Updated September 2026.
Most teams that say they are “ITIL mature” are actually describing a feeling, not a measurement. They mean their incident process runs smoothly, or their last audit went well, or nobody complained about change management this quarter. The ITIL Maturity Model exists to replace that feeling with a number you can defend, track, and act on. Published by PeopleCert, the same organization behind the ITIL certification scheme, it is the first maturity framework to come directly from ITIL’s own publisher rather than from a consultancy or a tool vendor building its own scorecard.
This post explains what the ITIL Maturity Model actually measures, how its levels and assessment types fit together, and a practical way to put it to work inside an organization that has never run a formal maturity assessment before.
What the ITIL Maturity Model actually is
The model answers two different questions that most organizations quietly conflate: can we do this, and how well is this governed and sustained. Keeping those two questions separate is the single most important idea in the whole framework.
Capability and maturity are not the same question
Capability asks whether an individual ITIL practice, such as incident management or change enablement, can reliably achieve its purpose. Maturity asks something broader: how value is governed, created, and improved across the whole Service Value System, including guiding principles, governance, the service value chain, practices, and continual improvement. A team can run a highly capable incident process and still belong to a low-maturity organization, if that capability depends on one skilled person rather than a governed, repeatable system.
Five levels, borrowed from a familiar scale
Both capability and maturity are scored on the same five-level scale: Initial, Managed, Defined, Quantitative, and Optimizing. At Initial, work gets done but outcomes are not consistently achieved. At Managed, planning exists and objectives are repeatedly achieved, though not yet in a standardized way. At Defined, organization-wide standards guide work across the Service Value System. At Quantitative, decisions are data-driven, with measured performance evaluation. At Optimizing, the system is actively tuned through continual improvement rather than left to run on its existing standards. Readers familiar with CMMI will recognize the shape of this scale immediately, and that resemblance is intentional rather than incidental.
Four dimensions, the same four as the rest of ITIL 4
The assessment does not score practices in isolation. It evaluates them against the same four dimensions that run through the rest of ITIL 4: organizations and people, information and technology, partners and suppliers, and value streams and processes. A practice that looks strong on process documentation but has no defined ownership, or runs on a spreadsheet nobody else can access, will score lower once those dimensions are factored in.
Three ways to run the assessment
PeopleCert defines three assessment types, and choosing the right one matters more than most organizations realize before their first attempt. A capability assessment evaluates one or more individual practices without touching Service Value System maturity at all. A high-level maturity assessment evaluates SVS maturity with fewer than seven practices in scope. A comprehensive assessment evaluates seven or more practices, including continual improvement, together with full SVS maturity. Official assessments of any of these three types are carried out by PeopleCert’s Accredited Consulting Partners.
Why maturity is not the average of your scores
The most common mistake organizations make when they first see a maturity report is averaging the practice scores to get a single headline number. The model explicitly rejects that logic. Overall maturity is determined by the lowest-performing component in the assessment scope, not by an average across components. A service value chain that scores Optimizing on value streams but Initial on governance is not a Defined-level organization on average. It is an Initial-level organization with one strong area, because the weakest link is what actually constrains predictable outcomes.
This is also why capability and maturity can diverge so sharply inside the same organization. A single incident management team can be highly capable, closing tickets fast and consistently, while the organization around it is low maturity because that capability depends on one senior engineer’s judgment rather than a governed, documented, and measured system. Capability answers whether the work gets done. Maturity answers whether the way it gets done would survive that person leaving.
How to use the ITIL Maturity Model in your organization
None of the following requires hiring an Accredited Consulting Partner on day one. An organization can apply the same logic internally to get a realistic picture before deciding whether a formal, certified assessment is worth commissioning.
1. Pick the assessment type before you pick the practices
Decide up front whether you need a capability assessment of one or two practices under scrutiny, a high-level maturity check across a handful of practices, or a comprehensive assessment meant to justify a transformation budget. Choosing the practices first and the scope second is how organizations end up with a report that does not answer the question they actually needed answered.
2. Score practices against evidence, not opinion
For each practice in scope, gather the evidence an assessor would actually ask for: documented procedures, ticket data, ownership records, and examples of the practice running under pressure, not just on a quiet day. A practice that “usually works” when described in a meeting often turns out to be Initial or Managed once someone asks for the data behind that description.
3. Score the four dimensions separately for each practice
Do not let a strong score on process documentation carry the whole practice. Check organizations and people (is there a defined owner, or one person who happens to know it), information and technology (is the data behind the practice trustworthy and accessible to more than one person), and partners and suppliers (does the practice depend on a vendor relationship nobody else manages). A practice that fails any one dimension caps its own score.
4. Assess Service Value System maturity as its own layer
Once individual practices are scored, step back and assess governance, guiding principles, the service value chain, and continual improvement as a system, not as a rollup of the practice scores. This is the layer that answers whether good practice execution would survive a reorganization, a key person leaving, or a change in tooling.
5. Let the lowest-scoring component set your priority
Because overall maturity is set by the weakest component, the fastest way to move the whole organization up a level is to fix whatever is scoring lowest, not to further polish whatever already scores highest. This runs against the natural instinct to invest more in an area that already shows results.
6. Reassess on a fixed cadence, not just once
A single assessment is a snapshot, not a program. Set a reassessment cadence, commonly annually or after any major change to tooling, team structure, or ownership, so the score reflects the current organization rather than a picture from eighteen months ago.
Where organizations misuse the model
- Averaging practice scores into a single headline number, which hides the one weak component actually holding the organization back.
- Treating a capability assessment of a favorite practice as if it said something about overall Service Value System maturity, when the two are deliberately separate questions.
- Running the assessment once and filing the report, instead of setting a reassessment cadence tied to real organizational change.
Where DesQcon fits
DesQcon’s own ITSM maturity assessments follow the same underlying logic as the ITIL Maturity Model: score practices against evidence rather than opinion, evaluate governance and system maturity as a separate layer from individual practice capability, and let the weakest component drive the roadmap instead of an averaged score that flatters the strongest area.
See our ITSM Maturity Assessment Methodology for how we score people, process, tools, automation, AI, and governance, and read ITSM Maturity Assessment: Why It Should Come Before Your Transformation Budget for why that baseline should come before any new spend. If you want the broader context first, What Is an ITSM Maturity Model? (And How It Helps Organizations) covers the general concept this post builds on.
Frequently asked questions
Is the ITIL Maturity Model the same thing as an ITIL certification?
No. ITIL certifications, such as Foundation or the practitioner-level modules, test an individual’s knowledge of the framework. The ITIL Maturity Model assesses an organization’s actual practices and Service Value System, and official assessments are delivered through PeopleCert Accredited Consulting Partners rather than an exam.
Do we need to assess every practice to get a useful result?
No. A capability assessment can evaluate a single practice under scrutiny, and a high-level maturity assessment covers Service Value System maturity with fewer than seven practices in scope. A comprehensive assessment covering seven or more practices plus full system maturity is usually reserved for decisions with real budget attached, such as a multi-year transformation program.
What should an organization do with a low maturity score?
Look at which specific component is setting the floor, since that is what determines the overall result, not the components already performing well. Prioritizing that weakest area, then reassessing after making a real change to it, moves the overall score faster than distributing effort evenly across every practice in scope.
Check your own ITSM and ITOM maturity
If this raised questions about where your own organization stands, DesQcon’s ITSM & ITOM Maturity Assessment gives you a structured, evidence-based read on that. Start with a free trial across one process area, or request the full deep-dive assessment across people, process, tools, automation, AI, and governance.
