Level 1
70%
Your basics are covered
70% overall or better (a grade of C or better)
Level 1 means your firm has the fundamentals in place. You have answered the 56-control assessment honestly, you have hit a passing threshold on the core Pillars, and you can demonstrate that you have taken cybersecurity seriously.
For most small financial firms that are just getting started, Level 1 is the first real goal. It says: we assessed ourselves against a structured standard, and we are not operating blind.
What Level 1 signals to someone looking at your firm:
- You have completed a structured cyber risk assessment.
- Your firm scores at or above the baseline required to earn the credential.
- You have a report to back it up.
This is the level that satisfies the initial "do you have a cyber risk assessment on file?" question from a regulator or an insurer.