The framework: four functions
CyberVadis evaluates your company's cybersecurity practices across four functions, based on internationally recognized security frameworks including ISO 27001, NIST Cybersecurity Framework, GDPR, NIS2, and DORA:
Identify - Does your company know what it needs to protect? This covers asset management, risk assessment, data classification, and governance.
Protect - What controls does your company have in place? This covers access control, encryption, network security, endpoint protection, and security awareness.
Detect - Can your company identify a security incident when it occurs? This covers monitoring, logging, anomaly detection, and vulnerability management.
React - Does your company have a plan to respond and recover? This covers incident response procedures, business continuity, and communication protocols.
Each function contributes to your overall score. You also receive a separate score for each function, so you can see where your company is strongest and where to focus improvement efforts.
What we look for: three layers of evidence
For each area of the assessment, our analysts evaluate three things:
Definition - Is there a formal policy or procedure in place?
Implementation - Is that policy actually being followed in practice?
Monitoring - Is there evidence that the control is being maintained and reviewed over time?
A policy document alone is not sufficient for a full score. The assessment looks for proof that security measures are not just written down but actively operated and controlled.
What "maturity" means
Your score reflects how systematically and consistently your company manages cybersecurity, not just whether individual controls exist. A company with documented, implemented, and actively monitored practices across all four functions will score higher than one with strong policies but limited evidence of real-world application.
Tailored to your company
The assessment is not a generic checklist. Your questionnaire is customized based on your company's sector, size, and the answers you provide during the qualification stage. Only the criteria relevant to your specific context are evaluated, so you are not assessed against controls that genuinely do not apply to your business.
Human-led review
Every assessment is reviewed by a CyberVadis cybersecurity analyst. Automated in-house tools assist the process, but the final evaluation of your responses and evidence is conducted by a human expert. The goal is not to check boxes but to give you an accurate, actionable picture of your security posture.
For details on how your score is calculated, see [How is the score calculated?]
