Identity
The IAM Maturity Checklist: Where Does Your Organisation Actually Stand?
ITTCsec Security Engineering Team · 5 September 2026 · 12 min read
Most organisations can't answer "how mature is our IAM?" with anything more precise than a shrug. This checklist exists to replace the shrug with a number, not a certification, and not a score to present to an auditor, but a private, honest snapshot of where 15 real control areas actually stand today, so you know which two or three to fix first.
How to use this checklist
Score each of the 15 areas below from 1 to 4, using the "what level 1 looks like" and "what level 4 looks like" columns as anchors. Most organisations will land somewhere in between, and that's the point. Be honest rather than aspirational: score what's actually running today, not what's in a project plan for next quarter.
- 1: Ad hoc. No defined process; it happens when someone remembers.
- 2: Managed. A process exists but is manual, inconsistent, or partially followed.
- 3: Governed. Defined, mostly automated, with clear ownership.
- 4: Optimized. Automated, monitored, and reviewed on a real cadence.
The 15 areas
| Area | Level 1 looks like | Level 4 looks like | Your score |
|---|---|---|---|
| Identity inventory | No single list of who/what has an identity | One authoritative source covering human and machine identities | / 4 |
| Joiner/mover/leaver | Manual, ad hoc, depends on someone remembering | Automated provisioning/deprovisioning tied to HR/system-of-record events | / 4 |
| MFA | Optional or partial rollout | Enforced everywhere feasible, phishing-resistant where it matters most | / 4 |
| Conditional Access | No policies, or one blanket rule for everyone | Risk-based policies driven by device, location and signal | / 4 |
| RBAC | Access granted ad hoc, by request | Role-based, reviewed, tied to job function | / 4 |
| PIM/PAM | Standing admin rights are the default | Time-bound, justified, logged elevation for privileged access | / 4 |
| SSO | Multiple disconnected credential silos | Single identity provider federated across the estate | / 4 |
| Identity governance | No formal review process exists | Scheduled access reviews with clear ownership and sign-off | / 4 |
| Privileged identities | Not inventoried separately from regular accounts | Separately inventoried, monitored, and held to tighter controls | / 4 |
| Service accounts | Created ad hoc, never reviewed or decommissioned | Inventoried, owned, credential-rotated, reviewed like any other identity | / 4 |
| Access reviews | Never happen, or only after an incident | Recurring, evidenced, and actually change access when needed | / 4 |
| Logging/monitoring | Sign-in logs exist but nobody looks at them | Centralised, alerting on anomalous auth patterns | / 4 |
| Emergency access | No break-glass process, or an undocumented one | Documented break-glass accounts, tested, tightly monitored | / 4 |
| Third-party access | Contractors/vendors get standing accounts indefinitely | Time-bound, scoped, reviewed on the same cadence as employees | / 4 |
| Zero Trust identity | Trust is implicit once you're on the network | Every access request verified on identity, device and context | / 4 |
On Microsoft-stack environments specifically, Conditional Access, PIM and identity governance largely mean "Microsoft Entra ID, configured properly rather than left on defaults." The mechanisms already exist in most E3/E5 licensing, which is exactly why under-configuration, not missing tooling, is the most common finding.
Scoring your organisation
Add up all 15 scores (range: 15 to 60) as a rough directional signal, not a certification:
- 15 to 26: Foundational gaps. Basic identity hygiene isn't in place yet. Start with identity inventory and joiner/mover/leaver: everything else depends on those two being solid.
- 27 to 41: Developing. Core controls exist but aren't consistently governed. MFA and Conditional Access are usually further along than access reviews and service-account hygiene at this stage.
- 42 to 52: Governed. Most areas have real process and ownership. The gap is usually monitoring and emergency-access testing: the areas that only get noticed when they fail.
- 53 to 60: Optimized. Genuinely mature. The remaining work is usually keeping pace as the organisation grows, not building anything new.
What a low score in a specific area actually means
A low score on joiner/mover/leaver or service accounts is the single most common real-world finding, not because either is technically hard, but because neither has an obvious owner until something goes wrong (a departing employee's access still active weeks later; a five-year-old service account with no one left who remembers what it does). A low score on Zero Trust identity is normal even in otherwise mature environments. It's an architecture to work toward, not a single setting to flip.
A note on the framework
The four-level structure here follows the shape of established maturity models (NIST's digital identity guidance and CISA's Zero Trust Maturity Model, both linked below) applied specifically to the 15 areas that come up most often in real IAM assessments. It isn't a substitute for either, and organisations pursuing a specific certification or regulatory framework (ISO 27001, NIS2) should score against that framework's own criteria as well.
Scored mostly 1s and 2s? That's a normal starting point, not a crisis. See our Identity & Access Management service for how we help organisations move through exactly this, starting with whichever two or three areas carry the most real risk for your environment.
Related services
Related reading
