CT4-MATURITY™
The 30-control progressive maturity matrix — 6 levels × 5 domains.
See the complete 30-control × 6-level × 5-domain matrix in detail.
CT4-MATURITY™ — Defined
CT4-MATURITY™ is the progressive control matrix that answers the question every SMB struggles with: "which control should we implement next?"
The framework defines 30 controls across 5 domains (Identity, Endpoint, Network, Application/Data, Security Operations) — and orders them across 6 maturity levels. At Level 1 (Foundation), you implement the 5 controls that absolutely everyone needs. At Level 6 (Resilient), you have the full 30-control complement of an enterprise-grade program.
What makes CT4-MATURITY™ different from CIS, NIST CSF, or ISO 27001? It is sequenced. It tells you not just what good security looks like, but in what order to build it.
The Building Blocks
-
Level 1 — Foundation
The baseline 5 controls. Asset inventory. Patch management. MFA. Endpoint protection. Backup with offline copy. Without these, no further investment makes sense.
-
Level 2 — Fundamentals
Add 5 more controls. Email security. Centralized logging. Vulnerability scanning. Privileged access controls. Awareness training. The minimum viable program.
-
Level 3 — Hardened
Add 5 more. Network segmentation. Configuration baselines. SIEM. DLP basics. Incident response plan. The defendable program.
-
Level 4 — Protected
Add 5 more. EDR/XDR. Identity governance. Application security. Encryption everywhere. Tabletop exercises. The proactive program.
-
Level 5 — Secured
Add 5 more. SOC operations. Threat intelligence. Zero trust networking. DevSecOps. Red team exercises. The mature program.
-
Level 6 — Resilient
Add the final 5. Continuous validation. Threat hunting. Deception technology. Cyber resilience metrics. Active defense. The enterprise-grade program.
The Strategic Impact
Most SMB security programs look like random walks. A SOAR purchase here. An EDR pilot there. A new awareness vendor next quarter. CT4-MATURITY™ replaces randomness with sequenced progression. Every quarter, you advance to the next set of 5 controls. After 18–24 months, you reach Level 5 — a measurably mature program. After 30+ months, Level 6.
From Theory to Practice
Score your organization across all 30 controls. Identify your current level (the highest level where all 5 controls are in place). Plan your roadmap: each upcoming quarter targets one specific level. Resource accordingly. Re-score every 6 months. Use CT4-PROCESS™ to ensure each control is implemented to a real, audit-defensible standard — not just deployed.
Apply CT4-MATURITY
Read the chapter. Try the framework. Engage the team that built it.