A SAM maturity assessment gives an organisation a simple point-in-time view of
how mature its software asset management practice is. Its value is that it comes
from outside: an independent review and a benchmark you can measure progress
against, rather than an internal opinion that tends to be either too generous or
too harsh depending on who was asked.
It is usually run either as a precursor to a full SAM engagement — establishing
where you are before anyone commits to where you are going — or as a periodic
review during a managed service, to check that the practice is still improving
rather than quietly reverting.
SAM maturity levels
The maturity models in general use descend from ISO/IEC 19770-1, the ISO standard
for software asset management processes. Microsoft built a SAM Optimisation Model
on that foundation, and variations of it circulated widely through the SAM
industry for years; most assessment frameworks you encounter are recognisably
related to it.
Two things are worth knowing before you use one. First, these models are
deliberately simple — that is the source of both their usefulness and their
limits. A common set of criteria makes assessments and recommendations
consistent between organisations, which is exactly what a benchmark needs, but no
four-box model captures a large organisation faithfully. Second, ISO/IEC 19770-1
itself has moved on since those models were built. The 2017 revision was a major
rewrite: restructured as a management system standard aligned with the likes of
ISO 9001 and ISO 27001, reduced from four conformance tiers to three
(trustworthy data, life cycle integration, optimisation), and — most relevant
here — broadened in scope from software asset management to IT asset management
as a whole. An assessment against an older derivative model is therefore
measuring against a snapshot of the standard rather than the standard as it now
stands, and against a narrower definition of what counts as an asset.
Assessments based on the Microsoft model typically place SAM maturity in one of
four states:
Basic — a lack of policies, procedures, resources and tools. Software is
managed reactively, usually by whoever last had to deal with an audit.
Standardised — processes exist, but the information behind them is neither
complete nor accurate. You have a licence position; you would not want to defend
it.
Rationalised — reliable information is used to manage software assets against
business targets. The data can be trusted, and decisions are made from it.
Optimised — SAM is a strategic contributor to business objectives, feeding
procurement, security and planning rather than reporting after the fact.
In reality, most organisations and most SAM programmes sit across several of
these at once, depending on what is being assessed. Microsoft licensing might be
rationalised while Oracle is basic. Desktop software might be optimised while the
data centre is standardised. This is precisely why the assessment should be
delivered by a skilled SAM consultant, and why it should not be performed in
isolation but as part of a wider engagement — a single headline maturity score
averages away the information you needed.
It is also why SAM service providers including Certero offer extended versions of
the maturity assessment for larger and more complex organisations. Working with
your stakeholders, consultants benchmark the current programme and help set
future goals against your business priorities and organisational structure,
rather than against a generic ladder.
What a maturity assessment covers
A SAM maturity assessment typically runs as a series of workshops that establish
the scope of your programme and its current state. The topics covered normally
include:
Overall management — responsibility, risk management, policies and
procedures, competence, awareness and training, performance and continuous
improvement, service continuity and availability management.
Core software asset management — asset identification, asset control and
financial management.
Logistics processes — requirements definition, design, evaluation,
procurement, build, deployment, operation, optimisation and retirement.
Verification and compliance — verification and audit, licence compliance.
Relationship processes — contract management, supplier management, internal
business relations and outsourcing.
The workshops produce a summary report setting out the maturity level and the
specific steps needed to advance it.
The scope problem nobody had in 2016
Read that list again and note what it assumes. Every category describes software
that was requisitioned, procured, built, deployed and retired — software with a
purchase order behind it and an installer in front of it.
A large share of software spending no longer works that way. SaaS subscriptions
are bought by departments on cards, renewed automatically, and never touch the
procurement process the assessment is examining. Cloud services are consumed by
the hour with no procurement event at all. AI tools are adopted individually,
frequently free at the point of use, and carry data-access questions no licence
count would surface.
An organisation can score well against the traditional scope and still have no
control over most of what it spends. That makes scope the single most important
thing to interrogate about any maturity assessment you commission — not the
model it uses, but what it agrees to look at.
A current assessment should therefore extend the same five categories to:
SaaS. Who owns each application, how many licences are assigned against how
many are used, what happens to those licences when someone leaves, and which
third-party OAuth grants hold access to company data. CerteroX SaaS Management
covers this with three converging discovery signals — identity provider sync,
vendor connector sync across 47 APIs, and a browser extension — plus offboarding
with per-licence revocation status, so “the user was offboarded” becomes
something you can evidence rather than assert.
Cloud. Whether cost is allocated to an owner, whether budgets and anomaly
detection fire before the invoice rather than after it, and whether tag
compliance and resource lifecycle are enforced or merely documented. CerteroX
Cloud Management applies twenty-six named optimisation checks across twelve cloud
and data platforms, with governance policies that act at the resource level and
a violation history you can hand to audit.
AI. Which AI tools are in use, by what proportion of the organisation, with
what data access, against what budget. CerteroX AI Management classifies AI tools
from feature tags in a catalogue of more than 35,000 applications rather than
from a fixed list, and ranks adoption risk by the share of the organisation using
each tool.
The five assessment categories still apply to all three. It is the inventory of
what falls inside them that has grown.
Do you need an independent assessment?
You can self-assess to a degree by working through the model yourself, and you
probably already have a reasonable sense of where you are strong and where you
are weak. Most people do.
The value of an independent assessment — particularly from a party with no
interest in selling you software licences — lies in three things the
self-assessment cannot produce. Validation, because your own judgement of your
programme is the thing under question. A specific improvement plan for the areas
you have chosen to target. And a business case for investment, built on a
consultant’s experience of what improvement actually cost at comparable
organisations, which is the part that determines whether anything happens next.
That acceleration is the point. NHS South West London ICB, using Certero’s SAM
managed service, put it this way:
Certero’s SAM managed service allowed us to significantly mature our license
posture at a fast pace, something that would have taken 3-4 years without their
involvement.
— Reece Emson, ITAM Asset/PSL Manager, NHS South West London ICB
The same engagement mitigated around £100k of Microsoft compliance risk. Maturity
is not an abstraction; it is the difference between finding that exposure and
being told about it.
Ultimately, choose the kind of assessment that fits your organisation, its size,
its structure and its ambitions — self-directed or independently managed. For a
straightforward view on which is right for you, have a no-obligation conversation
with a qualified Certero SAM consultant. Get in touch.