What Is Your VLAN Segmentation Maturity Score?

What Is Your VLAN Segmentation Maturity Score?

Use this VLAN segmentation maturity assessment to score your network from ad-hoc to optimized and identify your next ISO 27001 action.

LakeRidge Team
July 18, 2026
8 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

Your VLAN segmentation maturity score measures whether your network separation is improvised, repeatable, documented, monitored, or continuously improved. A practical VLAN segmentation maturity assessment lets you score your current state from 1 to 5, identify the evidence an ISO 27001 reviewer will expect, and select the smallest next step that improves control without delaying your enterprise deal.

For ISO 27001, this work supports Annex A control 8.22, Segregation of Networks: “Groups of information services, users and information systems shall be segregated in the organization’s networks.”[1] You do not need an enterprise-sized network team to demonstrate this. You need a defensible design, working enforcement, and records showing that your separation rules are intentional rather than accidental.

Why does a VLAN segmentation maturity assessment beat a binary checklist?

A binary checklist asks whether VLANs exist. That is too weak for a customer security questionnaire or an ISO 27001 audit. A business can truthfully answer “yes” because it has a guest Wi-Fi VLAN, while its employee laptops, production servers, backups, printers, and network administration interfaces can still communicate freely.

Maturity scoring asks better questions: Which systems are separated? Who is allowed across those boundaries? Is the rule enforced on switches, firewalls, wireless networks, and cloud-connected equipment? Can you show an auditor that the configuration was reviewed and approved?

For an SMB owner, the value is prioritization. You may not be able to redesign every subnet before an enterprise prospect finishes due diligence. A network segmentation maturity review helps you distinguish deal-blocking gaps—such as flat access between staff devices and production—from improvements that can be scheduled after certification readiness work, such as automated policy testing.

What do the five maturity levels look like for ISO 27001 control 8.22?

Level 1: Initial — separation is informal

Your network is largely flat, or VLANs were created by an installer without a written purpose. The office router may have separate “guest” and “staff” Wi-Fi names, but employee devices can reach printers, NAS devices, hypervisors, and administrative interfaces by default. Firewall rules are broad, undocumented, or owned by a former IT provider.

At this level, you cannot reliably explain which information services are separated or why. This is a high-risk position when an enterprise buyer asks how production systems are protected from ordinary user devices.

Level 2: Repeatable — basic zones exist

You consistently place common device types into a few zones, such as corporate users, guest Wi-Fi, servers, and voice devices. For example, UniFi or Meraki may use VLAN 10 for staff, VLAN 20 for servers, VLAN 30 for guest access, and VLAN 40 for VoIP. Guest traffic is denied access to internal RFC 1918 networks.

However, rules are applied because “that is how we did it last time,” not because an approved standard exists. Exceptions, such as a staff laptop reaching a server over RDP, are often left permanently open.

Level 3: Defined — the design and rules are documented

You have an approved network segmentation standard that defines each VLAN, its business owner, permitted services, and default access posture. Production services, backups, administration, corporate endpoints, guest devices, and Internet of Things equipment are separated based on risk and business need.

Inter-VLAN traffic crosses a firewall or Layer 3 policy boundary. A realistic example is allowing VLAN 10 staff devices to access a file server in VLAN 20 over TCP/445, while denying staff access to the backup repository VLAN except through the backup service account and approved server address. Changes are recorded in a ticketing system such as Jira, Freshservice, or HaloITSM.

Level 4: Managed — effectiveness is measured and reviewed

You periodically verify that segmentation is working. Firewall logs are reviewed, denied connections are investigated when they affect business operations, and VLAN membership is checked against asset inventory records. Administrative access uses a dedicated management VLAN, such as VLAN 99, rather than being available from every employee laptop.

You can produce evidence: firewall rule exports, switch configuration backups, quarterly access reviews, network diagrams, change tickets, and records of remediation. This is a credible target for most SMBs preparing for ISO 27001 because it shows that control 8.22 is operated, not merely designed.

Level 5: Optimized — segmentation improves through feedback and automation

You use monitoring, configuration management, and lessons from incidents to refine network boundaries. Tools such as Fortinet FortiManager, Cisco Meraki Dashboard, UniFi Network, Microsoft Defender for IoT, or a SIEM identify unexpected cross-VLAN traffic. Policy changes are tested, reviewed, and deployed consistently, with configuration drift detected automatically.

Optimized does not mean buying every security product. It means you can show that segmentation decisions evolve with new services, remote work patterns, acquisitions, and customer requirements.

How can you calculate your VLAN maturity score?

Score each area from 1 to 5 using the closest description below. Add the five scores for a total out of 25. Use evidence, not intent: if a rule is not configured, documented, or verifiable, score the lower level.

Assessment area Score 1: Initial Score 3: Defined Score 5: Optimized Your score
Network inventory and zones No reliable VLAN map; devices join the main network. Diagram identifies staff, server, guest, voice, IoT, backup, and management VLANs. Asset inventory and diagrams are updated through change workflows and reconciled regularly. ___ / 5
Inter-VLAN enforcement Most internal networks can communicate freely. Firewall rules use deny-by-default between zones and permit required ports, such as TCP/443 to an application server. Rules are centrally managed, tested, and monitored for drift and unnecessary access. ___ / 5
Administrative access Switches, firewalls, and servers are administered from ordinary staff networks. Management interfaces are restricted to an admin VLAN or jump host with named administrator accounts. Privileged paths are logged, reviewed, and continuously refined based on access patterns. ___ / 5
Documentation and approval Settings exist only in the network device console or the IT provider’s memory. Each VLAN has a purpose, owner, permitted connections, and approved change records. Documentation is version-controlled, reviewed on a schedule, and linked to risk treatment decisions. ___ / 5
Monitoring and review No one checks whether segmentation rules still work. Firewall logs and rules are reviewed quarterly; exceptions have owners and review dates. Alerts, metrics, and periodic tests identify anomalous east-west traffic and policy failures. ___ / 5

Interpret the result this way: 5–9 is Initial, 10–14 is Repeatable, 15–19 is Defined, 20–23 is Managed, and 24–25 is Optimized. A score of 15 is often the practical minimum for an organization that needs to show an enterprise prospect a coherent ISO 27001 control design; aim for 20 where time and resources allow.

What commonly keeps organizations stuck at each maturity level?

  • Initial: The owner assumes a firewall automatically creates internal separation. It does not if all devices sit on the same subnet or permissive inter-VLAN rules exist.
  • Repeatable: VLANs exist, but there is no documented traffic matrix. Teams create “allow any” rules whenever an application fails, turning logical separation into a label only.
  • Defined: Documentation is stronger than operations. The diagram says backups are isolated, but a broad rule still permits every workstation to reach the backup network.
  • Managed: Reviews produce evidence but not decisions. Logs are collected, yet nobody owns removal of old firewall exceptions, vendor access, or retired systems.
  • Optimized: Automation becomes the goal instead of risk reduction. Avoid adding complex tooling before basic asset ownership, rule review, and change control are reliable.

The most common blocker for a small business is outsourced IT ambiguity. Your managed service provider may operate the firewall, but your organization remains responsible for defining the acceptable separation standard, approving risk-based exceptions, and retaining evidence for ISO 27001.

How can you advance one VLAN maturity level in 90 days?

  1. Days 1–30: Establish the baseline. Export firewall rules, switch VLAN settings, wireless SSID mappings, and DHCP scopes. Create a one-page diagram and list every network zone, its purpose, owner, and the systems it contains. Identify any production, backup, or management system reachable from the general staff VLAN.
  2. Days 31–60: Remove the highest-risk paths. Put guest Wi-Fi, IoT devices, backups, and network management on separate VLANs where feasible. Apply a default-deny policy between sensitive zones, then permit only required traffic. Record each approved rule in a change ticket, including source, destination, port, purpose, owner, and review date.
  3. Days 61–90: Build ISO 27001 evidence. Approve a short segregation-of-networks standard, perform a firewall-rule review, test selected deny rules from a staff device, and retain screenshots or exports. Schedule a quarterly review and assign one internal owner, even if an MSP performs the technical work.

Start by completing the scoring table with your MSP this week, then use the lowest-scoring area as the first item in your ISO 27001 remediation plan.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.