What Good IAM Measurement Looks Like

NEWSLETTER SERIES: WE STILL DON’T HAVE A STANDARD WAY TO MEASURE IAM MATURITY

Part 3 of 3

By Vidyaa Ganesh

This is Part 3 of a three-part series on IAM maturity measurement. Part 1 reviewed the published research showing that 60-70% of organizations remain at early-to-mid stages of IAM maturity. Part 2 examined the frameworks currently available and the structural reasons no standard has emerged. This final installment proposes what a credible standard would need to include.

If the IAM community is going to move toward standardized measurement, what would a credible framework need to look like? Based on the published research reviewed in this series, established precedent from other domains, and the practical needs of practitioners, seven design principles emerge.

Principle 1: Domain Decomposition, Not Monolithic Scoring

IAM is not one thing. A useful maturity framework must decompose the discipline into distinct domains and assess each independently before producing any aggregate score. Treating IAM as a monolith obscures critical gaps. An organization with excellent identity governance but absent privileged access controls has a fundamentally different risk profile than one with moderate capabilities across the board, even if their aggregate scores are identical.

Gartner’s six-dimension structure is a reasonable reference point for domain decomposition. At minimum, a framework should separately assess identity lifecycle management, access management and authentication, privileged access management, and governance. Depending on the organization’s context, customer identity, cloud identity, and identity threat detection may also warrant distinct assessment.

Principle 2: Foundational Prerequisites Must Gate Advanced Claims

This may be the single most important design principle. A framework must account for the reality that some IAM capabilities are prerequisites for others. An organization that has deployed sophisticated analytics and AI-driven threat detection but has not implemented basic multi-factor authentication on privileged accounts has a fundamentally flawed security posture. A credible maturity score should reflect that.

This principle is well-established in adjacent fields. CMMI’s staged representation explicitly requires lower-level process areas to be satisfied before higher-level ratings can be claimed. SailPoint’s Horizons framework states that to be placed in a given horizon, capabilities must cover most environments and identity types. CISA’s Zero Trust Maturity Model states that identity pillar capabilities must be established before device trust can be meaningful.

A standardized IAM framework should identify a limited set of foundational controls and ensure that gaps in those controls are reflected in the overall maturity score. Without this, organizations can game the assessment by investing in visible, advanced capabilities while neglecting the basics that actually prevent breaches.

Principle 3: Risk-Weighted Scoring

Not all IAM controls carry equal risk. The presence or absence of MFA on privileged accounts has a materially different security impact than the presence or absence of a formal identity data classification scheme. A credible framework must reflect this through some form of risk-weighted scoring.

Published research supports this approach. IBM’s 2025 data shows that organizations with extensive security automation experienced average breach costs of $3.62 million compared to $5.52 million without, a 34% cost reduction attributable to mature controls. Microsoft’s Digital Defense Report found that MFA blocks over 99% of account compromise attacks. The data makes clear that certain controls deliver disproportionate risk reduction and should be weighted accordingly.

Principle 4: Industry-Contextualized Benchmarks Derived from Empirical Data

A maturity score in isolation is nearly useless. What makes it actionable is context: how does this score compare to others in the same industry, of similar size, facing similar regulatory requirements? A credible framework must include an empirical benchmark layer.

The data for this already partially exists. SailPoint publishes industry breakdowns. Ponemon publishes breach cost data by industry. Simeio publishes maturity scores by vertical. What does not exist is a single, consistent benchmark set that covers all IAM domains across major industries. Building this requires either a large-scale survey effort or, more practically, the aggregation of assessment data across organizations over time, with appropriate anonymization and consent.

Principle 5: Transparency of Methodology

Every number in a maturity assessment should have a documented derivation. If a domain receives a higher weight than another, the rationale should be published. If a benchmark is based on a specific data source, that source should be cited. If a benchmark is estimated rather than measured, that should be disclosed.

This level of transparency is uncommon in commercial assessment tools, where scoring logic is often proprietary. But for a community standard, it is essential. Consultants need to be able to explain and defend the numbers they present to clients. CISOs need to trust that the methodology is sound before presenting results to their boards. Transparency is not just a nice-to-have. It is a prerequisite for adoption.

Principle 6: Technology Agnosticism

A standardized framework must assess capability, not tooling. The question is not whether an organization has deployed a specific vendor’s IGA platform, but whether it has a functioning identity lifecycle management process that covers joiners, movers, and leavers with appropriate automation and oversight. This distinction matters because organizations achieve similar maturity outcomes with very different technology stacks, and a useful standard must accommodate that diversity.

Principle 7: Actionable Outputs

A maturity assessment that produces only a number is insufficient. The assessment process should produce outputs that enable direct action: identification of specific capability gaps, prioritized remediation guidance, regulatory compliance mapping, and clear criteria for what moving from one level to the next requires.

Gartner’s recommendation of outcome-driven metrics for IAM aligns with this principle. The goal of measurement is not the score itself but the improvement roadmap it enables. A framework that scores but does not guide action is an academic exercise.

Gaps and Open Questions

Even with sound design principles, significant gaps remain that the community will need to address.

Non-human identity. Machine identities (service accounts, API keys, certificates, workload identities) now outnumber human identities by ratios that CyberArk’s 2025 research places at approximately 80 to 1. Yet most maturity models treat identity as synonymous with human identity. A credible standard will need to account for non-human identity management as a distinct assessment domain.

AI agent governance. As AI agents increasingly operate autonomously within enterprise environments, the question of how to govern their identities, permissions, and access patterns is emerging as a new challenge. SailPoint’s 2025 Horizons research added AI agent governance to its capability thresholds. No existing maturity model addresses this domain in depth. Any framework designed for longevity should be extensible enough to incorporate it.

The data collection problem. The most practical path to building reliable industry benchmarks is through the aggregation of anonymized assessment data across many organizations over time. This creates a chicken-and-egg problem: organizations are reluctant to contribute data to a benchmark pool unless the benchmark already exists, and the benchmark cannot exist without contributed data. Solving this will likely require a combination of opt-in data sharing, strong privacy guarantees, and a trusted neutral party to manage the aggregation.

Weighting validation. Any risk-weighted scoring system involves judgment calls about how much weight to assign to different controls and domains. These weights can be informed by published research on breach costs, attack frequency, and control effectiveness, but they cannot be fully derived from first principles. Ongoing validation through correlation analysis between assessment scores and actual security outcomes is needed to refine the weights over time.

Conclusion

The IAM community has a measurement problem. Five independent research sources, covering over 2,000 respondents, consistently show that 60% to 70% of organizations are at early-to-mid stages of IAM maturity. At the same time, the industry relies on a fragmented set of incompatible frameworks that prevent meaningful comparison, benchmarking, or progress tracking.

This is not a technology problem. The tools exist. This is a standards problem. The community lacks a shared, vendor-neutral, empirically-grounded framework for measuring IAM maturity, and the absence of such a standard has real consequences: CISOs cannot articulate their posture to boards in comparable terms, consulting firms deliver assessments that start from scratch with each engagement, and the industry has no aggregate data pool that could identify systemic weaknesses and drive collective improvement.

The design principles outlined in this series are not radical. Domain decomposition, foundational prerequisite gating, risk-weighted scoring, empirical benchmarks, methodology transparency, technology agnosticism, and actionable outputs are all well-supported by existing research and established practice in adjacent disciplines. What is missing is the will to build and adopt a standard that incorporates them.

Identity practitioners are the people best positioned to solve this. They live the problem daily. They understand the domains. They see the consequences of unmeasured and unmeasurable IAM programs. The question is whether the community will continue to tolerate a landscape where every assessment is a one-off, or whether it will converge on a shared approach that raises the bar for everyone.

About the Author

Vidyaa Ganesh is a Senior IAM Engineer and Team Lead at Raah Technologies, with over six years of experience spanning enterprise IAM implementations, strategic advisory, and maturity assessments. She has held consulting roles at KPMG Canada and Indigo Consulting, delivering identity governance and privileged access programs for financial services, energy, telecommunications, and public sector clients. She holds Okta and Saviynt certifications and a Master of Engineering from Concordia University. She is a member of IDPro.

Endnotes

17. Gartner, IAM Program Maturity Model (September 2025).

18. ISACA, CMMI Version 3.0: “A maturity level rating is achieved when all process areas at that level have been appraised as meeting their specific and generic goals.”

19. SailPoint, Horizons 2025-2026: “To be in one horizon, customer capabilities need to cover most environments and identities.”

20. CISA, Zero Trust Maturity Model (2023).

21. IBM Security, Cost of a Data Breach Report 2025.

22. Microsoft, Digital Defense Report (Microsoft Security, 2024).

23. NIST, SP 800-30 Rev 1: Guide for Conducting Risk Assessments (2012). See also FAIR Institute.

24. SailPoint, Horizons 2025-2026, Exhibit 7.

25. IBM Security, Cost of a Data Breach Report 2025, Industry Analysis section.

26. Simeio, State of Identity 2024.

27. Gartner, IAM Program Maturity Model (September 2025). Recommends outcome-driven metrics (ODMs).

28. CyberArk, The Urgent Reality of Machine Identity Security in 2025 (CyberArk, 2025), 2,600 decision-makers.



About the Author

Vidyaa Ganesh is a Senior IAM Engineer and a solutions architect with over six years of experience delivering identity governance programs for financial services, energy, telecommunications, and public sector clients. She holds a Master of Engineering from Concordia University, is a member of IDPro, and is the creator of AXIS (axis.identara.ca), an open IAM maturity assessment framework.

Lets get in touch ...

Please use the below contact form to leave your message with us. We will be pleased to respond as soon as possible.

Contact Us

Name(Required)
You may contact us by filling in this form any time you need professional support or have any questions. You can also fill in the form to leave your comments or feedback.