Identity and Access Management (IAM) is far more complex than many people assume. While it is omnipresent in organizations, it is still frequently treated as a hidden infrastructure service which just needs to “work” in the background. As a result, IAM is often underestimated, underfunded, and under-strategized. Yet IAM is not simply infrastructure. It is a security service that can enable business growth, digital transformation, and secure collaboration across ecosystems. Without a clear plan, however, IAM quickly becomes an operational burden rather than a strategic advantage.
Identity Fabric – from concept to practice
Over the past years, the Identity Fabric has become a widely recognized foundation for modern IAM. It is no longer an abstract concept, but a strategic framework embraced by vendors, service providers, and enterprises alike. The core idea is straightforward but powerful: Provide seamless, controlled, and secure access for everyone and everything, from any location to any service.
Figure 1: KuppingerCole Identity Fabric (Version 2025)
The Identity Fabric illustrates how different identity types such as employees, customers, partners, devices, and services can interact with target systems. This access is enabled through functional capabilities. These capabilities are bundled into services, and these services are mapped to specific tool categories. In other words, the Identity Fabric turns the abstract question “how do we manage access for everyone to everything?” into a structured model.
Figure 2: The KuppingerCole IAM Reference Architecture (Version 2025)
The Reference Architecture as capability map
The KuppingerCole Reference Architecture provides the necessary level of detail to bring the Identity Fabric to life. It is organized as a capability matrix along five functional layers and four domains which are the well-known “4 A’s.” By breaking IAM into clearly defined functional capabilities, the Reference Architecture helps organizations avoid the trap of viewing IAM only as products or tools. Instead, it establishes a structured view of what IAM must achieve and how these achievements fit into a business-aligned security ecosystem.
This structured approach is not an academic exercise. It is the foundation for achieving a cohesive, adaptable, and future-proof IAM environment. Diving into the Reference Architecture is therefore essential, not only for strategy development but also for handling daily operational demands.
Three ways of operationalization
At EIC 2025, KuppingerCole presented the updated version of the Identity Fabric in a workshop and demonstrated three distinct approaches to operationalization:
- Flexible Reference Architectures
This part highlighted how the Reference Architecture can be used to flexibly change the scope of the Identity Fabric. One major takeaway was the presentation of the new draft version of the CIAM Reference Architecture, showing how customer-specific requirements can be mapped consistently into the same structured approach. - Strategic Development
Here, KuppingerCole demonstrated how the frameworks can be used to assess an organization’s IAM landscape and derive a strategic roadmap in five steps: - Maturity assessment,
- Definition of the target state,
- Gap analysis,
- Identification of action items,
- Roadmap creation.
This structured sequence helps organizations move beyond buzzwords and develop a practical, measurable plan for improvement.
- Operational Development
Finally, the third chapter focused on daily IAM challenges and how do you resolve recurring operational issues with a structured, hands-on mentality. The Identity Fabric and Reference Architecture offer a common language to classify problems, highlight dependencies, and provide a structured pathway toward resolution.
The feedback from this workshop was remarkably positive. Many attendees emphasized that this workshop had helped them greatly by showing them how to translate these frameworks into concrete steps for strategy and operations.
The next step: Maturity as foundation
While many organizations confidently state that they already have an IAM strategy, reality often tells a different story. Without a solid understanding of their own current state, these strategies remain vague and aspirational. At EIC 2025, the focus was on showing how to move forward in five steps. At the upcoming Identity Fabric Impact Day (IFID) on September 18, 2025, in Munich, the spotlight will shift to the very first step: The maturity assessment.
A well-executed maturity assessment provides a structured overview of an organization’s functional capabilities. It helps build a common understanding across departments, prevents misunderstandings, and establishes a baseline for measuring progress. It also enables benchmarking against industry leaders transforming subjective assumptions into objective evaluations.
Why maturity matters
A maturity assessment is not simply about scoring an organization on a scale. It is about enabling clarity:
- Which IAM capabilities exist, and how well are they implemented?
- Where are the strengths, weaknesses andgaps?
- How do different levels of maturity interact and depend on each other?
- What is realistic to achieve as the next step?
Without this clarity, organizations risk investing in the wrong initiatives or trying to adopt trends like Zero Trust or CIAM without having established the operational excellence to support them. The maturity assessment ensures that ambitions are matched with the current reality.
What to expect in Munich
At IFID, KuppingerCole will present a five-level maturity assessment model based on the Identity Fabric and the Reference Architecture. The event will provide concrete answers to key questions:
- How many maturity levels are really required?
- Which criteria are important to assess IAM capabilities?
- How exactly are the levels and criteria defined?
- How do the different levels relate to each other?
- Which possibilities exist to improve maturity step by step?
In addition, participants will have the chance to meet directly with KuppingerCole experts, discuss their own challenges, and receive advice on applying these insights in their organizations.
From frameworks to real progress
The operationalization of the Identity Fabric and Reference Architecture is not a theoretical exercise. It is about providing clarity, structure, and practical guidance in a complex area that too often suffers from misunderstanding. Focusing on the maturity assessment is the next step and will help organizations establish a transparent foundation for strategic development and operational excellence.
Join us in Munich on September 18, 2025, to see how KuppingerCole's frameworks can be transformed into actionable insights and how maturity can become the starting point for real progress in IAM.