When an organization describes its IAM program as “level 2, moving to level 3,” the vocabulary is usually Gartner's. The Gartner IAM Program Maturity Model, most recently updated in September 2025, is the closest thing the industry has to a common reference for identity program maturity. Boards recognize it, consultants anchor roadmaps to it, and RFPs cite it.
It is also a subscription product. The detailed rubric, the assessment worksheets, and the supporting research sit behind a Gartner license, which means most of the people asked to place their organization on its scale have never read the model itself. This article covers what the model is, what it does well, where it stops, and how to get a comparable measurement if you do not have Gartner access.
What the Model Is
Gartner's model describes IAM maturity in five levels, from an improvised program to a continuously optimized one. The level names follow the lineage most maturity frameworks share, running from Initial through Developing, Defined, and Managed to Optimized. That lineage traces to CMMI, the software-engineering maturity framework whose staged levels shaped nearly every security maturity model in use today.
Two properties distinguish the Gartner model from a control checklist. First, it is a program model: it evaluates strategy, governance, process discipline, organizational structure, and technology adoption together, rather than auditing individual controls. Second, it is descriptive rather than computational. It characterizes what a level 2 program looks like; it does not prescribe a formula that turns evidence into a score. Placement on the scale is a judgment, typically made in a workshop or by an advisory analyst.
What It Is Good For
The model's value is real, and it is mostly linguistic. A shared five-level vocabulary lets a CISO tell a board “we are a 2 and the plan gets us to 3” without a methodology seminar. The Gartner name carries weight in exactly the rooms where IAM programs compete for budget, and anchoring a roadmap to an analyst framework is often what gets that roadmap approved.
The program-level lens is also genuinely useful. IAM failures are more often organizational than technical: unclear ownership, no executive sponsor, processes that exist on paper only. A model that forces attention to strategy and operating model, rather than tool inventory, is asking the right category of question. The research base agrees with this framing: SailPoint's Horizons program (375 IAM decision-makers, 2025-2026) evaluates strategy, operating model, and talent alongside technology for the same reason.
Where It Stops in Practice
Four limits show up consistently when organizations try to run their programs on the Gartner model alone.
Access. The rubric is licensed. Practitioners without a subscription work from secondhand summaries, and even inside licensed organizations the model is often known only through a slide someone made from it. A reference few people can read is a weak foundation for a shared measurement.
Granularity. A program-level judgment tells you where you are. It does not tell you which of the dozens of underlying capabilities is holding you there, or which investment moves the number. Translating “we are a 2” into next quarter's work still requires a control-level assessment the model does not provide.
No empirical benchmark. The model is a rubric, not a dataset. When a client asks how they compare with their industry, the answer rests on analyst judgment, not on aggregated assessment results. Independent research such as SailPoint's Horizons and Simeio's State of Identity publishes population data, but that data does not attach to Gartner levels in any systematic way.
No risk weighting or gating. A descriptive rubric has no mechanism to stop strong governance scores from papering over a missing foundational control. A program can present as level 3 on process discipline while workforce MFA coverage is partial, and the model has no arithmetic to force that gap into the headline number.
None of this is a flaw in what Gartner built. It is a mismatch between what a descriptive analyst framework is for and what running a program requires. I wrote about that structural gap across the whole framework landscape in Part 2 of my IDPro Newsletter series.
Mapping Gartner Levels to a Measurable Scale
Organizations that report in Gartner vocabulary internally do not need to abandon it to get a computable score. The AXIS scale was aligned level-for-level with the September 2025 Gartner model precisely so the two can coexist: AXIS level 0 (Absent) corresponds to Gartner's Initial, level 1 (Initial) to Developing, level 2 (Developing) to Defined, level 3 (Established) to Managed, and level 4 (Optimized) to Optimized. The full cross-walk, including CMMI and NIST CSF tiers, is published on the methodology page.
The difference is in how the number is produced. AXIS scores 37 control-level questions across nine domains, weights them by breach impact, applies a cap when foundational controls are missing, and computes the result deterministically, so the same answers produce the same score for anyone. The output reads in the same five levels a Gartner-literate audience already understands, but it arrives with a domain-by-domain breakdown and an industry benchmark behind it. For what each level looks like in practice, see The IAM Maturity Model, Explained.
Common Questions
Is the Gartner IAM maturity model free? No. The model and its supporting research require a Gartner subscription. Public summaries exist, but the rubric itself is licensed content, which is why this article describes its structure rather than reproducing it.
Do auditors or regulators require it? No. No major regulation or audit framework mandates any specific maturity model. What auditors want is evidence that controls exist and operate; what boards want is a defensible number and a trend. Any consistent, well-documented instrument can serve both.
Can I self-assess against the Gartner model? Without a license, only approximately, and approximation defeats the purpose of a shared scale. A practical path is to run a free, deterministic assessment whose levels map to Gartner's, keep the Gartner vocabulary for reporting, and keep the control-level detail for planning.
AXIS is free to use. Get a maturity score that reports in the same five levels, backed by a domain breakdown and an industry benchmark.
Start AssessmentSources
- Gartner, “IAM Program Maturity Model” (September 2025, subscription required)
- CMMI Institute, “CMMI V2.0” staged representation
- SailPoint, “The Horizons of Identity Security 2025-2026” (375 IAM decision-makers)
- Simeio, “State of Identity 2024”
- Ganesh, “We Still Don't Have a Standard Way to Measure IAM Maturity,” IDPro Newsletter, Parts 1-3 (2026)
Gartner is a registered trademark of Gartner, Inc. AXIS is not affiliated with or endorsed by Gartner. References to the Gartner model are descriptive.