If you've ever tried to report your IAM program's progress to a board, you've probably hit the same wall: which maturity model do you use? And once you pick one, how do you know if your score actually means anything?
The short answer is you don't. Despite multiple published frameworks, IAM maturity measurement remains fragmented, incompatible, and largely unbenchmarked.
The Stagnant State of IAM Measurement
Five independent research sources show that 60-70% of organizations remain stuck at early-to-mid stages of IAM maturity. Yet we still don't have a standard way to measure progress or compare results across organizations. The frameworks exist, CMMI, Gartner's IAM Program Maturity Model, SailPoint's Horizons framework, CISA's Zero Trust Maturity Model, and vendor-specific models from Okta, Auth0, and WSO2, but they're mutually incompatible.
If you assess your program using SailPoint's five-horizon model, you can't compare your results to a peer who used Gartner's six-dimension framework. The scales differ. The definitions differ. The weighting logic differs. Change consultants, and you're starting from scratch.
Key Findings
CMMI provides structure but no IAM-specific guidance. The Capability Maturity Model Integration, maintained by ISACA, offers a proven five-level framework (Initial, Managed, Defined, Quantitatively Managed, Optimizing) with staged representation that prevents organizations from skipping foundational capabilities. But it's domain-agnostic. It won't tell you what IAM-specific capabilities to measure, how to weight them, or what constitutes a reasonable benchmark for your industry.
Gartner's model is comprehensive but paywalled and unbenchmarked. Gartner published an IAM Program Maturity Model in September 2025 that defines six dimensions across five levels. It's probably the most authoritative vendor-neutral reference available. But it's behind a paywall, and Gartner doesn't publish empirical data showing where organizations actually fall on the scale. You can assess yourself against the definitions, but you can't compare yourself to peers.
SailPoint publishes benchmark data but faces vendor objectivity questions. SailPoint's Horizons framework is the only model that publishes actual empirical data. It uses a clustering algorithm to assign organizations to five maturity levels based on annual surveys, breaks results out by industry and geography, and explicitly incorporates capability prerequisites. The 2025-2026 edition surveyed 375 respondents. The limitation: SailPoint sells identity governance software, so the recommended path to higher maturity runs through capabilities the vendor provides.
CISA's Zero Trust model covers identity but not IAM broadly. The Cybersecurity and Infrastructure Security Agency published a Zero Trust Maturity Model with an identity pillar that includes explicit maturity levels and cross-pillar dependencies. It's publicly available and government-backed. But it's scoped to zero trust architecture, not IAM as a whole. It doesn't cover Identity Governance and Administration, customer identity, or the organizational dimensions of an IAM program.
Vendor-specific models define levels but don't populate them with data. Okta published a four-stage CIAM maturity curve. Auth0 published an Identity Maturity Framework with six assessment dimensions. WSO2 published a five-level CIAM maturity model. None publishes empirical data about where organizations actually fall on their respective scales. Gartner's 2025 research found that over 50% of organizations still use homegrown or no CIAM solution at all, yet the CIAM measurement gap remains unfilled.
What This Means for Your Team
You're measuring progress in a vacuum. When you report IAM maturity to leadership, you're describing your position on a scale that has no external reference points. You can track year-over-year improvement, but only if you use the same assessment framework each time. You can't answer the question every CISO wants answered: "How do we compare to our peers?"
The lack of standardization creates three specific problems:
Consultant churn resets measurement. If your organization changes IAM consultants or advisors, you'll likely restart the maturity assessment process using a different framework. Your historical trend data becomes incomparable.
Vendor pitches skew perception. When a vendor presents their maturity model, they're framing advanced maturity in terms of their product capabilities. You're not getting a neutral assessment, you're getting a sales qualification tool.
Budget justification becomes subjective. Without benchmark data, you can't make the argument that "organizations at our maturity level typically invest X% of IT budget in IAM" or "moving from level 3 to level 4 requires these specific capabilities." You're left making qualitative arguments instead of data-driven ones.
Action Items for Your Team
1. Document which framework you're using and stick with it. Pick one maturity model and use it consistently for at least three years. If you're already using one, don't switch unless you have a compelling reason. Year-over-year trend data within a single framework is more valuable than a one-time assessment using the "best" framework.
2. Demand benchmark data from your assessor. If you're working with a consultant or vendor that uses a proprietary maturity model, ask them directly: "Where do organizations in our industry typically score on this scale? What's the distribution?" If they can't answer, their model is a rubric, not a benchmark.
3. Separate foundational capabilities from advanced features. Use CMMI's staged representation principle: you can't claim high maturity if you have gaps in foundational controls. Before you invest in advanced capabilities like Just-in-Time Elevation or Risk-Based Authentication, verify that you've implemented baseline controls: Reconciliation, Certification Campaigns, Privileged Access Management session recording, and Entitlement Catalog maintenance.
4. Track CIAM maturity separately from workforce IAM. Don't try to combine customer identity and workforce identity into a single maturity score. They have different risk profiles, different regulatory drivers, and different vendor landscapes. If you're running a CIAM program, use one of the CIAM-specific models (Okta's four-stage curve, Auth0's six-dimension framework, or WSO2's five-level model) even though they lack benchmark data. At minimum, you'll have consistent definitions.
5. Contribute to open frameworks if they emerge. If an open-source or community-driven IAM maturity framework gains traction, participate. The only way the industry gets reliable benchmark data is if enough organizations contribute their assessments to a shared data pool.
By taking these steps, your team can better navigate the fragmented IAM maturity landscape and work towards more standardized, comparable measurements.



