Abstract
This protocol describes a sequential, multi-phase study to develop and validate an AI-Assisted Cyber Maturity Framework for Higher Education Institutions (AICMF-HEI). Existing cybersecurity assessments often inadequately represent the distributed governance, mixed missions, transient populations, research environments, third-party dependencies, and resource diversity of higher education institutions. Phase 1 will refine the construct and candidate domains through evidence synthesis. Phase 2 will use semi-structured interviews with higher-education and cybersecurity stakeholders. Phase 3 will establish content validity and consensus through a modified Delphi study. Phase 4 will develop and cognitively test an assessment instrument. Phase 5 will examine reliability and exploratory factor structure. Phase 6 will conduct confirmatory validation using an independent multi-institutional sample and evaluate inter-rater agreement, convergent and discriminant validity, measurement invariance, usability, and decision usefulness. Phase 7 will evaluate a bounded AI-assistance prototype for evidence retrieval, mapping, contradiction detection, and rationale drafting under human oversight. The protocol prespecifies governance, ethics, data protection, stopping criteria, and transparent reporting. It does not report empirical results. The intended outcome is an evidence-centred and managerially useful framework rather than an autonomous certification system.



![Author ORCID: We display the ORCID iD icon alongside authors names on our website to acknowledge that the ORCiD has been authenticated when entered by the user. To view the users ORCiD record click the icon. [opens in a new tab]](https://www.cambridge.org/engage/assets/public/coe/logo/orcid.png)