Skip to content
Assessment · IT Maturity

IT Maturity Assessment

The business is about to ask IT for things it cannot sustain today. We evaluate the real state of your technology operation —governance, services, infrastructure, suppliers and continuity— and build the roadmap to close the distance between what IT delivers now and what the business will need next.

What it is
An operation that works is not an operation that scales.

The assessment measures the maturity of eight domains of the IT operation against recognised frameworks, identifies where daily effort is compensating for a structural weakness, and builds the roadmap to correct it. It also serves to decide, on criteria, what is worth delegating to a third party and what should stay in house.

01

Know where you stand

A maturity level per domain, measurable and comparable year on year.

02

Prioritise on criteria

What to fix first by business impact, not by who shouts loudest.

03

Decide what to delegate

What is worth outsourcing and what should remain under internal control, with an argument.

Assessment or consulting

One surveys and maps the route. The other executes it.

These are two different services and it is worth knowing which one you need before contracting. The assessment does the first information-gathering exercise, builds the roadmap and aligns it with the business areas. The consulting practice executes that roadmap.

IT Maturity Assessment — this page

Surveys, maps and aligns. It surveys the state of the operation across eight domains, measures maturity against COBIT and ITIL, identifies the structural gaps and builds the roadmap agreed with the business. It runs two to four weeks depending on the size of the organisation. It does not implement, does not configure and does not operate anything.

Managed Services — execution

Executes the roadmap. It takes the roadmap and operates: assumes daily management under service levels, implements the missing processes and sustains continuous improvement. It works just as well if you already have a roadmap of your own.

What it covers

Eight domains of the operation, evaluated one by one.

An operation fails at its weakest link, not at its average. We review each domain with the same depth and rate it by maturity level.

01

Governance and organisation

How decisions get made, who answers for what, and whether the IT structure matches the size of the operation.

02

Service management

How incidents, requests and changes are handled, and whether measurable service levels exist.

03

Infrastructure

Servers, network and the workplace: state, capacity, obsolescence and maintenance.

04

Applications

Which systems support the business, in what state they are and who maintains them.

05

Data

Where the information lives, with what backup, and with what level of confidence for deciding.

06

Security

Basic hygiene of access, patching and protection, and whether there is any capacity to detect an incident.

07

Suppliers

What is outsourced, under what contract, and how dependent the operation is on each one.

08

Continuity

What happens when something fails: verified backups, recovery times and tested plans.

How we do it

Six phases, without interrupting your operation.

The assessment rests on interviews, configuration review and documentation. There is no intervention on your systems at any point.

01

Scope and preparation

We define which domains, sites and systems are in, and agree read-only access.

02

Interviews

With the IT team, the key suppliers and the business areas that depend on the services.

03

Technical review

Inventory, configurations and existing documentation, checked against what the interviews said.

04

Gap analysis

Comparison against COBIT 2019, ITIL 4 and CMMI, domain by domain.

05

Prioritisation

Each gap with its business impact and the effort to close it, to order the roadmap.

06

Business alignment

Presentation of the roadmap with leadership and the areas, so priorities are agreed.

Method and frameworks

What your maturity is measured against.

The evaluation does not rest on the judgement of whichever consultant shows up, nor on a vendor catalogue, but on public and auditable frameworks your team can consult and your auditor will recognise. The fieldwork is run from Bogotá and Mexico City, in the time zone of the IT team that has to answer the questions.

01

COBIT 2019

Evaluation framework. IT governance and management. It is the basis of the maturity rating per domain.

02

ITIL 4

Evaluation framework. Service management: incidents, changes, problems and service levels.

03

CMMI

Maturity framework. Provides the scale that makes the result comparable year on year.

04

ISO/IEC 20000

Service guide. The IT service management standard, useful where certification is required.

05

ISO/IEC 38500

Governance guide. Who decides on IT, on what criteria and to whom they answer.

06

ISO 22301

Continuity guide. Reference for evaluating backups, recovery times and tested plans.

Risks of going without

What it costs to hold the operation together by hand.

An immature operation works until it stops working. These are the risks that accumulate in the meantime.

01

Dependency on people

Knowledge lives in a few heads and one absence halts the operation.

02

Incidents that repeat

With no problem management, the same failure returns every month and nobody measures what it costs.

03

Silent obsolescence

Equipment and systems age without a plan, until a business change turns them into a blocker.

04

Suppliers without control

Contracts with no service levels, no metrics and no viable exit.

05

Untested continuity

Backups exist, but nobody verified whether they can be restored within the time the business tolerates.

06

IT that slows the business

Every new initiative takes longer because the foundation does not support it, and the blame lands on the wrong area.

What it asks of your team

What it costs you in time, said upfront.

An assessment that does not state the commitment it requires ends up delayed. This is what we need from your side to deliver on time.

01

Two to four weeks

Two weeks in organisations of up to 50 employees; four between 51 and 300. The timeline is agreed before starting.

02

Scheduled interviews

Sessions with the IT team, key suppliers and the business areas that depend on the services.

03

Read-only access

Queries against the platforms and existing documentation. At no point is a configuration modified.

04

A single point of contact

One person coordinating schedules and access. It is the factor that most affects hitting the deadline.

05

Whatever documentation exists

Asset inventory, support contracts, procedures and incident reports, in whatever state they are in.

06

A closing session

The presentation of findings with leadership and the areas involved, where the roadmap priorities are agreed.

Who it is for

When it makes sense and when it does not.

It makes sense if…

Your operation depends on a few people; the same incidents keep repeating; you are about to grow or open a site and do not know whether IT supports it; you are evaluating outsourcing and need to know what; or you changed IT lead and want an objective baseline.

Probably not if…

You already know what is missing and what you need is someone to operate: go straight to Managed Services. Or if your question is about direction rather than operation — where to invest over the next three years — that is answered by the Technology Strategy Assessment.

Benefits

What you gain from the assessment.

An objective baseline

A maturity level per domain, comparable against itself the following year.

Priorities on criteria

What to fix first by business impact and effort to close.

An outsourcing decision

What is worth delegating and what to retain, with an argument rather than intuition.

Fewer repeat incidents

The structural causes are identified, not just the symptoms.

Verifiable continuity

How real your recovery capability is, measured rather than assumed.

A backed budget

An argument with figures for operational investment before leadership.

The SUMāTO approach

Why this evaluation and not an inventory audit.

The difference is not in listing equipment: it is in explaining why the operation is held together by hand and what it costs to fix.

01

Evaluation, not inventory

A list of assets does not say whether the operation is sustainable. Maturity is measured in processes, not in equipment.

02

Recognised frameworks

The comparison is against COBIT, ITIL and CMMI, not against whichever consultant shows up.

03

Business language

Each gap with its operational impact and the cost of not closing it.

04

Vendor independence

The roadmap is not shaped by what would suit us to sell afterwards.

05

No interruption to operations

Interviews and document review. No intervention on production systems.

06

Continuity into operation

If you decide to delegate, the roadmap connects with Managed Services and Help Desk without starting the survey again.

The conclusion

As-Is, To-Be and the plan to get from one to the other.

Every assessment closes with the same structure, whatever the practice: where you stand today, where you need to be, what separates the two states and in what order that distance gets closed.

01

Current state — As-Is

The starting point surveyed with evidence, not declared in an interview: what exists, how it operates and how far it sits from what the business needs.

02

Target state — To-Be

Where the organisation needs to get to, defined with the business areas rather than imposed by the consultant. It is the benchmark everything else is measured against.

03

Gap analysis

Every difference between the As-Is and the To-Be, with everything required to close it: technology, processes, people, governance and budget. No gap is stated without what it demands.

04

Risk matrix

Each gap rated by probability and business impact, so priority does not depend on who pushes hardest but on what it costs to leave it open.

05

Work plan

The concrete sequence to reach the To-Be: what comes first, what it depends on, how much effort it takes and who should answer for each front.

06

Business alignment

The plan is presented and agreed with the areas involved. A roadmap signed only by IT does not survive the first quarter.

The report

How what you receive is structured.

The central deliverable is a report with a fixed structure, designed so leadership reads the first pages and the technical team works with the rest.

01

Executive summary

Two pages: overall maturity level, the three gaps that weigh most and what decision each one calls for.

02

Maturity by domain

Rating of the eight domains with the gap made explicit against COBIT, ITIL and CMMI.

03

Findings with evidence

Each finding with what was observed, where, and why it matters to the business.

04

Dependency map

Which people, suppliers and systems the continuity of the operation depends on today.

05

Roadmap

Gaps prioritised by impact and effort, with a suggested owner and horizon.

06

Immediate actions

What can be corrected without a project or additional budget.

Deliverables

What you receive at the end.

  • Current state (As-Is): maturity of the IT operation, rated across each of the eight domains against COBIT 2019, ITIL 4 and CMMI.
  • Inventory of assets, services and managed contracts.
  • Dependency map of critical people, suppliers and systems.
  • Continuity assessment: backups, recovery times and tested plans.
  • Target state (To-Be): the maturity level the business requires per domain, agreed with the areas.
  • Gap analysis between the As-Is and the To-Be, with each gap, its evidence and everything required to close it: processes, tooling, people and suppliers.
  • Risk matrix: continuity, dependencies and obsolescence, rated by probability and business impact.
  • Work plan to reach the To-Be, prioritised by business impact and effort to close.
  • Recommendation on what is worth outsourcing and what to retain internally.
  • Immediate-impact actions, executable without additional budget.
  • Executive presentation for committee and leadership.
  • Alignment session with the business areas involved.
Frequently asked questions

About the IT Maturity Assessment.

What exactly do you evaluate?+
Eight domains: governance and organisation, service management, infrastructure, applications, data, security, suppliers and continuity. Each is rated for maturity against COBIT, ITIL and CMMI.
How does it differ from Managed Services?+
The assessment does the first information-gathering exercise, measures maturity, builds the roadmap and aligns it with the business areas. Managed Services is the one that operates: assumes daily management under service levels and sustains continuous improvement.
Is it useful for deciding whether to outsource?+
Yes, that is one of its most frequent uses. Delegating works when you know what you are delegating: the assessment makes explicit what to hand to a third party and what should stay in house.
Does it interrupt our operation?+
No. It rests on interviews, configuration review and documentation, with no intrusive action on production systems.
Who should take part on our side?+
The IT team, key suppliers and the business areas that depend on the services. Without the business, prioritisation ends up technical rather than impact-driven.
What if we have no documentation?+
That is a finding, not an obstacle. We work with whatever exists; the absence of documentation is itself a maturity indicator the report captures.
Is it the same as a cybersecurity assessment?+
No. Here security is one of eight domains and is evaluated at the level of basic hygiene. If the central concern is risk exposure, the right service is the Cybersecurity Assessment.
How often should we repeat it?+
Annually, or after a relevant change: an acquisition, a new site or a change of IT lead all justify measuring again.
The first step

Know whether your operation supports what is coming.

Book your IT Maturity Assessment and get an objective baseline per domain, with a roadmap prioritised by business impact.

Book my assessment See the Managed Services