# Maturity model

Maturity is measured neither by the number of models in use nor by the degree of autonomy.

| Level | State | Expected evidence |
|---|---|---|
| M0 — Informal | Uninventoried individual use | No reliable control |
| M1 — Visible | Usage rules, register, and owners | Inventory, basic training, prohibited-data rules |
| M2 — Measured | Prioritized cases and reproducible evaluations | Baselines, thresholds, pilot reports |
| M3 — Governed | Portfolio, common architecture, and risk management | Gates, responsibilities, suppliers, incidents |
| M4 — Adaptive | Monitoring, reassessment, and controlled retirement | Trends, exercises, audits, and lifecycle decisions |

## Progression rule

An organization progresses only when evidence from the previous level exists for the scope concerned. It may be M3 in one department and M0 in another; an overall score must not hide those gaps.

## Next action by level

- **M0 → M1**: inventory real use and publish simple data rules.
- **M1 → M2**: select a measurable case and build evaluations before the prototype.
- **M2 → M3**: establish gates, a supplier register, and a shared security foundation.
- **M3 → M4**: automate controls, exercise incident response, and institutionalize retirement.
