EDIH, EEN, Interreg: the platform for European programmes.Find out more

Cyber Resilience Maturity of Public Sector Institutions

Your institution’s ability to keep serving under attack, measured then turned into a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Cyber Resilience Maturity of Public Sector Institutions

Resilience governance and accountabilityN1 → N5
Identification of essential servicesN1 → N5
Risk and technical scope controlN1 → N5
Protection and digital hygieneN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Resilience governance and accountability6484
Identification of essential services5379
Risk and technical scope control6182
Protection and digital hygiene3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • CNES
  • Docaposte
  • Cetim
  • Aerospace Valley
  • Pôle SCS
  • Cap'Tronic

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Public sector cyber resilience framework (NIS 2, ANSSI frameworks, ISO 22301) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism, one level, the level above, and the action that links the two, that turns a finding into a trajectory.

Is the ability to restore essential services from backups proven?

  1. N1

    No documented restore test. Recovery capability rests on the assumption that backups work.

  2. N2

    Restores are carried out occasionally, prompted by incidents or one off requests, with no defined scope or report.

  3. N3

    A restore test is planned and documented on essential service applications, with a measured recovery timeframe.

  4. N4

    Tests cover a full rebuild scenario from isolated backups, with the business teams involved and timeframes compared against set targets.

  5. N5

    The arrangement is reassessed after every exercise and every architecture change, and timeframe gaps trigger tracked, followed up actions.

Action to move from level 2 to level 3

Select the two applications most critical to citizens, schedule a full restore on a test environment at the next security committee, measure the timeframe achieved and compare it against the stated recovery target.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurement

What this framework covers

Public sector cyber resilience is defined across several overlapping texts: the NIS 2 directive, which places public administrations among the entities in scope, the ANSSI frameworks on accreditation and security of state information systems, the business continuity principles of ISO 22301, and the obligations specific to citizens’ data. What is assessed here is not technical protection alone: it is the ability of a local authority, hospital, ministry or public operator to keep essential services running during an incident, report it within the required timeframe, and return to a controlled operating state.

In practice, steering this is difficult for structural reasons. The information system is often legacy, spread across autonomous business departments and long-standing suppliers. A few concrete questions: do you know which services to citizens must restart first, and in what order. Have your backups actually been restored, on a full scenario, or only tested in isolation. Who decides to shut down a business application on a Sunday, and could that person be reached during the last exercise.

One point of context is worth making: the transposition of NIS 2 significantly widens the scope of public entities concerned and introduces a multi-stage incident reporting chain, with responsibility resting on the governing body. Many institutions began by mapping their obligations without addressing the operational question that follows: does their crisis arrangement work on a school holiday, when the IT department is reduced and the elected official or chief executive has to communicate.

A common confusion is worth clearing up: a compliance audit concludes with compliant or non-compliant, requirement by requirement. A maturity assessment answers a different question: what level of control does each practice sit at, and what concrete action moves it up a level. An institution can be compliant on paper and unable to restore its civil registry within 48 hours. The maturity scale makes this gap visible and turns it into a costed action plan, with cost, timeframe and expected effect on the score.

In Datamensio, the framework is ready to use and remains yours. You adjust the themes, questions and level wording to your status, size and essential services. The AI refines the levels using the CMMI method, or builds a version from your own documents: continuity plan, risk analysis, exercise reports.

Reference standard: Public sector cyber resilience framework (NIS 2, ANSSI frameworks, ISO 22301)

The themes assessed

  • Resilience governance and accountability

    Sponsorship by senior management or the executive, roles and backup arrangements, coordination between business, IT and communications, resources allocated.

  • Identification of essential services

    Inventory of services delivered to citizens, criticality, recovery timeframes and acceptable data loss, application and human dependencies.

  • Risk and technical scope control

    Information system mapping, legacy asset management, up to date risk analysis, accreditation of sensitive systems.

  • Protection and digital hygiene

    Privileged access management, network segmentation, patch management, endpoint and remote access security.

  • Detection and monitoring

    Logging, monitoring coverage, detection capability outside office hours, use of a shared or outsourced service.

  • Crisis management and public service continuity

    Activatable crisis arrangement, degraded operating modes, paper based procedures, decision chain and on call duty.

  • Backups and rebuild capability

    Backup isolation and immutability, coverage scope, full restore testing, ability to rebuild an environment from scratch.

  • Incident reporting and relations with authorities

    Points of contact, notification timeframes and stages, informing citizens, coordination with the relevant authorities and partners.

  • Supply chain and procurement

    Security requirements in public procurement, supplier recovery commitments, reversibility, oversight of hosting providers and business software vendors.

  • Exercises, lessons learned and progression

    Frequency and realism of exercises, involvement of business teams and elected officials, tracking of corrective actions, comparison of assessments over time.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Does this assessment deliver certification or accreditation?

No. Datamensio measures the maturity of your practices and produces the associated action plan. Accreditation of a system or certification against a standard is the remit of an authority or accredited body. The assessment prepares for these steps and documents the starting point.

How does this differ from a NIS 2 compliance audit?

An audit checks for the presence of requirements and concludes with a gap or a pass. The assessment places each practice on a progressive scale and points to the action that raises it a level. The two complement each other: the assessment builds the trajectory, the audit validates the state reached.

How long does the assessment take?

A self assessment run by the security officer takes one working session. In collaborative mode, with IT, business departments and continuity teams involved, allow one to two weeks, most of the time spent gathering and reconciling answers.

Can the framework be adapted to a small local authority?

Yes. You remove themes out of scope, reword the questions and adjust the levels. The AI proposes a coherent version based on your status and headcount, or builds on your existing documents as a base. The framework stays under your control.

Can several entities be compared with each other?

Yes. Applying the same framework across several business units, facilities or councils within a group allows internal benchmarking and comparison with previous assessments. A cross cutting roadmap then consolidates the action plans from several assessments.

How is the action plan costed?

The gap between the score achieved and the target generates the actions to take. The service catalogue matches a solution to each action, with its cost, timeframe and expected effect on the score. The AI groups all of this into a prioritised roadmap.

Where is the data hosted?

In France, with OVH, backed up at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European offerings.

Take your first measurement