Skip to content

Identity

The IAM Maturity Checklist: Where Does Your Organisation Actually Stand?

ITTCsec Security Engineering Team · 5 September 2026 · 12 min read

Most organisations can't answer "how mature is our IAM?" with anything more precise than a shrug. This checklist exists to replace the shrug with a number, not a certification, and not a score to present to an auditor, but a private, honest snapshot of where 15 real control areas actually stand today, so you know which two or three to fix first.

How to use this checklist

Score each of the 15 areas below from 1 to 4, using the "what level 1 looks like" and "what level 4 looks like" columns as anchors. Most organisations will land somewhere in between, and that's the point. Be honest rather than aspirational: score what's actually running today, not what's in a project plan for next quarter.

  • 1: Ad hoc. No defined process; it happens when someone remembers.
  • 2: Managed. A process exists but is manual, inconsistent, or partially followed.
  • 3: Governed. Defined, mostly automated, with clear ownership.
  • 4: Optimized. Automated, monitored, and reviewed on a real cadence.

The 15 areas

AreaLevel 1 looks likeLevel 4 looks likeYour score
Identity inventoryNo single list of who/what has an identityOne authoritative source covering human and machine identities / 4
Joiner/mover/leaverManual, ad hoc, depends on someone rememberingAutomated provisioning/deprovisioning tied to HR/system-of-record events / 4
MFAOptional or partial rolloutEnforced everywhere feasible, phishing-resistant where it matters most / 4
Conditional AccessNo policies, or one blanket rule for everyoneRisk-based policies driven by device, location and signal / 4
RBACAccess granted ad hoc, by requestRole-based, reviewed, tied to job function / 4
PIM/PAMStanding admin rights are the defaultTime-bound, justified, logged elevation for privileged access / 4
SSOMultiple disconnected credential silosSingle identity provider federated across the estate / 4
Identity governanceNo formal review process existsScheduled access reviews with clear ownership and sign-off / 4
Privileged identitiesNot inventoried separately from regular accountsSeparately inventoried, monitored, and held to tighter controls / 4
Service accountsCreated ad hoc, never reviewed or decommissionedInventoried, owned, credential-rotated, reviewed like any other identity / 4
Access reviewsNever happen, or only after an incidentRecurring, evidenced, and actually change access when needed / 4
Logging/monitoringSign-in logs exist but nobody looks at themCentralised, alerting on anomalous auth patterns / 4
Emergency accessNo break-glass process, or an undocumented oneDocumented break-glass accounts, tested, tightly monitored / 4
Third-party accessContractors/vendors get standing accounts indefinitelyTime-bound, scoped, reviewed on the same cadence as employees / 4
Zero Trust identityTrust is implicit once you're on the networkEvery access request verified on identity, device and context / 4

On Microsoft-stack environments specifically, Conditional Access, PIM and identity governance largely mean "Microsoft Entra ID, configured properly rather than left on defaults." The mechanisms already exist in most E3/E5 licensing, which is exactly why under-configuration, not missing tooling, is the most common finding.

Scoring your organisation

Add up all 15 scores (range: 15 to 60) as a rough directional signal, not a certification:

  • 15 to 26: Foundational gaps. Basic identity hygiene isn't in place yet. Start with identity inventory and joiner/mover/leaver: everything else depends on those two being solid.
  • 27 to 41: Developing. Core controls exist but aren't consistently governed. MFA and Conditional Access are usually further along than access reviews and service-account hygiene at this stage.
  • 42 to 52: Governed. Most areas have real process and ownership. The gap is usually monitoring and emergency-access testing: the areas that only get noticed when they fail.
  • 53 to 60: Optimized. Genuinely mature. The remaining work is usually keeping pace as the organisation grows, not building anything new.

What a low score in a specific area actually means

A low score on joiner/mover/leaver or service accounts is the single most common real-world finding, not because either is technically hard, but because neither has an obvious owner until something goes wrong (a departing employee's access still active weeks later; a five-year-old service account with no one left who remembers what it does). A low score on Zero Trust identity is normal even in otherwise mature environments. It's an architecture to work toward, not a single setting to flip.

A note on the framework

The four-level structure here follows the shape of established maturity models (NIST's digital identity guidance and CISA's Zero Trust Maturity Model, both linked below) applied specifically to the 15 areas that come up most often in real IAM assessments. It isn't a substitute for either, and organisations pursuing a specific certification or regulatory framework (ISO 27001, NIS2) should score against that framework's own criteria as well.

Scored mostly 1s and 2s? That's a normal starting point, not a crisis. See our Identity & Access Management service for how we help organisations move through exactly this, starting with whichever two or three areas carry the most real risk for your environment.

Want help applying this to your environment?