HomeBlogITAM Maturity Model
Redress Compliance  |  Research Note  |  ITAM Maturity 2026

ITAM Maturity in 2026: The Five Stages, What Each One Is Worth, and How to Move Up

Most enterprise ITAM programs sit at stage 1 or 2 of a five stage model, and they pay for it at every renewal and in every audit. This note sets out the five stages, what each is worth, how to score your estate in ten working days, and the moves that take it up one stage a year.

A research note for CIOs, IT asset managers, software asset managers, procurement leaders and finance controllers who own software spend and want a maturity model that produces money rather than a scorecard. It is not tied to any single client situation. Written from the buyer's side of the table. Redress Compliance, 2026.

Prepared by Redress Compliance · September 2, 2026 · Written by Morten Andersen, Co Founder. Based on the 40 to 55 ITAM maturity assessments Morten Andersen ran across 2024 to 2025.

Key takeaways

  • An ITAM maturity model is a statement about how much of your software estate you can prove, not how many tools you own. The five stages are Reactive, Inventoried, Reconciled, Managed and Commercial. An estate's stage is set by the weakest of six domains, never by the average.
  • Roughly two of every three estates assessed in 2024 to 2025 sat at stage 1 or 2. Most of them owned a discovery tool. Almost none had an entitlement record that could survive an audit letter.
  • The money is concentrated in one transition. Moving from stage 2 to stage 3, the first real reconciliation, recovered 8 to 14 percent of addressable spend within twelve months. Every later transition pays less and protects more.
  • Vendors already know your stage. An audit notice, an unsolicited true up proposal or a collaborative baseline request is priced on the assumption that you cannot count. Every stage you climb changes the opening number the vendor puts on the table.
  • You can score your own estate in ten working days with the six domain rubric in section 4. The scoring needs evidence, not opinions: a contract you can produce, a count you can reproduce, a decision you can trace.
  • Buy the tool last. The most common failure pattern was a stage 1 estate buying a stage 4 platform and spending eighteen months tuning discovery while the top three vendors renewed on the vendor's numbers.
2 of 3
Estates assessed in 2024 to 2025 that scored stage 1 or 2 overall, most of them with a discovery tool already deployed.
15 to 30%
The gap between deployed and entitled quantities on the largest vendor, found at the first real reconciliation.
8 to 14%
Addressable spend recovered in the first twelve months after an estate moved from stage 2 to stage 3.
10 days
The working time needed to score all six domains with evidence, using the rubric in this note.

Part one: the model

1.

What an ITAM maturity model is, and what it is not

An ITAM maturity model is a graded description of how well an organization can prove what software it runs, what it is entitled to run, and what the difference costs. The word prove carries the weight. Every stage in the model is defined by the quality of evidence an estate can produce on demand.

Evidence is the common currency because it is what an auditor, a vendor account team and a chief financial officer all ask for. A stage is not a feeling about how organized the team is. It is a measure of what leaves the building when someone asks for a number.

The model in this note has five stages and six domains. The domains are inventory, entitlement, reconciliation, process, tooling and commercial governance. An estate's stage is the lowest domain score, not the average, because a vendor attacks the weakest domain and ignores the others.

What the model is not

It is not a tool selection guide, although it tells you when a tool will pay. It is not a conformance certificate. ISO/IEC 19770-1:2017 defines the management system requirements for IT asset management in three tiers, and the model here maps loosely to those tiers, but it measures money rather than conformance.

It is not a one time project either. Estates that treated the assessment as a project, scored themselves, and moved on drifted back one stage within two years in our engagements. Positions went stale, owners changed roles, and the next audit letter found a stage 1 estate with a stage 3 report on file.

The NIST National Cybersecurity Center of Excellence publishes a reference architecture for IT asset management that treats the asset inventory as a security control. The same inventory is the first commercial control. An organization that cannot enumerate its servers for its security team cannot enumerate them for Oracle either.

Why the stage matters more in 2026 than it did five years ago

Vendors have industrialized compliance. Oracle's Java employee metric, IBM's collaborative baseline, Microsoft's move of smaller Enterprise Agreement customers to CSP and MCA E, Broadcom's VMware subscription conversion and the Red Hat subscription review program run through Deloitte all share one premise. The premise is that the customer cannot count.

The maturity stage is a measure of whether that premise is true for you. Where it is true, the vendor's opening number stands. Where it is false, the opening number falls before the negotiation begins, because the account team knows the customer will produce its own count and will dispute the difference.

The stage that matters is the one the vendor sees. In every audit and every unsolicited true up proposal we reviewed in 2024 and 2025, the vendor's opening number was built on the assumption that the customer could not reproduce its own deployment count. Where the customer could, the opening number fell before anyone sat down.

The corollary is uncomfortable. A maturity program that produces dashboards nobody outside the ITAM team sees has not changed the stage the vendor sees, and has not changed the price.

2.

The five stages

The five stages run from Reactive, where nobody counts until a vendor does, to Commercial, where the count drives the negotiation calendar. Each stage is defined by an artifact the estate can produce and by what the vendor sees when it looks in.

StageWhat it looks likeWho owns itWhat the vendor sees
1. ReactiveNo maintained inventory. Entitlement lives in email and reseller portals. The first count happens when an audit letter arrives.Nobody, or a part time role inside IT operations.A customer that will accept the vendor's count.
2. InventoriedA discovery tool reports installations. Entitlements are partly collected. Nobody reconciles the two on a schedule.An ITAM analyst inside infrastructure or service management.A customer with data but no position.
3. ReconciledEvery top vendor has an effective license position, refreshed at least quarterly, with that vendor's contractual counting rules applied.A named SAM manager with a vendor by vendor calendar.A customer that will dispute the number.
4. ManagedPositions feed decisions: renewal quantities, decommissioning, architecture choices and audit responses, all with a documented workflow and owners.A SAM function with procurement and architecture in the same review.A customer that will negotiate on evidence.
5. CommercialThe license position is a negotiating asset. Benchmarks, scenario models and exit options are costed before every renewal, and the vendor's calendar no longer sets yours.A licensing and negotiation capability reporting to the CIO or CFO, usually with an outside advisor.A customer that sets the terms of the conversation.

Stage 1: Reactive

A stage 1 estate discovers its software when a vendor tells it what it runs. The pattern is consistent. Procurement holds the purchase orders, IT holds the servers, nobody holds the entitlement, and a reseller portal is treated as the license record. When an audit notice arrives, the first inventory is run by the auditor's scripts.

The cost of stage 1 is not the audit settlement alone. Every renewal is quoted on the vendor's count, and the vendor's count is never low. In the stage 1 estates we assessed, top vendor renewal quantities ran 10 to 25 percent above what a later reconciliation supported.

Stage 1 is also where the tier two vendors live even in otherwise capable organizations. The estate may have a good Microsoft position and no idea what it owes Micro Focus, Quest or Veeam, and those vendors generate a large share of audit letters precisely because their customers do not count them.

Stage 2: Inventoried

A stage 2 estate can list its installations but cannot say which ones are licensed. This is where most enterprises live. A discovery tool, often the one bundled with the service management platform, reports installed software. An analyst exports a spreadsheet. The entitlement side is half collected: contracts for the big vendors, nothing for the rest.

The trap is that stage 2 feels like progress. The dashboard is green, the count is large, and the reconciliation that would turn the count into a position never happens because it requires reading contracts. Stage 2 estates pay the same renewal premium as stage 1 and add the cost of the tool.

A second trap is that the discovery number leaks. An installation count without the contract's counting rules applied is a claim, and once it has been shared with an account team in good faith it becomes the vendor's baseline. Several stage 2 estates we assessed had handed the vendor a number that was higher than their true licensable use.

Stage 3: Reconciled

A stage 3 estate can produce a defensible license position for every vendor that matters, on demand. The defining artifact is an effective license position: deployment count, entitlement count, the contractual counting rules applied, the delta, and the evidence behind each line. It exists for the top vendors by spend and by audit risk.

The position is refreshed on a schedule that matches the renewal calendar, not the ITAM team's convenience. A position that is older than the last renewal is a historical document, and an auditor will treat it as one.

This is the stage where the money appears. Reconciliation finds shelfware, wrong editions, unlicensed use that can be fixed before disclosure and, most often, quantities the vendor quoted that the estate never needed. Section 3 puts ranges on each of those.

Stage 4: Managed

A stage 4 estate uses its license positions to make decisions rather than to answer questions. Renewal quantities come from the position, not from last year's order form. Architecture reviews check licensing impact before a virtualization host is added or a database edition is upgraded. Audit responses follow a written procedure that routes the notice to the contract owner.

Stage 4 is an organizational achievement more than a technical one. It requires procurement, architecture and ITAM in the same review with the same data, and it requires an executive who will hold them there when the vendor tries to route around the group and sell directly to a business unit.

The sign that an estate has reached stage 4 is a renewal that closed at a lower quantity than the previous one, with a written explanation of why, and nobody outside the review being surprised by it.

Stage 5: Commercial

A stage 5 estate treats every license position as an input to a negotiation it planned a year ago. Benchmarks are collected before the renewal, not requested from the vendor. Exit options are costed so the walk away is real. Contract terms, not just prices, are on the negotiating list: audit clauses, metric definitions, price caps and transfer rights.

Very few internal ITAM teams reach stage 5 on their own, and they should not be expected to. The skills are negotiation and vendor intelligence, which are exercised a few times a year per vendor inside one organization and every week inside an advisory practice.

That is why this note describes stage 5 as a commercial capability rather than an ITAM one, and why the practical target for an internal program is a durable stage 4 with the commercial layer bought in for the renewals that justify it. Section 6 returns to this point, because the common advice gets it wrong.

3.

What each stage is worth

The money in an ITAM maturity model is front loaded. The first reconciliation pays the most, and every later stage pays less but protects more. The ranges below are what we observed across the 2024 to 2025 assessments, expressed as a share of addressable spend.

TransitionRecovered spend, observed rangeWhere the money comes fromTime to bank
Stage 1 to 20 to 3 percent of addressable spendDecommissioning obviously dead installations and cancelling maintenance on retired products.3 to 6 months
Stage 2 to 38 to 14 percentRenewal quantities corrected, shelfware reclaimed, editions right sized, audit exposure fixed before disclosure.6 to 12 months
Stage 3 to 43 to 6 percentArchitecture decisions that avoid licensing cost, audit settlements avoided or reduced, contract terms actually enforced.12 to 24 months
Stage 4 to 55 to 12 percent at the renewals it touchesBenchmarked pricing, costed alternatives and terms that cap future increases.Each renewal cycle

How to read the ranges

Addressable spend is the annual software spend with the vendors covered by the program, not the whole IT budget. In the estates we assessed it ran 30 to 60 percent of total software spend at stage 2, because the tier two vendors were not covered, and above 85 percent at stage 4.

The ranges are wide because the starting estates were different. An estate with a large Oracle or IBM footprint recovered at the top of the stage 2 to 3 range because those vendors' counting rules create the largest gaps.

An estate that was mostly SaaS recovered at the bottom, because SaaS overspend is subscription quantity, which is easier to see and smaller per line.

Time to bank is the interval between doing the work and seeing the money in a lower invoice. It is set by the renewal calendar, not by the ITAM team's speed. That is why the first action in section 7 is to build the renewal calendar before anything else.

The protective value the table does not show

Stage 3 and above changes the audit outcome, and over five years that is worth more than the recovered spend. In our engagements, audits that arrived at a stage 3 or higher estate closed at 20 to 40 percent of the vendor's opening claim. At stage 1 the same kind of letter closed at 60 to 90 percent.

The difference is not negotiating skill. It is that a stage 3 estate answers the letter with its own position and its own evidence, and the auditor's findings have to be reconciled against something. At stage 1 there is nothing to reconcile against, so the findings stand.

There is a second protective effect that is harder to price. Vendors track which customers dispute numbers. An estate that has disputed once, with evidence, receives fewer speculative true up proposals afterwards. Several stage 4 clients told us the unsolicited proposals simply stopped.

1 Reactive 2 Inventoried 3 Reconciled 4 Managed 5 Commercial 0 to 3% 8 to 14% 3 to 6% 5 to 12% Recovered share of addressable spend at each transition, observed 2024 to 2025 Stage is set by the lowest of six domain scores: inventory, entitlement, reconciliation, process, tooling, commercial governance
Figure 1. The five stages as a staircase, with the observed recovery at each transition. The ranges come from the 40 to 55 maturity assessments Redress ran in 2024 and 2025. The stage 2 to 3 step is the largest because it is the first time the contract's counting rules are applied to the deployment count.
Try Vera AI · free 30 day trial
Vera benchmarks your next three renewals against real closed deals in minutes.
  • Percentile standing for your exact deal size and industry, from real closed transactions
  • Scenario simulation before the call: test alternative quantities and terms and see the financial impact of each
  • A negotiation playbook, talking points, and a two page executive brief on day one
Start the free Vera AI trial →30 days free · no credit card · cancel anytime

Part two: the assessment

4.

The six domains and how to score them

Score each of the six domains from 1 to 5 against evidence, and take the lowest score as the estate's stage. The rubric below gives the evidence expected at stages 1, 3 and 5. Stages 2 and 4 are the points between them, and an honest scorer will find most domains land there.

DomainStage 1 evidenceStage 3 evidenceStage 5 evidence
InventoryAd hoc scans. No coverage figure anyone will defend.Discovery covers over 95 percent of servers and endpoints, the gaps are listed, and the data is refreshed monthly.Coverage includes cloud accounts, containers and SaaS tenants, reconciled to the CMDB and to finance.
EntitlementContracts in email. The reseller portal is treated as the record.Every top vendor contract, order and amendment sits in one repository with the metric definition extracted.The entitlement record includes terms, caps, transfer and audit clauses, versioned and searchable by anyone who needs it.
ReconciliationNone, or once, during an audit.An effective license position per top vendor, quarterly, with counting rules applied and evidence linked to each line.Positions are modeled forward: growth, architecture changes and exits are costed before each renewal.
ProcessNo owner. Audit notices go to whoever received them.Written procedures for audit response, renewal preparation and deployment approval, with named owners.Procedures are measured. Vendor contact is routed through one channel. Lessons feed back into contracts.
ToolingSpreadsheets and the discovery built into the service platform.A SAM tool or a disciplined data set that stores entitlements and produces positions, reviewed by a person who has read the contract.Tooling integrated with procurement, the CMDB and finance. Benchmarks and scenario models are maintained.
Commercial governanceRenewals signed by whoever is asked. No benchmark.Renewals over a threshold go through a review with ITAM, procurement and the budget owner, using the position.Every renewal above threshold has a costed alternative, a benchmark and a negotiation plan twelve months out.

The ten working day self assessment

The assessment is designed to be run by one person with authority to ask for documents, in ten working days, without buying anything. It produces a one page result that a CIO can act on.

  1. Days 1 and 2. List the top twelve vendors by annual spend and by audit risk. That is the scope. Pull the last invoice and the last signed contract for each one, and note how long each document took to find.
  2. Days 3 and 4. For each vendor, ask for the current license position. Score what arrives, not what is promised. A position that cannot be reproduced from its inputs scores as no position.
  3. Days 5 and 6. Run the inventory coverage test. Take fifty random servers and endpoints from the CMDB or the hypervisor and check whether the discovery tool reports them, with the right software.
  4. Day 7. Find the entitlement record for three orders chosen at random from accounts payable. Time how long it takes and note who had to be asked.
  5. Day 8. Read the audit clause and the metric definition for the top three vendors. Note whether anyone still in the organization had read them before, and who owns the response if a notice arrives tomorrow.
  6. Day 9. Score all six domains against the rubric with the evidence collected. Take the lowest score as the stage. Resist the average.
  7. Day 10. Write the one page result: the stage, the domain that set it, the three vendors where the gap is largest, and every renewal date in the next eighteen months.

The rule about the lowest score matters because vendors do not average. An estate with stage 4 tooling and stage 1 entitlement is a stage 1 estate to an auditor, who will ask for the contracts and get silence. The platform's dashboard does not attend the audit meeting.

Scoring traps that flatter the estate

Three scoring habits produced a stage higher than the evidence supported in the assessments we reviewed. The first was counting a tool's presence as a capability. Owning a SAM platform is stage 2 tooling until it has produced a position someone has defended.

The second was scoring on the best vendor. A strong Microsoft position and nothing else is a stage 1 estate with one stage 3 vendor. The third was accepting a verbal description of a process as a process. If the audit response procedure is not written down, the first audit will show that it does not exist.

5.

What we saw across ITAM maturity assessments, 2024 to 2025

Across the 40 to 55 maturity assessments Morten Andersen ran in 2024 to 2025, the same four findings appeared in almost every estate, regardless of industry or size. The estates ranged from 2,000 to 90,000 employees across financial services, manufacturing, retail, healthcare and the public sector.

2 of 3
Estates at stage 1 or 2

The share of assessed estates whose lowest domain score was 1 or 2, most often entitlement or reconciliation.

15 to 30%
The gap on the largest vendor

Deployed against entitled quantity at the first reconciliation, split roughly evenly between exposure and shelfware.

Finding one: tooling ran ahead of everything else

More than half the estates owned a dedicated SAM platform, and in most of them the platform was the highest scoring domain. Entitlement and reconciliation were the lowest. The tool was counting installations of software nobody had a contract for, and producing confident reports about it.

The pattern had a cause. A platform is a purchase, and purchases are easy to approve. A reconciliation is a discipline, and disciplines need an owner, a calendar and an executive who asks for the result. The platform was bought in place of the owner.

Finding two: the gap on the largest vendor was 15 to 30 percent in either direction

Roughly half the gaps were over deployment, meaning compliance exposure, and half were over licensing, meaning shelfware. The estate did not know which until the reconciliation was done. The vendor only ever raised the first kind.

The shelfware half is the part most programs miss. An estate that only reconciles when a vendor asks will only ever find exposure, because the vendor's process is built to find exposure. The quantity reductions that pay for the program are found by the estate's own reconciliation, run on the estate's own calendar.

Finding three: the audit clause had not been read

In the ITAM maturity assessments Morten Andersen ran in 2024 to 2025, the audit and verification clauses for the top three vendors had been read by someone still in the organization in fewer than one in four estates. The contract owner was usually procurement. The data owner was IT. Neither had read the other's document.

This matters because the clause defines what the vendor may ask for, on what notice, and at whose cost. An estate that has not read it provides whatever is requested. An estate that has read it provides what is owed. The difference in a Passport Advantage review or an Oracle audit is measured in months and in millions.

Finding four: the renewal calendar did not exist as a single artifact

Renewal dates lived in the vendors' systems and in individual inboxes. Notice periods were discovered when they had passed. The estates that moved fastest to stage 3 all started by building the calendar, because it told them which reconciliation to do first and how long they had to do it.

The calendar also exposed the auto renewals. In several estates, a subscription that nobody had reviewed for three years was renewing at an uplift each year because the notice date was never on anyone's list. Building the calendar was the cheapest recovery in the whole program.

Vendors run the same assessment on you. An account team that sends an unsolicited true up, a collaborative baseline request or a subscription review is scoring your entitlement and reconciliation domains from the outside. If the request goes to the ILMT administrator or the Linux team rather than the contract owner, they already know the answer.

The buyer side response is the same for every vendor: route the request to the contract owner, read the contract, run your own count before disclosure, provide exactly what is owed, agree nothing, and move every finding into the renewal on your own calendar.

6.

Where the common advice on ITAM maturity is wrong

Most published maturity models are written by tool vendors or by consultancies that sell the program, and their advice reflects that. Four pieces of common advice cost buyers money in the estates we assessed, and each has a better alternative.

Where the common advice on tooling is wrong

The common advice says buy a SAM platform first. The evidence says buy it after the first manual reconciliation of the top three vendors. A platform automates a process. At stage 1 there is no process to automate, so the platform produces a large, confident and wrong number.

The estates that bought first spent twelve to eighteen months tuning discovery and normalization while the renewals that would have paid for the program went through on the vendor's count. The tool was not at fault. It was asked to answer a question nobody had defined.

Do the first reconciliation for the top three vendors by hand, with the contracts open. It takes six to ten weeks. The output tells you exactly which data the tool must collect and which counting rules it must apply. Our review of tool output against reviewed positions found the gap was always interpretation, never discovery.

Where the common advice on stage five is wrong

The common advice treats stage 5 as the destination for the ITAM team. In practice stage 5 is a negotiation capability that most ITAM teams should not try to build. The skills that produce stage 5 outcomes are pricing intelligence, contract drafting and negotiation choreography, and they are exercised a few times a year per vendor.

An internal team that negotiates Oracle once every three years cannot hold a benchmark current. An advisor that negotiates Oracle every month can. The right target for an internal program is a durable stage 4, with the commercial layer bought in for the renewals that justify it.

Attempting stage 5 internally produced, in the cases we saw, stage 3 with a benchmarking subscription and a team that had stopped refreshing positions because it was busy building negotiation decks. The trigger events for hiring an advisor are the same events that mark the stage 4 to 5 boundary.

Where the common advice on the CMDB is wrong

The common advice says fix the CMDB first. The money says reconcile the top vendors first and let the reconciliation fix the CMDB. A complete CMDB is a multi year program with its own owners and its own failures, and licensing cannot wait for it.

Licensing needs a complete count for a handful of products, and the fastest way to get one is a targeted discovery for those products, checked against the hypervisor, the cloud accounts and the vendor's own tooling: Oracle's audit scripts, IBM's ILMT, Microsoft's admin center exports. That count is defensible in weeks.

Every product level reconciliation surfaces CMDB gaps in the servers that matter, which is a better prioritization than any CMDB program produces on its own. The CMDB improves as a by product of the reconciliation rather than as a precondition for it.

Where the common advice on audits is wrong

The common advice says an audit is an ITAM failure. The estates with the best outcomes treated the audit as a scheduled event they had already prepared for. Audits arrive on the vendor's cycle, not on yours, and the top five vendors audit or review most large customers within any five year window.

A stage 3 estate answers the letter with its own position. A stage 1 estate answers it with the auditor's scripts. The preparation is the reconciliation, done before the letter, and the response procedure is written before it is needed. The audit defense practice sets out the response by vendor.

Part three: moving up

7.

Stage by stage: how to move up

Each transition has one artifact that proves it, and building that artifact is the whole of the work. The sequence below is the one that moved estates up one stage a year in our engagements. Estates that skipped a step usually came back to it.

From stage 1 to stage 2: the renewal calendar and the coverage figure

The artifact is a single renewal calendar for the top twelve vendors, with contract end dates, notice periods and the last invoice value, plus an inventory coverage figure you can defend. Do not start with a tool. Start with the hypervisor exports, the cloud account lists and the endpoint management console, and state what share of the estate they cover.

Collect the contracts as you go. Every order, every amendment, every click through terms page for the top twelve vendors goes into one repository with one owner. This is unglamorous work and it is the foundation of every later stage. An entitlement record that lives in a reseller's portal is not yours.

Time: eight to twelve weeks with one dedicated analyst and the cooperation of procurement. Cost: mostly time. Money recovered: dead installations and maintenance on retired products, usually 0 to 3 percent of addressable spend, and the auto renewals the calendar catches.

From stage 2 to stage 3: the first three effective license positions

The artifact is an effective license position for each of the top three vendors by spend, produced with the contracts open. For Oracle that means processor and Named User Plus rules, the partitioning policy and the Java employee definition. For Microsoft it means the Product Terms applied to servers, client access licenses and Microsoft 365 assignments.

For IBM it means PVU counting, sub capacity eligibility and the ILMT reports the contract requires you to retain. For SAP it means named user classification and digital access. Each vendor's counting rules are different, and the position is only defensible when the right rules have been applied to the right count.

Each position lists deployment, entitlement, the counting rule, the delta and the evidence. Where the delta is exposure, remediate before anyone outside the organization sees it. Where the delta is shelfware, take it into the next renewal as a quantity reduction, with the evidence attached.

Time: six to ten weeks per vendor, run in parallel by one analyst per vendor with an advisor reviewing the counting rules. This is the transition that pays: 8 to 14 percent of addressable spend within twelve months in our assessments, most of it at the first renewal after the position existed.

From stage 3 to stage 4: the review that uses the position

The artifact is a written renewal and audit procedure, and a review that meets on the calendar. Every renewal above a threshold, for most enterprises $250,000 a year, is presented with the current position, the proposed quantity and the difference between them. Every audit notice is routed to the contract owner within one working day.

The change is organizational. ITAM produces the position, procurement runs the negotiation, architecture signs off on deployment changes that affect licensing, and finance sees the number before the order. The executive sponsor's job is to stop the vendor routing around this group, which every vendor will try.

Time: two to four renewal cycles for the review to become habit. Money: 3 to 6 percent of addressable spend, plus the audit settlements that never happen because the estate answered the letter with its own numbers.

From stage 4 to stage 5: the costed alternative and the benchmark

The artifact is a negotiation plan per major renewal, built twelve months out, with a benchmark of what comparable buyers paid, a costed alternative the organization would actually execute, and a list of terms to change. The alternative has to be real. A walk away the vendor knows you will not take is not leverage.

This is where an outside advisor earns the fee, because the benchmark and the alternative are the two things an internal team cannot keep current between renewals. The Renewal Program and the Benchmark Program are how we deliver this layer, and the ITAM team's stage 4 positions are the input they require.

Time: one renewal cycle per vendor to establish, then continuous. Money: 5 to 12 percent at the renewals it touches, which for the top three vendors is most of the addressable spend. The terms negotiated at this stage, price caps and metric definitions in particular, protect the next two renewals as well.

8.

What maturity changes at the negotiating table, vendor by vendor

The same maturity stage produces a different outcome with each vendor, because each vendor's compliance motion attacks a different domain. The table maps the motion, the domain it targets and what changes once the estate reaches stage 3.

VendorThe compliance motionThe domain it attacksWhat stage 3 changes
OracleAudit under the license agreement, Java download logs, ULA certification.Entitlement and reconciliation: processor counting, partitioning, the Java employee definition.You bring the count. The employee number moves 18 to 28 percent. The ULA certification is planned rather than survived.
MicrosoftTrue ups, SAM engagements, the move from EA to CSP and MCA E.Reconciliation: assignment data against the Product Terms.Renewal quantities come from usage, not the last order. The vehicle change is sequenced on your calendar.
IBM and Red HatFormal license review, collaborative baseline, Red Hat subscription reviews delivered by Deloitte.Process and entitlement: ILMT reports, sub capacity terms, who responds.The request is routed to the contract owner. The baseline is yours. The two motions are negotiated as one.
SAPLicense measurement, digital access, RISE conversion proposals.Reconciliation: named user classification and indirect use.User classification is defended before measurement. RISE is priced against the position, not against fear.
Broadcom and VMwareSubscription conversion, core minimums, portfolio bundling.Inventory: cores per host and cluster design.Core counts are yours. The bundle is evaluated against a costed alternative.
ServiceNow, Salesforce, WorkdayRenewal uplift, unassigned licenses, module bundling.Commercial governance: usage against subscription.Unassigned and dormant seats leave the order before the uplift is applied.

Two observations follow from the table. The first is that no single domain protects against every vendor, which is why the stage is the lowest domain score. An estate with excellent reconciliation and no process still hands IBM a validated baseline from the ILMT administrator's inbox.

The second is that the vendors with the largest opening claims, Oracle and IBM, attack the domains that are hardest to build, entitlement and reconciliation. That is not a coincidence. Their commercial models depend on the customer's inability to apply the counting rules, and the Oracle and IBM practices exist because those rules are where the money is.

The enterprise buyer guide to the ITAM maturity model covers the payback roadmap by stage in more detail, and the license optimization playbook sets out where the reclaimed quantity came from across the 2024 to 2025 engagements.

9.

Mistakes that cost the most

10.

What to do next

  1. Build the renewal calendar for the top twelve vendors this week, with end dates, notice periods and last invoice values. It is the cheapest recovery in the program and it sets the order of everything else.
  2. Run the ten working day self assessment in section 4 and take the lowest domain score as the stage. Write the one page result and give it to the CIO.
  3. Reconcile the top three vendors by hand, with the contracts open, before any tool decision. Six to ten weeks per vendor, in parallel, is the transition that pays.
  4. Remediate exposure before disclosure and carry shelfware into the next renewal as a quantity reduction with the evidence attached.
  5. Write the audit response and renewal review procedures and name the owners. Route every vendor request through the contract owner from now on.
  6. Decide the tool after the first positions exist, when you know which data it must collect and which counting rules it must apply.
  7. Buy the commercial layer for the renewals that justify it, and keep the internal target at a durable stage 4. The SAM consulting practice runs the program with you.
11.

How Redress helps

Redress Compliance runs the maturity exercise from the buyer's side: the six domain assessment with evidence, the first reconciliations for the top vendors with the contracts open, the audit and renewal procedures, the tool decision once the positions exist, and the commercial layer for the renewals that justify it.

Our fees are fixed, and every dollar removed from a vendor's number belongs to the client.

For estates that already have positions, the Vendor Shield program keeps them current across the top vendors and answers the audit letter when it arrives. For estates starting at stage 1, the first engagement is usually the calendar, the contracts and three positions, delivered in a quarter.

The International Association of IT Asset Managers publishes the practitioner body of knowledge that our assessment vocabulary is aligned to.

Free white paper

Enterprise SAM and ITAM governance

How mature buyers stand up software asset management to control cost, reclaim shelfware and defend against audits across every vendor in the estate. The operating model behind the stages in this note.

Get the white paper →
12.

Frequently asked questions

What is an ITAM maturity model?

An ITAM maturity model is a graded description of how well an organization can prove what software it runs, what it is entitled to run, and what the difference costs. The model in this note has five stages, Reactive, Inventoried, Reconciled, Managed and Commercial, scored across six domains.

The stage is the lowest domain score, not the average, because vendors attack the weakest domain and ignore the rest.

What are the five stages of ITAM maturity?

Reactive, where nobody counts until a vendor does; Inventoried, where a discovery tool reports installations but nobody reconciles them to entitlements; Reconciled, where every top vendor has a defensible license position; Managed, where positions drive renewal, architecture and audit decisions; and Commercial, where the position is a negotiating asset with benchmarks and costed alternatives.

Roughly two of three estates assessed in 2024 to 2025 sat at stage 1 or 2.

How do you assess ITAM maturity?

Score six domains, inventory, entitlement, reconciliation, process, tooling and commercial governance, from 1 to 5 against evidence, and take the lowest score as the stage. The ten working day method in this note pulls contracts and invoices for the top twelve vendors, tests inventory coverage on fifty random machines, and times how long an entitlement record takes to find.

Score what can be produced, never what is described.

How much does moving up a maturity stage save?

The stage 2 to 3 transition recovered 8 to 14 percent of addressable spend within twelve months in our 2024 to 2025 assessments, because it is the first time the contract's counting rules are applied to the deployment count.

Stage 1 to 2 recovered 0 to 3 percent, stage 3 to 4 recovered 3 to 6 percent, and stage 4 to 5 recovered 5 to 12 percent at the renewals it touched.

Audits at stage 3 or above closed at 20 to 40 percent of the vendor's opening claim, against 60 to 90 percent at stage 1.

Should we buy a SAM tool before assessing maturity?

No. Reconcile the top three vendors by hand with the contracts open first, six to ten weeks per vendor, and buy the tool once you know which data it must collect and which counting rules it must apply.

Estates that bought first spent a year or more tuning discovery while the top renewals went through on the vendor's count.

The tool automates a process, and at stage 1 there is no process to automate.

How does this model relate to ISO/IEC 19770-1?

ISO/IEC 19770-1:2017 defines management system requirements for IT asset management in three tiers, and this model maps loosely to them: stages 1 and 2 sit below tier 1, stage 3 corresponds to a trustworthy data tier, and stages 4 and 5 to lifecycle integration and optimization. The difference is what is measured.

The standard measures conformance; this model measures money recovered and the outcome of the next audit.

© 2026 Redress Compliance LLC · 1314 E Las Olas Blvd, Fort Lauderdale, FL 33301 · 100 percent buyer side, zero vendor affiliationsredresscompliance.com
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent
Free White Paper

Enterprise SAM and ITAM governance: the operating model behind the stages.

How mature buyers stand up software asset management to control cost, reclaim shelfware and defend against audits across every vendor in the estate.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
Independent, buyer side. We never share your details with vendors.
Score your estate against the six domains, then run the software spend health check in minutes.
Open the Tool → SAM Advisory →
Deep Library

More on this topic.

SAM Consulting →
ITAM Maturity Model: Enterprise Buyer Guide
Software Asset Management · Guide
ITAM Maturity Model: Enterprise Buyer Guide
The payback roadmap by stage, in more detail.
Guide
Software Asset Management Tools Guide 2026
Software Asset Management · Guide
Software Asset Management Tools Guide 2026
Tool categories, fit by estate, and the build versus buy math.
Guide
The Largest Savings Came From Reclamation, Not Discount
Software Asset Management · Guide
The Largest Savings Came From Reclamation, Not Discount
Where the reclaimed quantity came from across the 2024 to 2025 engagements.
Guide
The Gap Was Always Interpretation, Never Discovery
Software Asset Management · Guide
The Gap Was Always Interpretation, Never Discovery
Tool output against reviewed positions on the largest vendor.
Guide
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of vendor audits and renewal moves.

One buyer side briefing a week. Audit signals, renewal levers, and the counting rules that decide the number. No vendor spin.