The ITIL Maturity Model: A Practical Guide for Organizations

Updated September 2026.

Most teams that say they are “ITIL mature” are actually describing a feeling, not a measurement. They mean their incident process runs smoothly, or their last audit went well, or nobody complained about change management this quarter. The ITIL Maturity Model exists to replace that feeling with a number you can defend, track, and act on. Published by PeopleCert, the same organization behind the ITIL certification scheme, it is the first maturity framework to come directly from ITIL’s own publisher rather than from a consultancy or a tool vendor building its own scorecard.

This post explains what the ITIL Maturity Model actually measures, how its levels and assessment types fit together, and a practical way to put it to work inside an organization that has never run a formal maturity assessment before.

What the ITIL Maturity Model actually is

The model answers two different questions that most organizations quietly conflate: can we do this, and how well is this governed and sustained. Keeping those two questions separate is the single most important idea in the whole framework.

Capability and maturity are not the same question

Capability asks whether an individual ITIL practice, such as incident management or change enablement, can reliably achieve its purpose. Maturity asks something broader: how value is governed, created, and improved across the whole Service Value System, including guiding principles, governance, the service value chain, practices, and continual improvement. A team can run a highly capable incident process and still belong to a low-maturity organization, if that capability depends on one skilled person rather than a governed, repeatable system.

Five levels, borrowed from a familiar scale

Both capability and maturity are scored on the same five-level scale: Initial, Managed, Defined, Quantitative, and Optimizing. At Initial, work gets done but outcomes are not consistently achieved. At Managed, planning exists and objectives are repeatedly achieved, though not yet in a standardized way. At Defined, organization-wide standards guide work across the Service Value System. At Quantitative, decisions are data-driven, with measured performance evaluation. At Optimizing, the system is actively tuned through continual improvement rather than left to run on its existing standards. Readers familiar with CMMI will recognize the shape of this scale immediately, and that resemblance is intentional rather than incidental.

Four dimensions, the same four as the rest of ITIL 4

The assessment does not score practices in isolation. It evaluates them against the same four dimensions that run through the rest of ITIL 4: organizations and people, information and technology, partners and suppliers, and value streams and processes. A practice that looks strong on process documentation but has no defined ownership, or runs on a spreadsheet nobody else can access, will score lower once those dimensions are factored in.

Three ways to run the assessment

PeopleCert defines three assessment types, and choosing the right one matters more than most organizations realize before their first attempt. A capability assessment evaluates one or more individual practices without touching Service Value System maturity at all. A high-level maturity assessment evaluates SVS maturity with fewer than seven practices in scope. A comprehensive assessment evaluates seven or more practices, including continual improvement, together with full SVS maturity. Official assessments of any of these three types are carried out by PeopleCert’s Accredited Consulting Partners.

Five levels, one scale for capability and maturity The same Initial-to-Optimizing scale is applied to individual practices and to the whole Service Value System 1. Initial Outcomes are not always achieved 2. Managed Planned, repeatedly achieved 3. Defined Organization-wide standards apply 4. Quantitative Data-driven performance review 5. Optimizing Actively tuned by continual improvement Most first assessments land here Where most organizations aim within 12 to 18 months Applied to a single practice, this scale measures capability. Applied to the whole Service Value System, it measures maturity. Source: PeopleCert ITIL Maturity Model publications, 2026.

Why maturity is not the average of your scores

The most common mistake organizations make when they first see a maturity report is averaging the practice scores to get a single headline number. The model explicitly rejects that logic. Overall maturity is determined by the lowest-performing component in the assessment scope, not by an average across components. A service value chain that scores Optimizing on value streams but Initial on governance is not a Defined-level organization on average. It is an Initial-level organization with one strong area, because the weakest link is what actually constrains predictable outcomes.

This is also why capability and maturity can diverge so sharply inside the same organization. A single incident management team can be highly capable, closing tickets fast and consistently, while the organization around it is low maturity because that capability depends on one senior engineer’s judgment rather than a governed, documented, and measured system. Capability answers whether the work gets done. Maturity answers whether the way it gets done would survive that person leaving.

Three assessment types, three different scopes Choosing the right scope before you start avoids a report that answers the wrong question Capability Assessment Evaluates one or more individual practices. Service Value System maturity is not assessed at all. Use when: one practice is under scrutiny, such as before a tool switch High-Level Maturity Evaluates Service Value System maturity with fewer than seven practices in scope. Use when: you need a fast baseline before committing to a bigger review Comprehensive Evaluates seven or more practices, including continual improvement, plus full Service Value System maturity. Use when: maturity will inform a multi-year transformation budget Official assessments of any type are delivered through PeopleCert Accredited Consulting Partners. Source: PeopleCert ITIL Maturity Model publications, 2026.

How to use the ITIL Maturity Model in your organization

None of the following requires hiring an Accredited Consulting Partner on day one. An organization can apply the same logic internally to get a realistic picture before deciding whether a formal, certified assessment is worth commissioning.

1. Pick the assessment type before you pick the practices

Decide up front whether you need a capability assessment of one or two practices under scrutiny, a high-level maturity check across a handful of practices, or a comprehensive assessment meant to justify a transformation budget. Choosing the practices first and the scope second is how organizations end up with a report that does not answer the question they actually needed answered.

2. Score practices against evidence, not opinion

For each practice in scope, gather the evidence an assessor would actually ask for: documented procedures, ticket data, ownership records, and examples of the practice running under pressure, not just on a quiet day. A practice that “usually works” when described in a meeting often turns out to be Initial or Managed once someone asks for the data behind that description.

3. Score the four dimensions separately for each practice

Do not let a strong score on process documentation carry the whole practice. Check organizations and people (is there a defined owner, or one person who happens to know it), information and technology (is the data behind the practice trustworthy and accessible to more than one person), and partners and suppliers (does the practice depend on a vendor relationship nobody else manages). A practice that fails any one dimension caps its own score.

4. Assess Service Value System maturity as its own layer

Once individual practices are scored, step back and assess governance, guiding principles, the service value chain, and continual improvement as a system, not as a rollup of the practice scores. This is the layer that answers whether good practice execution would survive a reorganization, a key person leaving, or a change in tooling.

5. Let the lowest-scoring component set your priority

Because overall maturity is set by the weakest component, the fastest way to move the whole organization up a level is to fix whatever is scoring lowest, not to further polish whatever already scores highest. This runs against the natural instinct to invest more in an area that already shows results.

6. Reassess on a fixed cadence, not just once

A single assessment is a snapshot, not a program. Set a reassessment cadence, commonly annually or after any major change to tooling, team structure, or ownership, so the score reflects the current organization rather than a picture from eighteen months ago.

A six-step way to put the model to work Usable internally before any formal, certified assessment is commissioned 1 Pick scope Choose assessment type first 2 Gather evidence Score against data, not opinion 3 Score dimensions Check all four, not just process 4 Assess system Score SVS maturity as its own layer 5 Fix the floor Prioritize the lowest score 6 Reassess On a fixed cadence

Where organizations misuse the model

  • Averaging practice scores into a single headline number, which hides the one weak component actually holding the organization back.
  • Treating a capability assessment of a favorite practice as if it said something about overall Service Value System maturity, when the two are deliberately separate questions.
  • Running the assessment once and filing the report, instead of setting a reassessment cadence tied to real organizational change.

Where DesQcon fits

DesQcon’s own ITSM maturity assessments follow the same underlying logic as the ITIL Maturity Model: score practices against evidence rather than opinion, evaluate governance and system maturity as a separate layer from individual practice capability, and let the weakest component drive the roadmap instead of an averaged score that flatters the strongest area.

See our ITSM Maturity Assessment Methodology for how we score people, process, tools, automation, AI, and governance, and read ITSM Maturity Assessment: Why It Should Come Before Your Transformation Budget for why that baseline should come before any new spend. If you want the broader context first, What Is an ITSM Maturity Model? (And How It Helps Organizations) covers the general concept this post builds on.

Frequently asked questions

Is the ITIL Maturity Model the same thing as an ITIL certification?

No. ITIL certifications, such as Foundation or the practitioner-level modules, test an individual’s knowledge of the framework. The ITIL Maturity Model assesses an organization’s actual practices and Service Value System, and official assessments are delivered through PeopleCert Accredited Consulting Partners rather than an exam.

Do we need to assess every practice to get a useful result?

No. A capability assessment can evaluate a single practice under scrutiny, and a high-level maturity assessment covers Service Value System maturity with fewer than seven practices in scope. A comprehensive assessment covering seven or more practices plus full system maturity is usually reserved for decisions with real budget attached, such as a multi-year transformation program.

What should an organization do with a low maturity score?

Look at which specific component is setting the floor, since that is what determines the overall result, not the components already performing well. Prioritizing that weakest area, then reassessing after making a real change to it, moves the overall score faster than distributing effort evenly across every practice in scope.

Check your own ITSM and ITOM maturity

If this raised questions about where your own organization stands, DesQcon’s ITSM & ITOM Maturity Assessment gives you a structured, evidence-based read on that. Start with a free trial across one process area, or request the full deep-dive assessment across people, process, tools, automation, AI, and governance.