Skip to content

Understanding your SAM Maturity Level

A SAM maturity assessment gives you a point-in-time benchmark and a plan to improve on it. What the four maturity levels mean, what a proper assessment covers, and why the scope of that assessment now has to reach SaaS, cloud and AI.

A SAM maturity assessment gives an organisation a simple point-in-time view of how mature its software asset management practice is. Its value is that it comes from outside: an independent review and a benchmark you can measure progress against, rather than an internal opinion that tends to be either too generous or too harsh depending on who was asked.

It is usually run either as a precursor to a full SAM engagement — establishing where you are before anyone commits to where you are going — or as a periodic review during a managed service, to check that the practice is still improving rather than quietly reverting.

SAM maturity levels

The maturity models in general use descend from ISO/IEC 19770-1, the ISO standard for software asset management processes. Microsoft built a SAM Optimisation Model on that foundation, and variations of it circulated widely through the SAM industry for years; most assessment frameworks you encounter are recognisably related to it.

Two things are worth knowing before you use one. First, these models are deliberately simple — that is the source of both their usefulness and their limits. A common set of criteria makes assessments and recommendations consistent between organisations, which is exactly what a benchmark needs, but no four-box model captures a large organisation faithfully. Second, ISO/IEC 19770-1 itself has moved on since those models were built. The 2017 revision was a major rewrite: restructured as a management system standard aligned with the likes of ISO 9001 and ISO 27001, reduced from four conformance tiers to three (trustworthy data, life cycle integration, optimisation), and — most relevant here — broadened in scope from software asset management to IT asset management as a whole. An assessment against an older derivative model is therefore measuring against a snapshot of the standard rather than the standard as it now stands, and against a narrower definition of what counts as an asset.

Assessments based on the Microsoft model typically place SAM maturity in one of four states:

Basic — a lack of policies, procedures, resources and tools. Software is managed reactively, usually by whoever last had to deal with an audit.

Standardised — processes exist, but the information behind them is neither complete nor accurate. You have a licence position; you would not want to defend it.

Rationalised — reliable information is used to manage software assets against business targets. The data can be trusted, and decisions are made from it.

Optimised — SAM is a strategic contributor to business objectives, feeding procurement, security and planning rather than reporting after the fact.

In reality, most organisations and most SAM programmes sit across several of these at once, depending on what is being assessed. Microsoft licensing might be rationalised while Oracle is basic. Desktop software might be optimised while the data centre is standardised. This is precisely why the assessment should be delivered by a skilled SAM consultant, and why it should not be performed in isolation but as part of a wider engagement — a single headline maturity score averages away the information you needed.

It is also why SAM service providers including Certero offer extended versions of the maturity assessment for larger and more complex organisations. Working with your stakeholders, consultants benchmark the current programme and help set future goals against your business priorities and organisational structure, rather than against a generic ladder.

What a maturity assessment covers

A SAM maturity assessment typically runs as a series of workshops that establish the scope of your programme and its current state. The topics covered normally include:

Overall management — responsibility, risk management, policies and procedures, competence, awareness and training, performance and continuous improvement, service continuity and availability management.

Core software asset management — asset identification, asset control and financial management.

Logistics processes — requirements definition, design, evaluation, procurement, build, deployment, operation, optimisation and retirement.

Verification and compliance — verification and audit, licence compliance.

Relationship processes — contract management, supplier management, internal business relations and outsourcing.

The workshops produce a summary report setting out the maturity level and the specific steps needed to advance it.

The scope problem nobody had in 2016

Read that list again and note what it assumes. Every category describes software that was requisitioned, procured, built, deployed and retired — software with a purchase order behind it and an installer in front of it.

A large share of software spending no longer works that way. SaaS subscriptions are bought by departments on cards, renewed automatically, and never touch the procurement process the assessment is examining. Cloud services are consumed by the hour with no procurement event at all. AI tools are adopted individually, frequently free at the point of use, and carry data-access questions no licence count would surface.

An organisation can score well against the traditional scope and still have no control over most of what it spends. That makes scope the single most important thing to interrogate about any maturity assessment you commission — not the model it uses, but what it agrees to look at.

A current assessment should therefore extend the same five categories to:

SaaS. Who owns each application, how many licences are assigned against how many are used, what happens to those licences when someone leaves, and which third-party OAuth grants hold access to company data. CerteroX SaaS Management covers this with three converging discovery signals — identity provider sync, vendor connector sync across 47 APIs, and a browser extension — plus offboarding with per-licence revocation status, so “the user was offboarded” becomes something you can evidence rather than assert.

Cloud. Whether cost is allocated to an owner, whether budgets and anomaly detection fire before the invoice rather than after it, and whether tag compliance and resource lifecycle are enforced or merely documented. CerteroX Cloud Management applies twenty-six named optimisation checks across twelve cloud and data platforms, with governance policies that act at the resource level and a violation history you can hand to audit.

AI. Which AI tools are in use, by what proportion of the organisation, with what data access, against what budget. CerteroX AI Management classifies AI tools from feature tags in a catalogue of more than 35,000 applications rather than from a fixed list, and ranks adoption risk by the share of the organisation using each tool.

The five assessment categories still apply to all three. It is the inventory of what falls inside them that has grown.

Do you need an independent assessment?

You can self-assess to a degree by working through the model yourself, and you probably already have a reasonable sense of where you are strong and where you are weak. Most people do.

The value of an independent assessment — particularly from a party with no interest in selling you software licences — lies in three things the self-assessment cannot produce. Validation, because your own judgement of your programme is the thing under question. A specific improvement plan for the areas you have chosen to target. And a business case for investment, built on a consultant’s experience of what improvement actually cost at comparable organisations, which is the part that determines whether anything happens next.

That acceleration is the point. NHS South West London ICB, using Certero’s SAM managed service, put it this way:

Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.

— Reece Emson, ITAM Asset/PSL Manager, NHS South West London ICB

The same engagement mitigated around £100k of Microsoft compliance risk. Maturity is not an abstraction; it is the difference between finding that exposure and being told about it.

Ultimately, choose the kind of assessment that fits your organisation, its size, its structure and its ambitions — self-directed or independently managed. For a straightforward view on which is right for you, have a no-obligation conversation with a qualified Certero SAM consultant. Get in touch.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.