By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. How the maturity model works
  2. What the tool doesn't do
  3. Related
  4. What to do with your result
You get

Your stage

Placed on a five-level model from ad hoc to optimised, with what characterises the level above yours.

You get

Per-area scores

Discovery, ownership, credential control and evidence, scored separately so you can see which one is holding the total down.

You get

Three moves

The highest-leverage actions for your specific stage, not a generic maturity roadmap.

Before you start

12 questions, about 4 minutes. Everything runs in your browser. Nothing is transmitted, nothing is stored, and no email is requested at any point. Answer honestly rather than aspirationally, because the output is only as useful as the input and nobody else sees it.

How the maturity model works

The 5-stage model draws on CSA's state-of-NHI-security work, informal NIST CSF v2 alignment, and the practical experience of enterprise CISOs running NHI programmes. The stages are descriptive, not prescriptive:

  • Stage 1, Reactive. No systematic NHI programme. NHIs are discovered when something breaks. Ownership is informal or absent.
  • Stage 2, Ad-hoc. Some discovery has happened, typically a one-off inventory, but it isn't continuous. Basic hygiene exists in silos.
  • Stage 3, Defined. Continuous inventory is in place. Ownership is assigned. Policies exist on paper. Posture is monitored but not fully remediated.
  • Stage 4, Managed. Lifecycle is automated end-to-end for most NHIs. Credentials are short-lived where possible. Third-party integrations are governed.
  • Stage 5, Optimised. Metrics drive improvement. AI-agent and workload-identity patterns are part of the programme, not separate. Board reporting is routine.

What the tool doesn't do

It doesn't recommend specific vendors. It doesn't capture the full richness of any real programme, twelve questions can't. It doesn't substitute for a serious internal assessment. What it does do is give you a defensible external framing and a sharper sense of which dimension is most worth attention next.

For the full maturity model with KPIs and a 12-month roadmap, see NHI management. For the control-level audit, use the OWASP NHI Top 10 self-audit. For exposure to specific known breaches, try the breach readiness score.

Want a second read on your score?

The tools give you a number. A 20-minute call with HumanAudit will tell you which gap to close first, roughly what it costs, and what you can defer with a documented rationale.

What to do with your result

A score is only useful if it changes what you do next. These are the routes we would suggest depending on where you land.

If your result showsDo this next
Below level 2Inventory and ownership first. Tooling will surface problems you cannot yet act on. See the discovery methodology.
Level 2 to 3Credential lifetimes and review execution. The policy template is the fastest route.
Level 3 and aboveBuild versus buy becomes a real question. See the decision guide.

Want a second read on your result?

Twenty minutes with HumanAudit, free and with no obligation. Bring the score and we will tell you which gaps actually matter for your estate and which are noise. If we are not the right answer we will say so on the call.