COBIT maturity assessment: A guide to capability and focus area levels
A COBIT maturity assessment helps you understand how well your governance and management practices are performing and where improvement is needed. But a COBIT assessment is not simply a checklist that gives your organization one overall score.
COBIT 2019 uses COBIT performance management (CPM) to assess performance at different levels. Process capability levels show how well individual processes are implemented and performing. Maturity levels are used at the focus-area level to provide a broader view of how a collection of governance and management objectives performs together.
This distinction is important here. A process can have a strong capability level even if the entire focus area is not equally mature.
Understanding how these two measures work makes it easier to assess your current state, set realistic targets, identify gaps, and prioritize improvements.
Quick link: How to implement COBIT 2019: A step-by-step guide
What is a COBIT maturity assessment?
A COBIT maturity assessment evaluates how effectively governance and management processes meet defined expectations. COBIT 2019’s performance management approach uses capability levels for processes and maturity levels for focus areas. Both use a scale from 0 to 5, but they answer different questions.
Process capability asks: How well is this particular process implemented and performing?
Focus-area maturity asks: How effectively are the processes within this broader focus area working together to achieve the intended outcomes?
For example, an organization assessing its information security governance may examine processes related to security management, risk, operations, and assurance. The individual processes can receive capability ratings, while the broader focus area can be assessed for maturity.
This gives decision-makers more useful information than a single organization-wide score. It shows where performance is strong, where gaps exist, and what needs attention.
What are COBIT capability levels?
COBIT 2019 framework uses six process capability levels, from 0 to 5. Each level represents a different degree of process capability.
| Level | Description |
| 0 – Incomplete | The process lacks basic capability and does not consistently achieve its purpose. |
| 1 – Performed | The process more or less achieves its purpose through an incomplete and often intuitive set of activities. |
| 2 – Managed | The process achieves its purpose through a basic but complete set of managed activities. |
| 3 – Established | The process achieves its purpose in an organized way using organizational assets, and the process is typically well defined. |
| 4 – Predictable | The process is well defined, and its performance is quantitatively measured. |
| 5 – Optimizing | The process is well defined, measured to improve performance, and subject to continuous improvement. |
The important point is that capability measures the process, rather than giving a broad rating to the whole governance system.
For example, an organization might assess a risk management process at capability level 2 because it has defined and managed activities but lacks the consistency or organizational assets expected at level 3.
That does not automatically mean its entire risk management focus area has maturity level 2.
Capability levels vs. maturity levels: What’s the difference?
This is one of the most important distinctions to understand when conducting a COBIT maturity assessment. Capability levels apply to individual processes. Maturity levels apply to focus areas.
| Capability level | Maturity level | |
| Applies to | Individual processes | Focus areas |
| Purpose | Measure how well a process is implemented and performing | Measure the performance of a broader focus area |
| Scale | 0-5 | 0-5 |
| Main question | How capable is this process? | How mature is this focus area? |
| Usage | Identify process-level gaps and improvement needs | Understand broader performance and improvement |
Both capability and maturity use a 0–5 scale, but they are assessed differently and apply at different levels of the COBIT performance management model.
What are COBIT focus areas?
A COBIT focus area is a specific governance topic, domain, or issue that can be addressed through a collection of governance and management objectives and their related components.
Focus areas make COBIT more adaptable to specific organizational needs.
For example, an organization could develop a focus area around privacy, information and technology risk, cyber security, or another topic that requires attention across multiple governance and management objectives.
COBIT 2019 uses design factors to help organizations determine which objectives are relevant to their situation. These factors include business strategy, enterprise goals, risk profile, I&T-related issues, the threat landscape, compliance requirements, the role of IT, the sourcing model, the technology adoption strategy, and enterprise size.
This means an assessment doesn’t need to cover every COBIT objective simply because the framework includes them.
How to conduct a COBIT maturity assessment
A useful assessment starts with scope, not scores. Before assigning a capability or maturity level, define what you are assessing and why. If you are assessing individual processes, you will establish their capability levels. If you are assessing a broader focus area, you can evaluate its maturity.
1. Define the assessment scope
Start with the business or governance problem you want to understand. You may want to assess information security because of recurring audit findings. You may need to evaluate risk management after changes to your enterprise risk profile. You may want to assess a specific focus area due to new regulatory requirements.
Define the scope around that need rather than automatically assessing all 40 COBIT governance and management objectives.
2. Select the relevant COBIT objectives and processes
Once the scope is clear, identify the governance and management objectives that apply. Use your business goals, risk profile, regulatory requirements, I&T issues, and other relevant design factors to determine which objectives matter most.
For example, an organization assessing cyber security governance may decide that objectives such as APO13 managed security, APO12 managed risk, and DSS05 managed security services are particularly relevant.
The goal is to assess the processes that matter to your intended outcome, not to create unnecessary assessment work.
3. Establish the current capability level
Next, evaluate how each relevant process currently performs. Look at the activities and practices associated with the process. Review the evidence that shows whether those activities are performed consistently and whether the process achieves its purpose.
Useful evidence can include policies, procedures, risk assessments, audit findings, performance reports, records of completed activities, management reviews, and other process-relevant documentation.
The result should be an evidence-based view of the current capability level, not a score based on perception alone.
4. Define the target capability level
The current level tells you where you are. The target level tells you where you need to be.
The target should reflect business requirements rather than an assumption that every process needs to reach level 5.
A highly important process may require a higher target because of its risk, regulatory obligations, or business impact. Another process may not justify the same investment.
For example, if an organization relies heavily on third-party technology providers, it may set a higher target for vendor management and risk processes than for lower-priority processes.
5. Identify the capability gap
Compare the current capability level with the target. Suppose a process is currently at level 2 and the target is level 4. The assessment should not stop at noting a two-level gap.
Break the gap into specific improvements.
| Area | Current state | Target | Main gap | Improvement |
| Risk assessment | Managed | Predictable | Risk performance is not consistently measured | Define metrics and establish quantitative monitoring |
| Risk reporting | Partially standardized | Established | Reports vary between business units | Establish a common reporting process |
| Risk ownership | Assigned | Established | Escalation responsibilities are inconsistent | Formalize ownership and escalation criteria |
This makes the assessment useful for planning, rather than turning it into another compliance scorecard.
6. Prioritize and track improvements
Prioritize improvements based on business impact, risk, regulatory requirements, dependencies, and available resources. Then assign owners, deadlines, milestones, and measures of success.
Make the assessment part of an improvement cycle. Once you implement changes, reassess the relevant processes to determine whether capability has improved and whether the target still makes sense.
Practical example: Assessing a COBIT process
Consider a financial services organization that has experienced recurring findings around technology risk reporting.
The organization assesses its risk management processes and finds that risk assessments are performed, but different business units use different criteria. Reports also vary in format, and senior management does not always receive consistent information about changes in technology risk.
The organization determines that the current process is operating at capability level 2. It sets a target of level 3 because it needs a more consistently defined and organized process.
The assessment identifies several improvements:
- Standardize risk assessment criteria across business units.
- Define consistent reporting requirements.
- Assign clear ownership for risk updates and escalation.
- Establish documented procedures for reviewing changes in technology risk.
- Define measures that management can use to monitor risk performance.
After implementing these changes, the organization can reassess the process and determine whether it has reached the target capability level.
You can then evaluate the broader focus area separately to understand how the related processes perform together.
How to use COBIT assessment results
A COBIT assessment is most useful when the results lead to decisions. You can use the findings to:
- Prioritize improvement initiatives. Focus resources on processes where gaps create the greatest business or risk impact.
- Support management reporting. Give leadership a clearer view of governance and management performance.
- Guide audit planning. Use capability gaps to identify processes that may need additional assurance or review.
- Track improvement over time. Repeat assessments to determine whether changes have improved process capability.
- Support governance decisions. Use evidence from the assessment to determine where additional resources, ownership, or management attention may be required.
Treat the assessment as a management tool rather than a one-time exercise.
Manage COBIT and other frameworks in one place
COBIT is often used alongside other governance, security, and compliance frameworks. CyberArrow helps you manage controls across multiple frameworks, automate evidence collection, and continuously monitor compliance from one platform.
With CyberArrow, you can:
- Keep evidence current: Automated evidence collection across 80+ integrations means your capability picture reflects what’s actually happening, not a snapshot from six months ago.
- Monitor continuously: Move from periodic reassessment projects to ongoing visibility into where capability stands at any time.
- Cross-map your work: Reuse evidence and controls across COBIT, ISO 27001, SOC 2, and NIST instead of reassessing the same processes separately for each framework.
Book your free demo today!
FAQs
What replaced the old COBIT maturity model?
COBIT 2019 replaced the single maturity score per process, used in COBIT 5 and earlier versions, with a two-part performance management scheme. Capability levels (0 to 5) are now assessed per process, and maturity levels are assessed at the focus area level.
How many capability levels are there in COBIT 2019?
COBIT 2019 has six capability levels, ranging from 0 (incomplete) to 5 (optimizing), used to rate how well an individual process achieves its purpose.
Do organizations need to reach capability level 5 for every objective?
No. Set target capability levels based on how important each objective is to the organization, using the same design factors applied when tailoring the governance system. Most organizations target higher capability only for objectives tied to significant business risk or strategic priority.
How often should a COBIT capability assessment be repeated?
There’s no fixed interval defined by COBIT itself, but most organizations reassess periodically, often annually or after major changes, rather than treating an initial assessment as permanent. Capability tends to drift without ongoing monitoring.