Data strategy

Data maturity assessment: what it should produce

October 8, 2026

Somebody has asked you to find out how mature your data estate is, probably because a board paper needs a number. So you go looking for the standard, the way you would look up the Well-Architected pillars for an Azure workload, and you discover something odd: there isn’t one.

That absence is the most useful thing to know before buying a data maturity assessment, because it tells you what you are actually buying. Not a score against a published model. A judgement, from someone who has looked.

There is no Microsoft data maturity model

Microsoft publishes one maturity ladder anywhere near the data estate, and it is not what people think it is. The Fabric adoption roadmap defines five levels: 100 Initial, 200 Repeatable, 300 Defined, 400 Capable, 500 Efficient.

Read what they measure. The roadmap’s own scope is organisational adoption of an analytics tool, which is a question about how people behave around Fabric and Power BI. It is not a measure of whether your data is correct, owned, documented, or fit to build on. Those are different questions and Microsoft does not publish a ladder for them.

Two details worth having when someone quotes those levels at you. Microsoft names a target in writing: “seek to attain at least maturity level 300 or 400”, and says plainly that level 500 across an entire organisation is not a realistic goal. And the levels are not Microsoft’s invention. They come from the Capability Maturity Model, “later enhanced by the Data Management Maturity (DMM) model from ISACA”, with Microsoft noting in the same breath that the DMM “was a paid resource that has since been retired”.

So the one published model that genuinely was about data management maturity is gone. Anyone selling you a score against an industry-standard data maturity model should be asked which standard, and the answer is unlikely to survive the question.

There is also no free Microsoft assessment for a data estate. The assessments catalogue has one for Azure architecture, one for landing zones, one for cloud adoption strategy, and nothing for data governance, data strategy, Fabric or Power BI. If you have run the free Azure assessments and assumed a data equivalent exists somewhere, it does not.

What Microsoft publishes instead, and it is better than a score

The absence of a model is not an absence of guidance. Microsoft’s data guidance in the Cloud Adoption Framework has no levels at all. It has four steps: organisational readiness, architecture, governance and security baselines, and operational standards. And its opening instruction is the one most assessments ignore: do not start with technology.

Organisational readiness breaks into four things, and none of them is a tool choice:

  • Data domain identification. Which parts of the business own which data.
  • Data product prioritisation. What you are actually going to build, in what order.
  • Data domain staffing. Who does it.
  • Skilling. Whether they can.

Microsoft even publishes a template for the central artefact, and it is five columns: business goal, the data domain’s goals, the priority, the data products required, and the data assets those products need. It is unglamorous and it is the right shape, because it forces every proposed piece of work to trace back to something the business said it wanted.

For each data product it then asks four questions: where the data comes from, who is accountable for its quality over time, what capabilities are needed, and what tools. Microsoft notes, mildly, that answering these “might reveal gaps”. In our experience that is where every useful assessment ends up: not in the architecture, but in the second question, because ownership is the one nobody has written down.

What a score is worth, and what it costs to produce

A number is attractive because it travels. “We are at level 2, heading for level 4” fits in a board pack in a way that a list of unowned datasets does not.

The honest position is that a maturity score is a communication device, not a measurement. It is useful for showing movement between two assessments run the same way by the same people. It is close to meaningless as a comparison against another organisation, because there is no shared scale underneath it, and anyone implying otherwise is selling the illusion of a benchmark.

One related trap, because it comes up whenever Purview is in the estate. Purview’s governance score is not an objective grade of how well you govern data. It averages a subset of controls, and the thresholds that turn a number into Healthy or Critical are configured by the customer. It is also an output of a working governance deployment, not an input to a decision about whether to build one: the scoring job only runs once a business domain exists, and the processing is metered. It is a useful operational signal once you are running. It will not tell you where to start.

What the work should actually produce

If not a score, then what. Four things, and a buyer should be able to see all four named in a proposal:

  1. A domain map with names against it. Which data belongs to which part of the business, and which named person is accountable for each. Not a team. A person.
  2. A prioritised data product list that traces to business goals, in the shape of Microsoft’s own template, so that every item can be challenged on its stated value rather than defended on technical merit.
  3. The gaps that fell out of doing the first two. Where the data does not exist, where two systems disagree, where nobody owns the answer.
  4. A sequence, with the first thing in it small enough to finish. We have written separately about what the first six weeks of a Fabric implementation should deliver, and the principle is the same here: the plan is proved by one thing in production, not by the plan.

What should not be in it: a tooling recommendation reached before the domain map, and a score with no method attached.

Our position: the deliverable is an owner, not a number

In our view a data maturity assessment that ends in a score and a roadmap has produced the easy half. The half that changes anything is a named owner against each data domain, agreed by the people being named, before the assessment is signed off.

The reason is unglamorous. Every data problem we are called in to fix eventually reduces to a question nobody can answer: who decides what this field means. Architecture does not fix that. A platform migration does not fix it either, which is why estates arrive at a Synapse to Fabric move carrying the same ambiguity they had before, now in a newer product. Ownership is the only part of the work that survives the next re-platforming.

The corollary is uncomfortable for us as much as anyone: if a client will not name owners, the assessment should say so in the readout rather than papering over it with a roadmap. A roadmap for an estate with no owners is a document that will be true for about a quarter.

Where to start

Three steps, and the first two are free:

  1. Write down your top five business goals, then try to fill in Microsoft’s five columns against them. The columns you cannot fill are the finding.
  2. Pick one data product and answer the four questions: sources, owner, capabilities, tools. If the owner question stalls, you have learned the most important thing before spending anything.
  3. Then decide whether you need help, and scope it to the questions you could not answer rather than to a framework.

Veratas runs a fixed-fee data strategy assessment that produces the domain map, the prioritised product list and the sequence, and our data platform assessment covers the technical half when that is the question. If you want a second opinion on a proposal you already have, talk to our team.

Frequently asked questions

Is there a Microsoft data maturity model? No. The only maturity ladder Microsoft publishes nearby is the Fabric adoption roadmap, which measures organisational adoption of an analytics tool rather than the condition of a data estate. Its five levels come from the Capability Maturity Model, and the ISACA data management model they reference has been retired.

What maturity level should we aim for? For Fabric adoption specifically, Microsoft says to seek at least level 300 or 400 of its five, and says level 500 across an entire organisation is not realistic. That is advice about analytics adoption, not about data quality or governance.

Is there a free Microsoft assessment for our data estate? No. Microsoft publishes free assessments for Azure architecture, landing zones and cloud adoption strategy, but the catalogue has nothing for a data estate, data governance, Fabric or Power BI.

Does the Purview governance score tell us how mature we are? Not in the way the name suggests. It averages a subset of controls, its health thresholds are set by the customer, and it only produces anything once a governance deployment is running. It is an operational signal, not a starting diagnosis.

What should a data maturity assessment deliver? A domain map with named owners, a prioritised list of data products traced to business goals, the gaps that emerged from building both, and a sequence whose first step is small enough to finish.

How long does an assessment take? Ours runs in weeks rather than months, and the limiting factor is almost never analysis. It is how quickly the people who own the answers can be got into the same room.