TL;DR
- Five levels: Unaware, Inventoried, Owned, Governed, Continuously verified.
- Four dimensions scored independently: discovery, ownership, credential control, evidence. Organisations are rarely level-consistent across all four.
- Your overall level is the lowest dimension, not the average. Evidence is usually the one dragging it down.
- Most first assessments land at level 1. That is normal and not a failure.
- The 1→3 gap is organisational, not technical. Tooling helps at 3→5 and barely at all before that.
Why a maturity model rather than a control list
Control lists such as the OWASP NHI Top 10 tell you what can go wrong. They do not tell you what to do first when everything is wrong at once, which is the actual situation in most organisations. A maturity model answers sequencing.
It also answers a budget question. "We have gaps" does not fund a programme. "We are at level 1 on evidence, which means we cannot answer an auditor's question about which agent took an action, and here is the measured cost of moving to level 3" does.
Status of this model
Practical recommendation, not a standard. This is our own model, derived from assessment work and aligned in structure to the CSA Agentic Trust Framework's maturity approach and the CSA NHI program guide. It is not certifiable and no regulator references it. Use it to sequence work, not to claim compliance. See the standards tracker for what is actually ratified.
The five levels
| Level | Name | What is true | What breaks |
|---|---|---|---|
| 0 | Unaware | Non-human identities are created by whoever needs one. No central visibility. Nobody owns the question. | Everything. Breach discovery is external. |
| 1 | Inventoried | A list exists. It is partial, manually maintained, and already out of date. Credentials are mostly static and long-lived. | The list. It decays faster than it is updated, and its coverage is unknown. |
| 2 | Owned | Discovery is automated for major platforms. Every discovered identity has a named accountable person. Exceptions are registered. | Credential hygiene. Ownership exists but authority is still standing and broad. |
| 3 | Governed | Credentials have bounded lifetimes. Access reviews include non-human identities. Revocation has been tested and timed. | Attribution under pressure. Logs show the principal but not the delegation chain. |
| 4 | Continuously verified | No standing authority. Authorization is evaluated per action. Delegation chains are reconstructable end to end. Evidence is exportable on demand. | Little, structurally. The remaining risk is operational discipline. |
Four dimensions, scored separately
- Discovery. What proportion of NHIs are found automatically, across which platforms, at what refresh interval? The honest test: run discovery on a system you believe is fully covered and count what you did not know about.
- Ownership. Does every identity map to a named person, and does that mapping update when people leave? A team name is level 1 regardless of how complete the list is.
- Credential control. Lifetime distribution, rotation, and whether credentials are attested from runtime rather than pasted into config.
- Evidence. Can you produce, on request, a dated export showing who owns what, when it was reviewed, and that a revocation actually took effect? This dimension is almost always the weakest and it is the one auditors test. See auditing NHI.
Score the lowest, not the mean. An organisation with excellent discovery and no evidence is not level 2.5; it is level 1 with good tooling, because it cannot demonstrate anything it knows.
How to score honestly
Self-assessment fails in a predictable direction: teams score the system they designed rather than the system that is running. Three corrections:
- Score on evidence you can produce today, in the next hour, without preparation. If producing it requires a project, you do not have it.
- Sample, do not survey. Take ten leavers from the last twelve months and trace their non-human identities. The result is your ownership score, whatever the process document says.
- Have someone outside the team score it. The most common self-assessment error is scoring intent as capability.
Our interactive maturity assessment runs this scoring in the browser and produces a written report.
The three moves that actually shift a level
- 0→1: pick an owner for the question. Not a tool, a person. Almost every organisation stuck at level 0 is stuck because NHI sits between IAM, platform engineering and security, and therefore belongs to nobody.
- 1→3: attribute ownership and bound lifetimes. This is the expensive middle and it is organisational work. Finding owners, negotiating expiry with teams that will resist, and registering exceptions. Buying a platform here produces a well-organised list of problems you are not structured to fix.
- 3→4: externalise authorization and fix delegation logging. This is where architecture and tooling genuinely carry the load. See the architect guide.
The asymmetry is the point: the level most organisations want to buy their way through is the one that cannot be bought.
Frequently asked questions
What maturity level are most organisations at for non-human identity?
Most organisations completing a first honest assessment land at level 1: a partial, manually maintained inventory with mostly static long-lived credentials. That is the normal starting position rather than a failure. The organisations that score higher usually did so because a specific incident or audit finding forced the work.
How do you score an NHI maturity assessment?
Score four dimensions separately: discovery, ownership, credential control, and evidence. Your overall level is the lowest dimension rather than the average, because an organisation that knows a great deal but can demonstrate none of it cannot pass an audit. Evidence is usually the weakest dimension and the one auditors test first.
Will buying an NHI platform raise our maturity level?
It helps substantially from level 3 to 4 and barely at all below level 2. The gap between level 1 and level 3 is organisational: attributing an accountable owner to every identity, negotiating bounded credential lifetimes with teams that will resist, and registering exceptions. No platform performs that work, which is why buying before measuring is the most common way NHI programmes stall.
Is this maturity model a recognised standard?
No. It is our own practical model, aligned in structure to the CSA Agentic Trust Framework's maturity approach and the CSA NHI program guide. It is not certifiable and no regulator references it. Use it to sequence work, not to claim compliance.
Assess your own NHI programme.
Run the free maturity assessment or the OWASP NHI Top 10 self-audit, get your score in the browser, and unlock the full written report.