The TMI Methodology
Last updated: July 27, 2026
The Technology Maturity Index (TMI) is the assessment framework at the core of vCIO Blueprint. It gives a vCIO a structured, repeatable way to evaluate a client organization’s technology maturity, express the result as a single defensible score, and turn low-scoring areas into a prioritized roadmap. This page describes how the index is structured and scored so you can explain it to your clients with confidence.
The scale
Every rating in a TMI assessment uses the same 1–5 maturity scale:
- 5 — Mature / Optimized
- 4 — Strong
- 3 — Acceptable
- 2 — Weak
- 1 — Poor / High Risk
Scores roll up to a letter grade clients recognize instantly: A at 4.5 and above, B at 3.5, C at 2.5, D at 1.5, and F below that. Scores of 1–2 surface as high-priority gaps, 3 as medium, and 4–5 as low.
The structure
The index covers five pillars, broken into 19 subdomains assessed through 113 questions:
- Foundation — EA & IT Governance
- Infrastructure & Cloud
- Applications & Integration
- Data & Information Architecture
- Security & Compliance
How scoring works
Assessments run in two modes: a quick subdomain-level pass for a first baseline in a single session, or a full question-level assessment for depth. Items that don’t apply to a client are excluded from the math entirely rather than counted as zero, so a small business isn’t penalized for controls it has no reason to run. Scores roll up from subdomain to pillar to a single overall TMI.
Framework alignment
Each subdomain is cross-mapped to established frameworks, including NIST CSF, ISO 27001, SOC 2, NIST 800-53, CMMC, CIS Controls, PCI-DSS, and HIPAA. That means a TMI finding can be translated into the compliance language a client’s auditor, insurer, or regulator expects, without running a separate assessment per framework.
What we don’t publish
The subdomain-level structure, the individual assessment questions, and their scoring rubrics are proprietary and available inside the product. If you’d like to see the full framework in action, request a demo.