← Back to blog
25 March 20266 min read

What is a cybersecurity maturity score and how do you get one?

Your customer asks for a cybersecurity maturity score. You don't know what that is, let alone how to get one.

What a maturity score is

A number between 0 and 100 that indicates how well your cybersecurity policies and procedures are set up. Not a technical test of your systems, but an assessment of your governance: do you have policies, procedures, training and controls in order?

How verified.supply calculates your score

The NIS2 assessment asks 10 questions in line with Article 21. For each theme you earn points based on your answers. Access management (MFA, least privilege) and incident management carry more weight than other areas.

A score of 70+ is achievable for any company that:

has a password policy

gives employees an annual cybersecurity awareness training

has MFA on critical systems (email, financial system)

has a procedure for when something goes wrong

What you don't need for a good score

ISO 27001, SOC 2, your own CISO or a security department. These are bonus points, not basic requirements.

Read also

Build your VS profile (formerly VSME) once

Create an account and get started today.

No password needed — we email you a login link.