Maturity Scorecard (Template)

Scale: 1 = ad hoc, 2 = basic, 3 = managed, 4 = measured, 5 = optimized

DomainScore (1–5)What we observedWhat “3” looks like
Identity & AccessMFA enforced, admin roles minimal, shared accounts eliminated
Email & CollaborationBaseline phishing protections, external forwarding controlled
EndpointsInventory + patch cadence + encryption + EDR visibility
Backups & RestoreCoverage known, restore tested, ransomware protections
Ops ResilienceIncident roles, vendor escalation, runbooks, periodic drills

Notes