top of page

September 25, 2025

Sector Risk Management Agency Maturity Model

Cybersecurity maturity varies widely across the federal government's Sector Risk Management Agencies (SRMAs), creating inconsistent protection for the critical infrastructure sectors they oversee. This paper proposes a new framework for the Office of the National Cyber Director (ONCD) to annually evaluate SRMA cybersecurity capabilities on a 1-to-5 maturity scale, assessing domain expertise, policies, risk assessment, incident response, and cross-sector coordination, with particular attention to operational technology (OT) environments.


The model would give federal officials a consistent benchmark for identifying capability gaps, guiding cybersecurity investment, and improving coordination between government and industry, ultimately strengthening the resilience of the nation's critical infrastructure.

bottom of page