Most models share a five-level shape: nothing deliberate is happening, some people do it well, it is documented and repeatable, it is measured, it is improved on purpose. The value is not the score but the vocabulary — a model gives a leadership team a shared way to say "we are at level 1 on quality and level 3 on access control", which is a much more productive conversation than trading anecdotes.
In practice. Use the model as an interview guide, not a questionnaire. The evidence that determines a level is what someone shows you: the actual glossary, the last three incident records, the approval trail for a definition change. Self-assessment inflates by roughly a level in every organization.
Where it goes wrong. The output is a radar chart, and the radar chart is the deliverable. A maturity assessment that does not end with three named actions, an owner each and a date has produced a diagnosis nobody can act on. The chart is the beginning of the conversation, not its conclusion.