Maturity models are a highly simplified (but still useful) view of reality. They are not the same as a detailed audit, gap analysis and/or review, which still serve crucial purposes in cybersecurity.
This model is for Chief Information Security Officer (CISO) and/or cybersecurity managers (and similar roles) to use.
Given the simplicity of the results, and focus on the most critical elements, the audience of the maturity is most likely to be top management.