Most organisations cannot answer a simple question: how secure are we, actually? The honest answer takes a framework, and the frameworks are written for assessors rather than for the people running the systems.
So it gets outsourced. A consultant arrives, runs a workbook, and leaves a PDF — expensive enough that it happens once a year at best, which is not a cadence that matches how fast an estate changes.
The controls themselves are the barrier. NIST CSF 2.0 and ISO 27001:2022 are written in language that assumes you already know the answer, and most of any framework is irrelevant to any given organisation.
And a score on its own changes nothing. Knowing you are at 63% maturity does not tell an IT manager what to do on Monday morning, or which of a hundred gaps is the one worth the next budget cycle.