Masterclass on assessing the maturity of an existing compliance program against industry benchmarks. Uses the CMMI for Cybersecurity model and NIST CSF Implementation Tiers to score people, process, and technology dimensions. Output is a board-ready maturity report and three-year roadmap. Useful for new CISOs and incoming compliance directors.
Most compliance programs grow reactively—controls get added after audits, policies get updated after incidents, and nobody steps back to ask whether the program as a whole is functioning at the level the organization needs. This six-hour masterclass gives compliance practitioners and security leaders a structured, repeatable methodology for answering that question honestly.
The session is built around two complementary frameworks: the CMMI for Cybersecurity model, which scores organizational capability across people, process, and technology dimensions on a five-level maturity scale, and the NIST Cybersecurity Framework Implementation Tiers, which characterize how rigorously risk-informed practices are integrated into operations and supply-chain decision-making. Together, these lenses reveal not just what controls exist, but how consistently and intentionally they are managed.
Instructor Carl B. Johnson draws on direct experience conducting maturity assessments for defense contractors and federal-adjacent organizations, translating framework language into the practical workflow a compliance team can execute with existing staff.
This is a working session, not a survey course. By the end of the six hours you will have produced or be ready to produce:
You will also leave with a clear vocabulary for communicating program maturity to non-technical leadership—a skill that directly influences whether improvement initiatives get funded.
This masterclass is designed for the people responsible for the health of a compliance program and for the leaders who need to understand what they are investing in.
If your organization already works with Cleared Systems on compliance program development or has engaged our Regulatory vCISO Services, this masterclass complements that work by giving your internal team the assessment skills to measure progress between engagements.
A maturity assessment is most valuable when it connects to a plan. Cleared Systems offers hands-on support for organizations ready to act on their findings—from targeted risk assessments to full program buildouts. Explore our full services catalog to see how ongoing advisory support can accelerate the roadmap you build in this session.
Ask about group rates, private delivery of this curriculum for your team, or whether this session fits your compliance roadmap.
Contact Us