Skip to main content
CR-CMM v1.1 - Excel Toolkit Available

Cyber Resilience Capability Maturity Model

Helping organizations enhance their ability to anticipate, withstand, recover from, and adapt to adverse cyber events. Its primary goal is to provide a structured approach for assessing an organization's current cyber resilience maturity and identifying priority areas for improvement.

Start the 5 minute assessment

Want something quicker? Start with the 5 minute version to get a first read, then unlock the workbook when you are ready for the deeper offline assessment.

CR-CMM is the community-driven cyber resilience capability maturity model, guided by an Advisory Board for technical integrity and strategic input. CR-CMM is sponsored and owned by High Value Target, a boutique cyber resilience firm.

Toolkit v1.1Excel Workbook151 Evidence Checks
CR-CMM Excel toolkit and assessment workbook preview

Quick scan

Run online first to see where your gaps are.

Deep dive

Use the Excel workbook for the full CR-CMM assessment.

Expert support

Bring in our experts if you need a facilitated deep dive.

Community-driven
Facilitated in minutes
10 core practices
150+ evidence checks
NIST AlignedMITRE Aligned

Moving from assumptions to a shared operational reality.

Resilience fails when teams operate on different assumptions. The CR-CMM workbench forces critical conversations and creates a single source of truth.

Cross-functional clarity

Break down silos between security, engineering, and business continuity by assessing capabilities together using a common language.

Evidence-based reality

Move beyond policy checks. The 150+ checkpoints require demonstrable evidence, exposing blind spots in actual operational maturity.

Actionable momentum

The outcome is not a static score. It is a prioritized backlog and a targeted roadmap designed to create immediate operational momentum.

Practice 06: Recovery42 / 150

Are critical data assets backed up to immutable storage isolated from the primary production environment?

Evidence Notes

Verified via Airgap config in AWS. Partial implementation noted as legacy DBs remain in transit.

A facilitated capability workbench.

CR-CMM is not a passive checklist or a compliance audit. It is designed to be used live in a room (or virtual room) with key stakeholders. The toolkit structures the conversation, ensuring you ask the right questions and capture reality accurately.

  • Structured AssessmentGuides facilitators through progressive capability layers with objective evidentiary checks.
  • Maturity ScoringCalculates current state against a rigid 5-level maturity model for immediate benchmarking.
  • Roadmap GenerationAutomatically highlights gaps to build your prioritized operational backlog.

The 10 Core Practices

The CR-CMM workbook is structured around ten core practices that map the operational lifecycle of cyber resilience capabilities.

Explore the full model
Practice 01

Criticality Analysis

Asset prioritization and business impact assessment.

Practice 02

Situational Awareness

Threat landscape monitoring and intelligence.

Practice 03

Threat Informed Defense

Intelligence-driven security controls.

Practice 04

Defensible Architecture

Security-by-design system architecture.

Practice 05

Crisis Management

Incident response and crisis coordination.

Practice 06

Scenario Simulation

Realistic cyber attack simulations.

Practice 07

Contingency Testing

Backup and recovery validation.

Practice 08

System Testing

Security control validation.

Practice 09

Security Testing

Adversarial security validation and penetration testing.

Practice 10

Cyber Recovery

Post-incident recovery operations.

Endorsed by resilience leaders.

The CR-CMM already carries strong community endorsement from leaders shaping cyber resilience practice.

Community endorsement

The Cyber Resilience Capability Maturity Model (CR-CMM) is a framework that enables organizations to evaluate their cybersecurity posture and determine areas for improvement. It offers a structured method for strengthening resilience and ensuring security practices remain aligned with changing threats and business requirements.

Jimmy Sanders

President, ISSA International

Information Systems Security Association - ISSA International

Community endorsement

In the modern world of complex cyber-physical systems, the focus has shifted from stove piped cybersecurity activities to building and deploying systems that are resilient. System resilience requires a multidimensional protection strategy that includes penetration resistant architectures, damage limiting operations, and cyber resiliency. The Cyber Resilience Capability Maturity Model (CR-CMM) is a framework that helps organizations understand their cyber resiliency posture and take specific actions to make meaningful improvements that support mission and business objectives.

Ron Ross

CEO RONROSSECURE, NIST-retired

RONROSSECURE

How the assessment works

A structured progression designed to keep the room focused, objective, and moving toward actionable decisions.

1

Prepare

Gather key stakeholders from security, IT, and risk.

2

Assess

Work through evidence-based checkpoints live.

3

Map

Generate the current-state maturity heatmap.

4

Prioritize

Identify critical gaps and build the backlog.

5

Define

Establish a realistic roadmap to Target Zero.

Outputs built for immediate action.

Walk out of the working session with tangible artifacts that leadership can understand and engineers can execute.

Heatmapped Profile

A visual matrix showing exactly where your capabilities sit across the 5 maturity levels.

Ranked Backlog

Identified gaps translated into specific, prioritized capability improvements.

Strategic Roadmap

A sequenced plan to move from current state to your required target maturity.

Repeatable Benchmark

A standardized foundation allowing you to track progress over time and demonstrate ROI.

Want something quicker? Try the 5 minute version first.

Start with the quick online assessment to get an immediate baseline. When you are ready to go deeper, unlock the XLSX workbook for the full offline assessment.

Start the 5 minute assessment