Updated September 2026.
Quick Answer: How Does DesQcon Score ITSM Maturity?
DesQcon’s maturity assessments score every process area across six capability domains , People, Process, Tool, Automation, AI, and Governance , each rated on a five-level scale from Ad Hoc to Optimized, producing a 0-5 score per domain and an overall average. The scale is the same one used across the free Incident & Major Incident Management assessment and DesQcon’s paid process assessments, and it’s built on the same maturity-modeling logic used by CMMI and the ITIL 4 Maturity Model, not a proprietary scoring system invented for marketing purposes.
Why Six Domains Instead of One Score
A single “maturity score” hides more than it reveals. An organization can have well-documented incident processes (high Process maturity) while still triaging everything by hand (low Automation), or have a capable ITSM platform (high Tool maturity) that frontline staff were never properly trained to use (low People maturity).
Scoring six domains separately, rather than blending them into one number, shows exactly where the gap sits , which matters because the fix for a People gap (training, staffing, on-call design) is completely different from the fix for a Tool gap (integration, configuration, CMDB accuracy).
The Six Capability Domains
Every question in a DesQcon assessment maps to one of six domains. The table below describes what each one measures, using People and Process as the anchor points and extending the same lens to the platform, workflow automation, AI usage, and measurement discipline around it.
| Domain | What It Measures |
|---|---|
| People | Roles, skills, staffing model, and training , whether responsibilities are clearly defined, whether on-call/escalation is designed deliberately, and whether staff have the training and simulations needed to perform under pressure. |
| Process | Whether procedures are documented, consistently followed, and enforced , severity/priority definitions, escalation paths, and review practices like blameless post-incident analysis. |
| Tool | How well the supporting platform is configured, integrated, and actually used , ticketing/ITSM tool integration with monitoring and observability, CMDB or service-map accuracy, and whether the tool enforces the process or just records it after the fact. |
| Automation | How much of the workflow runs without manual intervention , automated routing, triage, enrichment, and runbook-driven remediation for known, recurring issues. |
| AI | Where and how AI is used within the process itself , from noise reduction and assisted diagnosis today toward predictive, proactive use over time, not AI as a separate initiative bolted on afterward. |
| Governance | Measurement and review discipline , whether KPIs are tracked, reviewed on a regular cadence, visible to leadership, and actually used to drive improvement rather than filed away. |
The Five-Level Maturity Scale
Each domain is scored on the same five-level scale DesQcon uses across its written maturity content, adapted from the levels of capability defined by the CMMI Institute and applied to ITSM specifically in frameworks like the ITIL 4 Maturity Model.
| Level | What It Looks Like |
|---|---|
| Level 1 , Ad Hoc | Work gets done, but inconsistently. No agreed process, no documented roles; outcomes depend on who happens to be on duty. |
| Level 2 , Developing / Repeatable | The basics exist , a tool, a rotation, a rough process , but they’re applied inconsistently and rarely measured. |
| Level 3 , Defined | The process is documented, agreed, and applied consistently. Roles, inputs, outputs, and escalation paths are clear regardless of who’s on duty. |
| Level 4 , Managed | The process is measured. KPIs are tracked, reviewed on a regular cadence, and used to catch drift before it becomes a problem. |
| Level 5 , Optimized | The process improves continually based on evidence. Automation reduces manual toil, and the organization actively pursues efficiency rather than just maintaining stability. |
This is the same scale explained in more depth, with a worked process-vs-tool example, in ITSM Process Maturity vs. Tool Maturity: Why You Need Both.
How the Score Is Calculated
Each question offers four maturity-level answer options (roughly mapping to Levels 1-4 above) plus an “unsure” option that’s excluded from scoring rather than counted as a low answer. A domain’s score is the average of its answered questions, converted to the 0-5 scale, so a domain with mostly Level-3-equivalent answers scores close to 3.0, not artificially inflated or deflated by unanswered questions. The overall score is the average across all six domains. Skipping a reasonable number of questions doesn’t invalidate the result , the score simply reflects what was answered.
What a Gap Looks Like in Practice
The point of scoring domains separately is that each one gets its own next step, not a generic “improve your ITSM” recommendation. For example, a mid-maturity result on the free Incident & Major Incident Management assessment might surface gaps like these, one per domain:
- People: defined roles and some training are in place, but there’s no formal certification path for incident commanders and no regular simulations to keep skills sharp under pressure.
- Process: core processes exist but aren’t consistently enforced , severity definitions need tightening and blameless post-incident reviews aren’t yet mandatory above a defined threshold.
- Tool: tooling covers the basics, but integration with monitoring and observability is partial, so alerts, tickets, and context don’t yet live in one place automatically.
- Automation: automation covers routing and some triage, but hasn’t been extended to runbook-driven remediation for the most common recurring incident types.
- AI: AI is used for noise reduction or assisted diagnosis today, with room to expand toward AI-assisted root-cause suggestions and auto-drafted incident summaries.
- Governance: core KPIs are tracked, but reviews are inconsistent or lack leadership visibility, so there’s no regular governance cadence with trend-based improvement targets.
Six separate, specific gaps , not one number.
Where This Framework Is Used
This scoring framework runs underneath DesQcon’s free Incident & Major Incident Management assessment today, and the same six-domain, five-level structure extends across DesQcon’s paid process assessments , Problem, Change, Service Request, Knowledge, Asset & Configuration, Hardware Asset, and Software Asset Management , so results are comparable across process areas rather than each one using its own ad hoc rubric.
No sign-up is required to see your score on the free assessment, and results are yours whether or not you choose to save a copy by email.
Sources
- CMMI Institute, “Levels of Capability and Performance” , https://cmmiinstitute.com/learning/appraisals/levels
- Beyond20, “An Overview of the ITIL 4 Maturity Model and Assessment (and why they’re important)” , https://www.beyond20.com/blog/itil-4-maturity-model-and-assessment-overview/
- Wikipedia, “Capability Maturity Model Integration” , https://en.wikipedia.org/wiki/Capability_Maturity_Model_Integration
- Service Desk Institute, “A Guide to ITSM Maturity Models and Finding Your Best Fit” , https://www.servicedeskinstitute.com/resources/itsm-maturity-models/
