Overview
This article explains how to assign a maturity level to a subcategory in the Cye Exposure Management Platform when working with the NIST CSF 2.0 framework. This article covers system-calculated scores, manual maturity levels, and how linked findings, technologies, and processes contribute to the assessment.
How to Rate a Subcategory
Navigate to the subcategory assessment pane
Go to Maturity Assessment
Select a Function > Category > Subcategory
Check for existing data
A system-calculated score may be present based on linked findings, technologies, or processes
The score can be accepted or reassessed manually
Set a manual maturity rating
Understanding Maturity Levels
Each level builds on the one before, layering improvements like formalized processes, clear responsibilities, measurement, and continuous monitoring:
Level | Description |
1 – Initial | Ad hoc or non-existent implementation; no ownership or repeatability |
2 – Developing | Some basic controls or processes in place; inconsistent application |
3 – Defined | Documented and standardized processes; supporting technologies in place |
4 – Managed | Effectiveness is actively measured and policy compliance is tracked |
5 – Optimized | Mature, continuously improved, and adaptable to change |
Linked Findings, Technologies, and Processes
Findings
Automatically factored into the maturity score if linked
Click a finding to view or edit it on the Findings page
Use the Unmapped Framework filter on the Findings page to locate findings not yet linked to subcategories
Technologies & Processes
Linked assets are visible under their respective sections
Click to view or manage them on the Assets page
Wrap-up / Next Steps
Rating a subcategory is a foundational step in building a maturity profile. Combine manual ratings with linked data where possible, and use filters to identify what's missing — assessments will be more complete and actionable.





