Skip to main content

Setting and Editing a Finding's Maturity Level

Learn how a fixed finding's maturity level is set — automatically or manually — and how to change it afterward in the Cye Exposure Management Platform.

Overview

When a finding is marked as fixed in the Cye Exposure Management Platform, its maturity level is set — automatically if the finding has linked remediation assets, or by you if it doesn't. Either way, the level can be adjusted afterward if you have the right permissions. This article explains both paths and the permissions required to edit.


Who Can Edit

To edit the maturity level of a finding, the user must be:

  • A Cye platform administrator, or

  • An engagement-level editor with the Findings & Graph initiator permission


Setting the Maturity Level When You Fix a Finding

If the Finding Has Remediation Assets

The maturity level is calculated automatically from the status of the finding's linked remediation assets — no manual selection is needed at fix time. The Fixed Finding dialog shows an explanatory note instead of a level dropdown, since the value is derived from remediation progress. You can still override the calculated value afterward — see Editing the Maturity Level Later below.


If the Finding Has No Remediation Assets

  1. Fix the finding

    • Open the finding to mark as fixed

    • Click Fix

  2. Review the Fixed Finding Dialog

    • A dialog appears to confirm the fix

    • The maturity level will be pre-filled with the default value of 3

  3. Adjust if needed

    • Use the dropdown to select a different maturity level (1–5)

    • Choose a score that reflects the actual improvements made


Editing the Maturity Level Later

  1. Open the finding

    • Navigate to the Findings page

    • Select the finding to edit

  2. Open the Standards tab:

    • In the right-hand pane, click the Standards tab:

    • This shows any NIST subcategory assignments

  3. Edit the Maturity Level

    • Hover over the Maturity score field

    • Click the pencil icon to enter edit mode:

    • Select a new maturity level from the dropdown:

This action can only be performed on findings that are already fixed.


Important Notes

  • If a finding is linked to multiple subcategories, the new maturity level will apply to all of them

  • Editing the maturity score affects the subcategory's contribution to the overall maturity assessment

  • All changes are logged in the History tab


Wrap-up / Next Steps

Fine-tuning the maturity level of fixed findings — whether it was set automatically from remediation progress, chosen at fix time, or adjusted later — ensures the assessment reflects meaningful improvements. Be sure to have the right permissions and consider the impact across all linked subcategories. For how remediation progress drives the automatic calculation, see Understanding Maturity: How Progress Drives Your Score.

Did this answer your question?