ANSSI maturity in five tiers, and why it beats the percentage
A percentage treats every gap as equal. A five-tier maturity model does not: it says what is genuinely achieved, and what single failure is blocking the next tier. It also makes a far better remediation plan — and a far better contractual objective.
The limit of a percentage
A weighted score is a real improvement on a raw ratio, but it still summarises everything into one number. Yet a service account sitting in Domain Admins and a missing diagnostic setting are not two instances of the same thing, and averaging them produces a figure that is accurate and unhelpful at the same time.
The ANSSI maturity model answers differently. Every control is placed on a scale from 1 to 5 according to its category, from identity foundations up to governance and advanced hardening. The result is not a score but a level — and a level is a sentence rather than a number.
The five tiers
| Tier | Active Directory | |
|---|---|---|
| 1 | Privileged accounts, delegations, the objects that grant domain control | Role assignments, custom roles, classic administrators, owner service principals |
| 2 | Authentication, Kerberos, password policy, LAPS | Key Vault and secrets, encryption, backup vaults, immutability |
| 3 | Service hardening, legacy protocols, certificate templates | Network, storage, databases, App Service, virtual machines, containers, AI services |
| 4 | Logging, monitoring, detection | Diagnostic settings, retention, flow logs, Defender for Cloud |
| 5 | Governance and advanced hardening |
The distribution is informative in itself. On Active Directory, the weight sits low: the risk is in the escalation paths, not in the services.
The rule is deliberately harsh
The level reached is the highest tier N such that no non-compliant control remains in tiers 1 to N. Not a percentage of tier 1, not an average — none. Two failures at tier 1 and the level is zero, whatever the rest of the estate looks like.
Why so strict? Because the alternative encourages exactly the wrong behaviour. A model that let you claim tier 3 with a residual tier 1 failure would reward polishing the visible layer while leaving the foundation open. There is no such thing as good monitoring on a directory where every user can become an administrator.
Controls in error or not evaluated are excluded from the count, as they are from the score. A tier with no evaluated control at all is considered clean — which is worth remembering when a role assignment is missing and half a tier comes back unevaluated.
Four ways to use it
- As the thread of the debrief. “Your estate is at level 1 out of 5” lands where “your compliance is 58%” does not. Present the level before the percentage.
- As a natural remediation plan. Handle tier 1 first. On Active Directory that means closing the escalation paths before touching protocols.
- As a contractual objective. “Reach level 3 within six months” is measurable and verifiable by a follow-up audit. “Improve our security posture” is not.
- Alongside the attack paths. The tier gives depth, the attack path graph gives urgency. Together they make the debrief; separately, each one is arguable.
What it does not do
The model is not a certification and carries no legal weight. It is a reading grid — a way of ordering findings that matches how an attacker actually proceeds. Its value is that it converts an audit into a sequence of decisions rather than a list of grievances, and that it survives contact with an executive committee, which a control-by-control table does not.