From Maturity Models to Ground Truth: Reconciling Cybersecurity Capacity Frameworks with Household-Level Governance Realities in the Global South
National cybersecurity and digital-governance capacity frameworks, most prominently the Cybersecurity Capacity Maturity Model for Nations (CMM), shape hundreds of millions of dollars in donor-funded governance investments across the Global South. Yet a persistent, under-theorised gap remains between state-level institutional maturity and the governance actually experienced by end-users. We term this the last-mile governance gap: the structural space between what a maturity assessment can see - laws, agencies, standards, awareness campaigns - and what a household living under that formal architecture can access, understand, or enforce. Drawing on a dual vantage point combining CMM assessment experience with peer-reviewed empirical fieldwork on smart-home privacy governance in Jordan, corroborated against studies from Kenya and China, we identify four mechanisms by which national capacity fails to reach the household: legibility, intra-household power distribution, accessibility of redress, and infrastructure-affordability constraints. We map these mechanisms explicitly onto the CMM's five dimensions, propose four concrete, low-cost last-mile indicators pilotable within existing CMM deployments, and outline a staged adoption roadmap with responses to anticipated objections. With AI-enabled devices entering homes across the Global South faster than institutional capacity can adapt, the stakes are rising: this dynamic risks converting a measurable maturity gap into an invisible one. We conclude with actionable implications for the GCSCC, the ITU, the World Bank, and other institutions relying on maturity scores to prioritize investment.