14.3 Architecture Maturity Models, Capability Assessment, and EA Performance Measures
Key Takeaways
TOGAF builds capability assessment into the Preliminary Phase (a maturity target), Phase A (Evaluate capabilities), the Capability Assessment deliverable, the Governance Repository, and Phase H.
The US Department of Commerce ACMM has six levels: 0 None, 1 Initial, 2 Under Development, 3 Defined, 4 Managed, and 5 Measured.
The ACMM scores nine characteristics separately, including architecture process, business linkage, senior management involvement, IT security, and architecture governance.
Target maturity is set by business need, risk, and cost; the highest level is not automatically the goal.
The Governance Repository's Performance Measurement log captures metrics for the architecture function; outcome measures such as reuse and value realization matter more than activity counts.
14.3 Architecture Maturity Models, Capability Assessment, and EA Performance Measures
An Architecture Capability must itself be assessed and improved. The TOGAF Standard builds this in at several points:
- The Preliminary Phase sets a capability maturity target.
- Phase A's Evaluate capabilities step assesses the enterprise's capabilities, including its architecture capability.
- The Capability Assessment deliverable records business, IT, and architecture capability.
- The Governance Repository keeps capability assessments, including architecture maturity assessments, over time.
- Phase H ensures that the EA Capability meets current requirements.
The detailed maturity model lives in the TOGAF Library's Architecture Maturity Models Series Guide. It is not part of the Fundamental Content, so expect it to support scenarios rather than be tested in depth.
Why Maturity Models Matter
TOGAF's guidance draws on the idea that organizations improve through recognizable stages, the Capability Maturity Model concept that originated at the Software Engineering Institute. Maturity models give an enterprise a way to:
- Assess the current state of its architecture practice objectively.
- Set a realistic target state and the steps to reach it.
- Track progress and compare business units over time.
Maturity models also appear in Business Transformation Readiness Assessment, which presents each readiness factor as a maturity model with baseline, target, and intermediate levels (Section 8.5).
The Architecture Capability Maturity Model (ACMM)
The best-known model reproduced with TOGAF is the US Department of Commerce IT Architecture Capability Maturity Model (ACMM). It has six levels, numbered from zero:
| Level | Name | Typical characteristics |
|---|---|---|
| 0 | None | No architecture program |
| 1 | Initial | Informal, ad hoc architecture processes; work depends on individual effort |
| 2 | Under Development | The architecture process is being established; roles and some standards are emerging |
| 3 | Defined | A documented architecture process is defined, communicated, and followed |
| 4 | Managed | The process is part of the culture and is managed with quality metrics |
| 5 | Measured | The process is continuously improved using quantitative feedback |
The ACMM assesses nine architecture characteristics separately:
- Architecture process
- Architecture development
- Business linkage
- Senior management involvement
- Operating unit participation
- Architecture communication
- IT security
- Architecture governance
- IT investment and acquisition strategy
An ACMM scorecard records the level reached for each characteristic. An organization is rarely at one level across the board. A practice can be Level 4 on architecture process and Level 1 on business linkage, and averaging the scores hides exactly the weakness worth fixing.
Other Maturity Models
TOGAF's maturity guidance also refers to other capability maturity models, such as CMMI and models aimed at specific concerns. The general lesson is the same: choose a model that fits the enterprise's purpose, assess each characteristic, and set targets that reflect business need.
Setting a Realistic Target
The target maturity level is a business decision, not automatically the top level. A small or low-risk organization may gain most of the value from reaching Level 3 (Defined) on key characteristics. A heavily regulated enterprise may need Level 4 (Managed) on governance and security. Each step up costs effort in governance, tooling, skills, and change management, so set the target by weighing value against cost, and record it with its rationale in the Preliminary Phase.
Capability Uplift Lifecycle
Improving architecture maturity is itself a change effort that the ADM can manage, through an Architecture Capability iteration (Preliminary Phase and Phase A):
- Baseline assessment: score each characteristic, for example with the ACMM scorecard, using interviews and evidence.
- Target formulation: agree the target level per characteristic and the business reasons for it.
- Gap analysis: identify the missing governance bodies, processes, skills, tools, and repository content.
- Uplift roadmap: define work packages such as chartering the Architecture Board, defining principles, establishing the repository, and building skills, which the Architecture Skills Framework guide supports.
- Execution and governance: deliver the work packages with sponsor oversight.
- Periodic reassessment: repeat the assessment, record it in the Governance Repository, and revisit the target in Phase H.
Measuring the Architecture Function
TOGAF's Governance Repository includes Performance Measurement: the performance criteria defined in the architecture function's charter and the metrics for project governance, so performance can be measured and evaluated continuously. The specific metrics are the enterprise's choice. A balanced set usually combines:
Process and Governance Measures
- Decision cycle time: the time from submitting an item to a governance decision.
- Compliance rate: the share of projects passing compliance reviews without unapproved deviations.
- Dispensation closure: the share of dispensations remediated by their expiry date.
- Repository currency: the share of production systems with up-to-date architecture descriptions.
Outcome Measures
- Reuse rate of approved building blocks.
- Reduction in duplicate or legacy systems and the associated run costs.
- Investment alignment: the share of change investment traced to capabilities on the target roadmap.
- Value realization: actual benefits compared with those expected, as tracked by Phase H's value realization process.
Counting documents, diagrams, or meetings measures activity, not value. Executives respond to outcome measures.
Practitioner Scenario: Capability Uplift in a Healthcare Network
A healthcare network of 45 hospitals finds, after a failed regional integration, that hospitals have bought incompatible clinical systems and duplicate patient databases. The new chief architect runs an ACMM assessment in the Preliminary Phase:
- Findings: architecture process and development score Level 1 (Initial), with no formal board and no shared repository. Senior management involvement scores higher after the incident.
- Target: given the regulated, safety-critical context, the board agrees on Level 4 (Managed) for architecture governance and IT security, and Level 3 (Defined) elsewhere, within 24 months.
- Uplift: charter an Architecture Board co-chaired by clinical and IT leadership; define principles; establish a repository with the relevant industry reference models in the Reference Library; and track reuse of shared patient-data services and the retirement of duplicate systems.
- Review: the assessment is repeated every six months, and results go to the Governance Repository and the executive sponsor.
Common Exam Traps
- Using the wrong level names. The ACMM levels are 0 None, 1 Initial, 2 Under Development, 3 Defined, 4 Managed, and 5 Measured.
- Assuming the top level is always the goal. Targets reflect business context, risk, and cost.
- Scoring one overall level. Assess each characteristic; averages hide weak spots.
- Treating assessment as one-off. Maturity is reassessed periodically and revisited in Phase H.
- Relying on activity metrics. Show business outcomes, not document counts.
An organization has a formally documented and followed architecture process, a chartered Architecture Board, and a working repository, but it does not yet manage the process with quality metrics. Using the ACMM level names, which level best describes its architecture process?
Level 0 (None)
Level 1 (Initial)
Level 3 (Defined)
Level 5 (Measured)
Which combination of Enterprise Architecture performance metrics best demonstrates the practice's tangible business value and strategic contribution to executive stakeholders?
Reuse of approved building blocks, reduction in legacy technical debt costs, and alignment of capital investment to business capabilities
The total page count of Architecture Definition Documents produced and the number of diagrams drawn each month by each member of the architecture team
The number of Architecture Board meetings held each quarter and the attendance percentage of software developers at those meetings
The number of hardware servers purchased and the total gigabytes of PDF documentation stored in the Architecture Repository each year
During a Preliminary Phase maturity assessment, why should the architecture team set an explicit target level for each ACMM characteristic rather than default to Level 5 (Measured) everywhere?
Because The Open Group restricts Level 5 to organizations that run an accredited TOGAF certification program for all their architects
Because Level 5 requires replacing architecture reviews with automated tooling, which most enterprises cannot yet support
Because the Preliminary Phase cannot assess governance or tooling, so only targets for architecture process can be set at this point
Because each step up costs governance, tooling, skills, and change effort, so targets should follow business need and can differ by characteristic
Sections you finish are checked off in the contents.