Maturity · Sensitive data protection and advanced cryptography
Your encryption and sensitive data protection practices, measured then turned into a roadmap.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
Maturity · Sensitive data protection and advanced cryptography
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One Datamensio maturity framework, grounded in sensitive data protection and cryptographic management practices (encryption, key management, anonymisation, post-quantum cryptography) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
This mechanism (one level, the level above, and the action that links the two) is what turns an observation into a trajectory.
Is the cryptographic key lifecycle under control, from generation to revocation?
- N1
No key inventory. Keys are generated and stored by project teams, sometimes in code or in configuration files.
- N2
A secrets vault exists and some keys are stored there. Rotation is manual, triggered by an incident or a migration.
- N3
Keys are inventoried and stored in a common vault with separation of duties. Rotation deadlines are defined and generally met.
- N4
Rotation and revocation are automated and logged. Access to production keys is logged and reviewed. Compromise procedures are tested.
- N5
The cryptographic inventory is kept up to date and feeds a migration trajectory, including post-quantum hybridisation, with documented periodic review.
Action to move from L2 to L3
Build the inventory of keys and secrets still outside the vault, assign an owner and a rotation deadline to each, then check these deadlines at the quarterly security committee.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurement
What this framework covers
This framework assesses how an organisation identifies, classifies and protects its sensitive data, and how it manages the cryptographic mechanisms that protect it. It covers data classification, encryption at rest, in transit and in use, key and secrets lifecycle management, anonymisation and pseudonymisation techniques, secure sharing with third parties, and anticipation of cryptographic developments. This is not a technical configuration check, but an assessment of management and governance practices.
In practice, these topics are hard to steer because knowledge is scattered. Encryption decisions sit with infrastructure teams, classification with business teams, keys with administrators who are sometimes external. Three questions are enough to reveal the gap: do you know which databases hold sensitive data, and how long since that inventory was last reviewed? Who can technically access a production key, and is that access logged? What happens if a supplier holds both the encrypted data and the keys?
One point of context matters here. The shift to post-quantum cryptography is underway: security authorities, including ANSSI, recommend hybridising mechanisms and building a cryptographic inventory to prepare for migrations. This moves the topic from a technical register to a transformation programme, with an inventory to build, supplier dependencies to qualify and a multi-year trajectory to fund. Many organisations have become aware of the issue without having started the inventory, which is the prerequisite.
A maturity assessment answers a different question from a compliance audit. An audit concludes with a gap or a compliance finding against a requirement. The assessment places each practice on a progressive scale and states the precise action that moves it up a level: from documented classification to applied classification, from manual key rotation to automated, logged rotation. The result is not a verdict, it is a costed trajectory, comparable across business units and over time.
In Datamensio, the framework is ready to use and editable. The AI adjusts the themes, rephrases questions to match your internal vocabulary, refines the levels along CMMI logic, or builds a variant from your existing security policy and cryptographic standards.
Reference standard: Datamensio maturity framework, grounded in sensitive data protection and cryptographic management practices (encryption, key management, anonymisation, post-quantum cryptography)
The themes assessed
Identification and classification of sensitive data
Inventory of data to protect, sensitivity levels, classification criteria, coverage of repositories and flows, review frequency.
Cryptographic policy and standards
Existence of an internal standard, approved algorithms and key lengths, explicit prohibitions, exceptions, alignment with security authority recommendations.
Encryption at rest and in transit
Coverage of databases, backups, endpoints and removable media, protection of internal and external flows, termination of encrypted sessions, documented exceptions.
Key and secrets management
Generation, storage, separation of duties, rotation, revocation, use of hardware security modules, application secrets management and removal of hardcoded secrets.
Anonymisation and pseudonymisation
Techniques chosen by use case, re-identification risk assessment, test data sets, data used for analysis and model training.
Access control for sensitive data
Entitlements and least privilege, privileged accounts, dynamic masking, access reviews, traceability of consultations.
Third party sharing and sovereignty
Contractual framing of transfers, data and key location, reversibility, customer-supplied encryption, supplier dependencies.
Advanced cryptography and post-quantum readiness
Cryptographic inventory, component agility, hybridisation of mechanisms, use of encryption in use and multi-party computation, migration trajectory.
Monitoring, incidents and data leakage
Detection of abnormal access and exfiltration, procedures in the event of key compromise, restoration tests, notification and lessons learnt.
Skills and ongoing steering
Available cryptographic expertise, awareness among development teams, tracked indicators, periodic review of the framework and progress comparison.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Does this assessment grant a certification?
No. Datamensio measures the maturity of your practices and produces an action plan. No body certifies this framework, which addresses the transformation of your data protection and cryptographic management practices. Results can, however, feed into preparation for an external audit.
How is this different from a technical configuration audit?
A technical audit checks settings at a given point in time: protocol version, key length, an expired certificate. The assessment evaluates the organisation’s ability to sustain these settings over time: who decides, who checks, who corrects. The two complement each other, the assessment provides the trajectory.
How long does the assessment take?
The short version can be completed in a single working session. The full version, run collaboratively with several contributors, takes one to two weeks, most of the time being spent gathering input from infrastructure, development and business teams.
Do you need cryptographic expertise to answer?
The questions address management practices, not implementation detail. A security manager or an architect can answer without difficulty. Some technical questions can be assigned to a dedicated contact, with the AI assistant rephrasing the wording to match the respondent’s profile.
Can the framework be adapted to our context?
Yes. Themes, questions and levels can be edited, and you can add your own. The AI can also build a variant from your security policy or your internal cryptographic standards. You retain full control of the framework.
How can several entities be compared?
Each business unit completes the same assessment, and scores by theme are compared across entities and against previous assessments. A cross-entity roadmap consolidates action plans and groups common actions instead of duplicating them.
Is the post-quantum topic covered?
Yes, as a theme within the framework: cryptographic inventory, component agility, hybridisation of mechanisms and migration trajectory. The assessment establishes your starting point, which is the prerequisite for costing any programme.
Where is the data hosted?
In France, at OVH, with backup at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European solutions.





