14.2 Capability Levels 0–5 and Maturity
Key Takeaways
- Official figure 6.2 characteristics in Introduction and Methodology are the source of truth for Levels 0–5; short labels are aliases, not a second scale.
- Capability is a 0–5 rating of how well a process is implemented.
- Maturity is how a focus area — a collection of objectives — achieves a capability level. Capability and maturity are not synonyms.
- Process activities are associated with capability levels; design sets a higher target on high-priority objectives.
- Level 5 Optimizing is not the default target. You do not need every process at level 5.
Quick Answer: Capability is how well a process is implemented on a 0–5 scale. Maturity is how a focus area (a collection of objectives) achieves a capability level. Official Introduction and Methodology figure 6.2 characteristics are the source of truth: 0 Incomplete, 1 incomplete / initial or intuitive, 2 basic yet complete (performed), 3 organizational assets / well defined (Established), 4 quantitatively measured (Predictable), 5 Optimizing. Short labels vary. You do not need every process at level 5.
Section 14.1 gave you the ruler. This section is the scale printed on it. Foundation items in the 4% Performance Management domain almost always test three things: the figure 6.2 characteristics, the capability-versus-maturity split, and the fact that design sets targets — Level 5 is not a default.
Official characteristics first (figure 6.2)
ISACA’s 2019 article “Defining Target Capability Levels in COBIT 2019” quotes figure 6.2, Capability Levels for Processes, from COBIT 2019 Framework: Introduction and Methodology. Prefer this language when a stem describes a level. Names on slides are aliases.
| Level | Official characteristic (source of truth) | Common Foundation short labels | CMMI-style name that can trap you |
|---|---|---|---|
| 0 Incomplete | Lacks basic capability; incomplete approach to the governance and management purpose; may or may not meet the intent of any process practices | Incomplete | Incomplete (same word, still means “not there”) |
| 1 | More or less achieves its purpose through an incomplete set of activities that can be characterized as initial or intuitive — not very organized | Initial or Performed | Initial |
| 2 | Achieves its purpose through a basic, yet complete, set of activities that can be characterized as performed | Managed or Performed-complete | Managed |
| 3 | Achieves its purpose in a much more organized way using organizational assets; typically well defined | Established | Defined |
| 4 | Achieves its purpose, is well defined, and performance is quantitatively measured | Predictable | Quantitatively Managed |
| 5 Optimizing | Achieves its purpose, is well defined, performance is measured in order to improve, and continuous improvement is pursued | Optimizing | Optimizing |
Read the table left to right the way the exam wants you to think. If the stem says “basic yet complete set of activities,” that is Level 2, even if one deck called Level 1 “Performed” and another called Level 2 “Managed.” If the stem says “organizational assets” and “well defined,” that is Level 3 Established, even if a CMMI flashcard says “Defined.” If the stem says “quantitatively measured” without “in order to improve,” that is Level 4 Predictable, not Level 5. Level 5 adds the purpose of the measurement: improve, plus continuous improvement pursued.
A compact list you can recite under time pressure:
- 0 Incomplete — no basic capability; incomplete approach; practice intent may be missed.
- 1 — purpose more or less met; activities incomplete; initial or intuitive; not very organized.
- 2 — purpose met with a basic yet complete set; performed.
- 3 Established — organized with organizational assets; well defined.
- 4 Predictable — well defined and quantitatively measured.
- 5 Optimizing — measured to improve; continuous improvement pursued.
Do not memorize CMMI’s Initial / Defined / Quantitatively Managed string as if it were the COBIT 2019 official list. Those words show up in CMMI and in some commentary. On Foundation day, match the characteristic. If a question uses “Established” or “Predictable,” accept them as the common 2019 short labels for Levels 3 and 4. If a question uses “Defined” or “Quantitatively Managed” without the COBIT description, treat that as a CMMI transplant and go back to figure 6.2.
Capability is a process. Maturity is a focus area.
Two sentences you should be able to write from a cold start:
- Capability = how well a process is implemented (0–5).
- Maturity = how a focus area — a collection of objectives — achieves a capability level.
A focus area (Chapter 6) is a topic lens: cybersecurity, DevOps, small and medium enterprises, risk, and other published or custom collections. Maturity is the focus-area score. A common teaching rule: a maturity level is reached when the required processes in that focus area attain that capability level. You do not call DSS02 “mature at 3” when you mean “the DSS02 process is at capability 3 Established.” You also do not call a whole cybersecurity focus area “capable at 4” when you only scored one process.
Chapter 9 already separated objective, process, and capability. Add maturity as a fourth noun:
- Objective — a governance or management goal (one of 40), achieved by seven components.
- Process — one component of that objective.
- Capability — how well that process is implemented (0–5).
- Maturity — how the focus area’s collection of objectives/processes sits on that same 0–5 idea.
Refuse the equation capability = maturity = objective = process. Each word answers a different question.
Activities carry the levels; design sets the targets
Every process activity in the core model is associated with a capability level. That is why the Governance and Management Objectives publication can specify which activities you need if you want Level 2 versus Level 3. You do not invent a homemade activity list and then stamp a number on it. You use the activities already tagged to the level you are targeting.
Higher target capability is set during design for high-priority objectives. Chapter 15 will walk the design workflow. For this section, remember the Design Guide logic ISACA quotes in the same 2019 article:
- Objectives that score as much more important than the benchmark get a higher target — often 3 or 4.
- Remaining processes can reasonably be left at capability level 1.
- The manufacturing example in the Design Guide assigns a mix of 2, 3, and 4. It does not set 5 on every row.
You do not need every process at level 5. Level 5 Optimizing means the process is already well defined and quantitatively measured and those measures are used to drive continuous improvement. That is expensive. It is the right target for a handful of objectives that truly differentiate the enterprise. It is the wrong default for a process that barely applies.
A useful exam sentence: priority changes the target; it does not rewrite figure 6.2. Harborline’s security-heavy risk profile (Chapter 15’s design factors) may push APO13 and DSS05 toward 3 or 4. It does not turn Level 2’s “basic yet complete” definition into something else, and it does not obligate BAI objectives the firm barely uses to climb to Optimizing.
Scenario: Northbridge Health mandates Level 5 everywhere
Northbridge Health is a regional hospital system. After a ransomware scare, the CIO issues three instructions:
- “Every COBIT process will be at Level 5 by year-end. That is the official default.”
- A consultant’s slide scores processes as Initial, Defined, and Quantitatively Managed, and tells the board those are the official COBIT 2019 names.
- The board pack asks for “the maturity of DSS02” when the assessor only rated the incident-and-request process.
Walk each instruction the way a Foundation item would.
Instruction 1 fails the design rule. COBIT 2019 is tailored. High-priority objectives get higher targets. The rest can sit at 1 or 2. Level 5 is Optimizing — measured in order to improve — not a starter setting and not a badge you stamp on all 40 objectives. A hospital should almost certainly raise targets on security, continuity, and risk objectives. It should not spend a year forcing a low-relevance process to continuous improvement just to make a dashboard all fives.
Instruction 2 fails the synonym rule. CMMI’s Initial / Defined / Quantitatively Managed string is not the figure 6.2 source of truth. If the consultant can point to “incomplete set of activities, initial or intuitive,” that is Level 1, and “Initial” as a short label is tolerable. If the slide says “Defined” but the evidence is only “basic yet complete / performed,” that is Level 2, not Level 3 Established. If the slide says “Quantitatively Managed” but nobody is using the measures to improve, that is Level 4 Predictable, not Level 5. Teach your eye to read the characteristic, not the CMMI tattoo.
Instruction 3 fails the capability/maturity split. DSS02 is a process (and an objective). A 0–5 score on that process is capability. Maturity would describe a focus area — for example a cybersecurity or service-management collection — once the required processes in that collection reach the level. The board can ask for DSS02 capability. Calling that number “maturity” is the synonym trap.
Exam traps in this section
Trap 1 — Mixing CMMI names without the COBIT 2019 descriptions.
“Defined” and “Quantitatively Managed” are CMMI labels. COBIT 2019’s common short labels for those rungs are Established and Predictable. The safe move is always the figure 6.2 text: incomplete approach; incomplete/initial activities; basic yet complete / performed; organizational assets / well defined; quantitatively measured; measured to improve.
Trap 2 — Treating maturity and capability as synonyms.
Capability = process. Maturity = focus area. A process can be Established while the focus area is not, because other required processes have not reached that level. An objective can still fail in practice if other components are empty (Chapter 9).
Trap 3 — Assuming Level 5 is the default target.
False. Design sets higher targets on high-priority objectives. Remaining processes may sit at 1. The Design Guide examples use 2, 3, and 4. Level 5 everywhere is neither required nor recommended.
Trap 4 — Scoring the short label instead of the characteristic.
If one training deck says Level 1 is Performed and another says Level 2 is Performed, do not panic. Figure 6.2 characterizes Level 2 as the basic yet complete set “performed.” Level 1 is the incomplete, initial or intuitive set. Match the description. The label is the alias.
When you reach Chapter 15, you will use these levels as targets the design workflow writes down. For Foundation day, the scoring move is smaller: quote figure 6.2, split capability from maturity, and refuse Level 5 as a default.
Which statement correctly separates capability from maturity in COBIT 2019?
Using the official Introduction and Methodology figure 6.2 characteristics, which description matches Level 4?
Northbridge Health’s CIO sets capability level 5 as the default target for every process and calls each process score “maturity.” What does COBIT 2019 actually require?