Back to Insights
Guide

The IAM Maturity Model, Explained

By Vidyaa Ganesh · Published

An IAM maturity model is a structured way to measure how well an organization manages identities and access. Not which tools it owns, but whether the underlying capabilities work: whether access is provisioned and revoked on time, whether privileged accounts are controlled, whether authentication holds up against modern attacks, and whether anyone can prove any of this to an auditor.

Organizations use maturity models for three things. To find gaps before an attacker or an auditor does. To prioritize investment when everything looks urgent. And to communicate posture to a board or a regulator in terms that survive scrutiny.

The concept is simple. The practice is not, because there is no industry-standard IAM maturity model. What exists is a patchwork of analyst frameworks, vendor research programs, and consultant scorecards that produce scores no one can compare. I wrote a three-part series for the IDPro Newsletter on that problem. This guide covers the practical side: what a maturity model measures, what the levels mean, and how to run an assessment that produces a number you can defend.

The Five Maturity Levels

Most IAM maturity models, whatever their origin, describe a progression from improvised to engineered. AXIS scores every capability on a 0 to 4 scale. The labels differ across frameworks, but the underlying stages are recognizable in all of them.

Level 0: Absent. The capability does not exist, or exists only as individual effort. Access is granted by whoever gets the ticket, shared admin passwords live in a spreadsheet, and nobody can produce a list of who has access to what. Most organizations are past level 0 on authentication and well within it somewhere else, often in privileged access or governance.

Level 1: Initial. The capability exists but is reactive and manual. Joiners get accounts because someone files a ticket; leavers keep access until someone remembers. There may be an MFA rollout, a PAM tool, or an access review, but each depends on individual diligence rather than process.

Level 2: Developing. Processes are defined and repeatable. Provisioning follows documented rules, reviews happen on a schedule, and privileged access goes through a broker for the systems that matter most. Coverage is the weak point: the process works where it has been deployed, and significant estate remains outside it. The published research consistently places the majority of organizations at this stage or below.

Level 3: Established. The capability is managed and proactive. Provisioning and deprovisioning are automated from an authoritative source, access reviews produce actual revocations rather than rubber stamps, privileged sessions are recorded, and coverage is measured and reported. For most organizations and most capabilities, level 3 is the right target.

Level 4: Optimized. The capability improves continuously. Access decisions use risk signals, standing privilege is being eliminated rather than managed, and identity telemetry feeds detection and response. Level 4 across the board is rare and, for many organizations, not worth the cost. In the IDSA's 2024 survey, only 8% of 521 security professionals placed their organization at the highest maturity level.

One Score Is Not Enough: The Nine Domains

A single maturity number hides more than it reveals. An organization can run a genuinely strong single sign-on program while its privileged access management is a shared spreadsheet. Averaging those into one score produces a comfortable middle number that describes neither.

A credible model decomposes the problem. AXIS measures nine domains: identity governance and administration (IGA), privileged access management (PAM), workforce authentication, cloud and SaaS IAM, identity security and posture, operating model and governance, and three customer identity domains covering CIAM itself and its intersections with data security and privileged access. Workforce-only assessments cover the first six; customer-facing organizations add the CIAM domains.

Domain decomposition is what makes a maturity score actionable. “We are a 2.1” starts no useful conversation. “We are a 3 on authentication and a 1 on privileged access” starts the right one, because it says where the next dollar should go.

Foundational Controls Gate Everything Else

Some controls are prerequisites. An organization that has not deployed MFA for its workforce, or cannot inventory its privileged accounts, does not have a maturity problem in one domain. It has a ceiling on the entire program, because every downstream control assumes the foundation holds. Session recording means little when attackers can log in with a stolen password.

AXIS handles this with foundational controls: a subset of the assessment questions are designated as gating. If a foundational control is weak, the overall score is capped no matter how strong everything else looks. The cap loosens as the foundations improve and lifts entirely once they are established.

This is the single most common source of disagreement between a structured assessment and an organization's self-image. It is also the point of doing the assessment. A model that lets excellent governance paper over missing MFA is producing a number for a slide, not a measurement.

Not All Gaps Weigh the Same

The second property a defensible model needs is risk weighting. A gap in privileged access management is not equivalent to a gap in access request usability, and a scoring formula that treats them equally will misdirect investment.

In the AXIS scoring model, every question carries an impact weight, with breach-critical controls weighted substantially heavier than enhancement capabilities, and every domain carries a weight reflecting its contribution to identity risk. The approach is documented in the methodology and the scoring is deterministic: the same answers produce the same score, every time, for anyone. That property matters more than it sounds. A score that depends on who ran the assessment cannot be tracked over time or compared against anything.

Where Organizations Actually Stand

Whatever model you use, it helps to know what the population looks like. Independent research efforts using different scales and different samples converge on the same picture: roughly 60 to 70% of organizations sit at early-to-mid maturity.

SailPoint's Horizons research (375 IAM decision-makers, 2025-2026) places over 40% of organizations at its lowest maturity horizon and roughly 63% in the bottom two. The Ponemon Institute and GuidePoint Security (626 IT professionals, 2025) found that only half of respondents rate their IAM tooling as effective, and that 34% still run access reviews from spreadsheets. Simeio's cross-industry research puts average maturity at 2.4 on a five-point scale, with financial services highest at roughly 2.6 and healthcare and public sector trailing.

The practical implication: if a structured assessment places you at a 2, you are ordinary, not negligent. What separates programs is not where they start but whether they can measure movement. AXIS publishes per-industry benchmarks derived from this research and adjusted for organization size and region, so a score lands with context rather than in a vacuum.

The Models in Use Today

If you are evaluating existing frameworks, four families cover most of the territory. Gartner's IAM program maturity model is the analyst reference, five levels across program dimensions, and sits behind a paywall. SailPoint's Horizons is the most data-rich vendor program, built on real survey research, with the obvious caveat that it is run by a vendor with a product to sell. Consultant scorecards, typically CMMI-derived, vary from engagement to engagement, which is precisely the problem. CISA's Zero Trust Maturity Model is free and rigorous but measures zero-trust adoption, of which identity is one pillar, rather than the IAM program itself.

Each is useful. None is a standard, and scores from one cannot be translated into another. I analyzed why in Part 2 of the IDPro series, and what a shared standard would require in Part 3. AXIS is my attempt to build to those design principles: vendor-neutral, domain- decomposed, risk-weighted, gated on foundations, and benchmarked against published research.

How to Run a Maturity Assessment

A useful assessment does not require a twelve-week engagement. It requires honest inputs and a consistent instrument.

Decide the scope first: workforce identity, customer identity, or both. Then involve the people who know the truth. The IAM lead alone will overrate coverage; pairing them with someone from infrastructure or the service desk keeps answers grounded in what is deployed rather than what was purchased. Answer against evidence: if the claim is “automated deprovisioning,” the test is the last leaver's actual exit, not the design document.

Treat the first score as a baseline, not a verdict. Its value is the delta: reassess every six to twelve months, or after any major change such as a merger, a new identity platform, or an incident, and let the trend tell the story. A deterministic instrument makes that trend meaningful, because a change in score reflects a change in the program rather than a change in assessor.

The AXIS assessment covers all nine domains in 37 questions and takes under an hour. Every score is cryptographically signed, so the result can be verified later, and every answer maps to compliance frameworks from SOX to DORA through the framework library. It is free, and no account is required to run it.

Common Questions

Is there an industry-standard IAM maturity model? No. As of 2026, no vendor-neutral standard has been adopted across the industry. Gartner's model is the closest thing to a common reference, and it is proprietary. This is unusual among security disciplines and is the gap the IDPro series examines.

What maturity level should we target? Level 3 in every domain is the right goal for most organizations. Level 4 is worth pursuing where the risk concentrates, typically privileged access and identity threat detection, and is rarely worth the cost everywhere. The worst plan is polishing a strong domain to 4 while a foundational control sits at 1.

How is IAM maturity different from zero trust maturity? Zero trust models such as CISA's measure adoption of an architecture, in which identity is one pillar among five. An IAM maturity model measures the identity program itself, in depth, including governance and operations that zero trust models barely touch. Mature IAM is a prerequisite for zero trust, not a synonym.

AXIS is free to use. Score your organization across all nine domains and see where you stand against your industry benchmark.

Start Assessment

Sources

  • SailPoint, “The Horizons of Identity Security 2025-2026” (375 IAM decision-makers)
  • Ponemon Institute and GuidePoint Security, “The State of IAM Maturity” (2025, 626 IT professionals)
  • IDSA, “2024 Trends in Securing Digital Identities” (521 professionals)
  • Simeio, “State of Identity 2024”
  • Gartner, “IAM Program Maturity Model” (Sept 2025)
  • CISA, “Zero Trust Maturity Model v2.0” (2023)
  • Ganesh, “We Still Don't Have a Standard Way to Measure IAM Maturity,” IDPro Newsletter, Parts 1-3 (2026)