Every maturity model borrows the same ladder from CMMI, whatever it calls the rungs. Level 1 is ad hoc: it works because a particular person is still employed. Level 2 is repeatable: the same thing happens twice for the same reason, usually inside one team. Level 3 is defined: it is written down, owned, and the same across domains. Level 4 is managed: it is measured, and the measurement is used to make decisions. Level 5 is optimized: it improves on purpose, on a cadence, without a program pushing it. Notice that none of those sentences mentions a tool.

In practice. Score each capability separately — metadata, quality, privacy, literacy, architecture — and expect an uneven profile. Level 3 in classification and level 1 in quality is not a contradiction; it is your roadmap, and it tells you what the next twelve months should buy. The useful conversation is never "what level are we", it is "what specifically would have to be true for this capability to be a 3, and is that worth doing this year".

Where it goes wrong. The level becomes a target instead of a description. Someone commits to "level 4 by December", the assessment quietly turns into a self-graded exam, and the program starts optimizing the score rather than the business. Level 5 everywhere is also the wrong ambition: most organizations should be deliberately level 2 in the domains where nothing much is at stake.