Quick answer: An IAM strategy is a written, board-endorsed statement of what the identity program protects, the target maturity level for each identity domain, the sequence of investments to get there, and the metrics that prove it. Use a five-level maturity model (ad hoc, repeatable, defined, managed, optimized) across eight domains: workforce access, authentication, governance, privileged access, customer identity, non-human identity, identity threat detection, and architecture. The rule: fund the gap that carries the most breach and audit exposure, not the one with the loudest vendor.
Identity programs rarely fail for lack of technology. They fail because the strategy is a tool list, the maturity claim is a feeling rather than a measurement, and the roadmap is whatever the renewal calendar dictates. Then an auditor asks for a service account inventory, or an attacker uses a stolen credential, and the program discovers its real maturity in public.
This article is for IAM program owners, security leaders and the CIOs and CISOs who fund them. It gives you an IAM strategy structure that survives a board review, a maturity model with enough specificity to score honestly, and a 12-month roadmap pattern that has worked across regulated enterprises in the US, UK and Australia. It assumes you already have IAM tools and need to turn them into a program.
What should an IAM strategy include?
A strategy document that fits on eight pages is more useful than a 60-page one nobody reads. Include:
- Scope and principles. Which identity types are in scope (workforce, customer, partner, privileged, machine, AI agent) and the three to five principles that resolve arguments later: for example, "identity is the control plane," "phishing-resistant by default," "every identity has an owner," "least privilege is measured, not assumed."
- Risk and obligation drivers. The specific threats (credential theft, MFA bypass, insider misuse, service account compromise) and the specific obligations: NIST CSF 2.0 and SP 800-63-4 in the US, NIS2 and DORA in Europe, APRA CPS 234 and CPS 230 in Australia, PCI DSS 4.0, SOX, SOC 2, plus the UK Cyber Security and Resilience Bill and Australian SOCI obligations where they apply. Map each to the domain it touches.
- Current and target maturity by domain. Scored with the model below, with the evidence behind each score.
- Target architecture. Usually a statement of intent toward an identity fabric: the standards you will require, the systems of record, and the consolidation posture.
- Roadmap. Sequenced initiatives over 12 to 36 months with dependencies.
- Operating model. Who owns identity (a single accountable executive), how application teams engage, and the governance forum that arbitrates.
- Metrics. The handful of numbers reported quarterly to the board.
- Budget and benefits. Cost of the roadmap set against avoided risk, audit findings closed, help desk and licensing savings, and productivity gains from faster onboarding.
What are the levels of an IAM maturity model?
Most models (Gartner's, the CISA Zero Trust Maturity Model's identity pillar, and the common CMMI-derived ones) use five levels. The labels matter less than the evidence required at each one:
- 1 — Name: Ad hoc · What it looks like: Access granted by ticket and tribal knowledge; MFA partial; no inventory of privileged or service accounts · Evidence: None that an auditor would accept
- 2 — Name: Repeatable · What it looks like: SSO and MFA for most SaaS; joiner-leaver automated from HR for core apps; PAM for domain admins · Evidence: Process documents; partial coverage numbers
- 3 — Name: Defined · What it looks like: Role or policy-based access; periodic certifications; PAM for all tier-0; phishing-resistant MFA for admins; NHI inventory started · Evidence: Coverage metrics by domain; certification completion rates
- 4 — Name: Managed · What it looks like: Risk-based, continuous access decisions; usage-driven certifications; NHIs owned and rotated; ITDR in place with runbooks; metrics drive investment · Evidence: Trend data; tested incident response; quantified least privilege
- 5 — Name: Optimized · What it looks like: Policy defined once and enforced everywhere (fabric); passwordless majority; automated remediation from posture signals; identity for AI agents governed · Evidence: Low variance across domains; continuous assurance evidence
Two honesty rules. First, score by the weakest evidence in the domain, not the best pilot. Second, you cannot be at level 4 in workforce access while service accounts are at level 1; the program's effective maturity is close to its lowest-scored domain because that is where the attacker goes.
How do you assess IAM maturity without fooling yourself?
A self-assessment that holds up to challenge has four steps:
- Score eight domains, not one. Workforce access management, authentication, identity governance and administration, privileged access management, customer identity (CIAM), non-human and machine identity, identity threat detection and response, and architecture/operating model.
- Demand a data point per score. "Phishing-resistant MFA coverage for privileged users: 61%" beats "MFA: strong." If the number does not exist, the score is at most level 2 in that domain.
- Triangulate. Pair the IAM team's self-score with internal audit's view and a sample of application owners'. Disagreement is information.
- Test two things live. Time to disable a leaver's access across all systems, and time to revoke a compromised service account credential. Both numbers tend to puncture optimistic scores.
For organizations that want an external anchor, the CISA Zero Trust Maturity Model (identity pillar) and NIST CSF 2.0's Protect and Identify functions provide language regulators recognize, and NIST SP 800-63-4 gives concrete authenticator assurance levels to target.
How do you build an IAM roadmap for the next 12 months?
Sequence by exposure, then by dependency. A pattern that has held across regulated enterprises:
Quarter 1: Visibility and the two tests.
- Complete the domain-level maturity assessment with evidence.
- Build the inventories you lack, starting with privileged and non-human identities (see the non-human identity playbook).
- Run the leaver and credential-revocation tests and record the baseline times.
- Secure executive sponsorship and publish the strategy.
Quarter 2: Close the highest-exposure gaps.
- Phishing-resistant MFA (FIDO2 passkeys or certificate-based) for every privileged and identity-administrator account; conditional access requiring managed devices for regulated data.
- Ownership attestation for tier-0 and tier-1 service accounts; quarantine the unclaimed.
- Define ITDR runbooks for credential theft, MFA fatigue and suspicious consent grants before buying more detection.
Quarter 3: Automate the lifecycle.
- Extend HR-driven joiner-mover-leaver to the long tail of applications via SCIM; switch certifications to usage-driven.
- Move CI/CD and cloud workloads to federated workload identity; begin static-secret elimination for tier 1.
- Register and govern the first production AI agents as identities (see AI agent identity).
Quarter 4: Architecture and consolidation decisions.
- Publish the target architecture and required standards; put them in procurement.
- Decide, with the fabric view, which renewals to decline in year two.
- Re-score maturity; report the delta to the board with the metrics below.
Dependencies to respect: you cannot do usage-driven certifications without telemetry, you cannot do risk-based access without a consistent policy layer, and you cannot govern AI agents before you govern service accounts.
How do you get budget for an IAM program?
Boards fund three things: regulatory exposure, breach exposure and business friction. Frame every initiative in those terms.
- Regulatory: "DORA Article 9 and APRA CPS 234 expect access controls over all accounts; we cannot currently evidence ownership for X% of privileged service accounts." Audit findings are the most reliable funding mechanism in identity.
- Breach: Credential abuse has been among the leading initial-access vectors in the Verizon DBIR for years; the direction is consistent even as the exact percentage moves. Tie each initiative to the attack path it removes.
- Friction: Days to onboard a new hire or a new application, help desk tickets for password resets, SaaS licenses held by leavers. These numbers are often large, easy to measure and convert directly into savings.
Present the roadmap as a portfolio with a cost per maturity-level step per domain, and be explicit about what you will not do this year. Credibility comes from the trade-offs, not the ambition.
How do you measure IAM program success?
Pick no more than eight metrics, report them quarterly, and keep the definitions stable so trends are real:
- Authentication — Metric: Percentage of workforce and privileged users on phishing-resistant MFA
- Lifecycle — Metric: Median time to disable a leaver across all connected systems; percentage of applications with automated deprovisioning
- Governance — Metric: Percentage of entitlements certified using usage data; standing privileged entitlements, trending down
- Privileged access — Metric: Percentage of tier-0 access via just-in-time elevation
- Non-human identity — Metric: Percentage of tier-0/1 NHIs with a named owner; median credential age
- ITDR — Metric: Mean time to contain an identity incident; runbook coverage of top identity attack techniques
- Architecture — Metric: Percentage of applications onboarded through standard patterns; number of distinct policy definition points
- Business — Metric: Days to onboard a new hire; help desk identity tickets per 1,000 users
The maturity score itself is a lagging indicator. These are the leading ones.
Key takeaways
- An IAM strategy is a short, board-endorsed document: scope, drivers, maturity by domain, target architecture, roadmap, operating model, metrics, budget.
- Score eight domains with evidence; the program's effective maturity is close to its weakest domain, which is usually non-human identity or ITDR.
- Two live tests (leaver disablement time, credential revocation time) reveal real maturity faster than any questionnaire.
- Sequence the roadmap by exposure then dependency: visibility, privileged MFA and NHI ownership, lifecycle automation, then architecture and consolidation.
- Fund the program through regulatory exposure, breach paths removed and measurable friction, with explicit trade-offs.
- Report a stable set of leading metrics quarterly; the maturity score is the lagging indicator.
Join your peers at Identity World 2027
Identity World is the global identity and access management forum: practitioner-led, with attendees who collectively manage well over $900M of technology budgets and no product pitches on stage. Benchmark your strategy and maturity against peers in every city: Sydney, February 18 · Melbourne, March 17 · New York, May 6 · London, June 16 · San Francisco, November 3.
Not ready to register? Sign up for updates and the IdentityBriefing newsletter.