LearnCTEM.com, Best CTEM Learning Platform
Program

CTEM Maturity Model: From Ad Hoc to Optimized

The CTEM maturity model has five levels: Ad Hoc, Repeatable, Defined, Managed, and Optimized. Each level is described with plain evidence you can honestly check for. Most organizations should target Managed within 12-18 months and use Optimized as a direction of travel.

Last updated: July 24, 2026

What you will learn

  • What each maturity level looks like
  • The evidence that proves you are at a given level
  • How to move up one level at a time

Explanation

The five levels

LevelEvidence
1 — Ad HocScans exist but no ranking, no owners, no cadence.
2 — RepeatableA scope, a register, and a weekly triage for one service.
3 — DefinedDocumented lifecycle, roles, cadence, and metrics across multiple scopes.
4 — ManagedValidation is routine, mobilization is measured, exec reporting is monthly.
5 — OptimizedAutomated discovery and prioritization, board-level reporting, continuous improvement loop.

Moving up

Pick the next level, list the missing evidence items, assign an owner to each, and set a 90-day target. Do not chase multiple levels at once.

How to apply this

  • Score your program honestly this quarter
  • Pick one level up as the next target
  • Assign each missing evidence item to an owner
  • Review progress next quarter

Common mistakes

  • Self-scoring generously to look good
  • Chasing Optimized before Managed
  • Adopting maturity as a compliance exercise

Frequently asked questions

Score yourself against the evidence column for each capability. Your level is the lowest one where all evidence is honestly present.

Related pages

Author

LearnCTEM Editorial Team

Practitioners and educators writing plain-English guides on Continuous Threat Exposure Management.

Reviewed by

Senior CTEM Practitioner Panel

Reviewed for accuracy against public CTEM guidance and real-world program experience.