Cybersecurity maturity varies widely across the federal government's Sector Risk Management Agencies (SRMAs), creating inconsistent protection for the critical infrastructure sectors they oversee. This paper proposes a new framework for the Office of the National Cyber Director (ONCD) to annually evaluate SRMA cybersecurity capabilities on a 1-to-5 maturity scale, assessing domain expertise, policies, risk assessment, incident response, and cross-sector coordination, with particular attention to operational technology (OT) environments.
The model would give federal officials a consistent benchmark for identifying capability gaps, guiding cybersecurity investment, and improving coordination between government and industry, ultimately strengthening the resilience of the nation's critical infrastructure.

