SP 800-53 Rev 5 PM-9 — Risk Management Strategy PM-9 ties governance expectations to a repeatable enterprise risk posture.
Recommendation — Use PM-9 to anchor capability improvements to an enterprise risk management strategy.
ISO/IEC 27001:2022 A.5.1 — Policies for information security Capability level depends on whether a practice is documented and governed as policy.
Recommendation — Use A.5.1 to ensure the practice is documented, approved, and consistently applied.

Practitioner Guidance

Why practitioners should care: Capability level should be used to judge whether a practice can be repeated and governed, not just whether it has produced good results recently. That keeps maturity reviews focused on durability and control, which is what most improvement programmes actually need.

Common misunderstanding: Teams often read a higher level as proof of effectiveness. In reality, a practice can be well managed and still be the wrong control, or a useful control can still be immature if it is not yet consistent enough to trust.