SAP License Maturity Model: Four Levels with a Self-Assessment
The SAP license maturity model describes four levels of organizational maturity in license management: from reactive classification on demand to strategically embedded license governance. An eight-question self-assessment helps you determine where you stand today. For each starting point, there are concrete first steps toward the next level.
Why a maturity model helps in the license space
SAP license management is not a one-time project: it is an ongoing discipline. Yet organizational maturity varies considerably. Some organizations run USMM only when SAP requests a measurement. Others have quarterly self-audits as an operational standard and systematically build FUE optimization analyses as the negotiating foundation for the next renewal.
A maturity model helps for three reasons.
First, it enables an honest assessment without blame. The challenge lies in the structure of SAP license management, not in individual people. Classification errors accumulate structurally when no ongoing rhythm has been established.
Second, it creates direction. Once you know which level you are at, you can plan concretely what it takes to reach the next one. The four levels are not abstract categories: they are defined by observable characteristics.
Third, it makes the connection between license maturity and commercial governance moments visible. The governance moment around usage and the governance moment around authorizations, both central to ongoing SAP contract governance, are not systematically leveraged until level 3. Organizations at level 1 or level 2 are leaving these governance moments unused month after month.
A note on scope relative to Pillar 1: the general SAP Contract Governance maturity model covers all four governance moment areas (usage, authorizations, infrastructure, costs). This model goes deeper on the license dimension specifically: named users, FUE, authorizations, measurement tools, and audit readiness.
Level 1: Reactive: classification on demand
At the first level, license classification happens at the outset but is not reviewed on an ongoing basis. USMM is run when SAP requests a measurement. There is no systematic connection between role design and FUE implications. Inactive accounts are not cleaned up according to a defined process.
In this situation, classification errors accumulate unnoticed. Users change responsibilities, receive additional roles, or leave the organization. Without an ongoing review rhythm, this only becomes visible in an audit context: at which point the remediation effort is significantly higher than it would be with continuous governance.
Typical characteristics of level 1:
- The license baseline is documented somewhere, but not consolidated or actively maintained
- USMM is run only on external request
- No awareness among stakeholders of the connection between role design and FUE type
- Inactive accounts remain in the system until they become noticeable
- No defined ownership for ongoing license governance
The two governance moments around usage and authorizations arise every month even at level 1. They are simply not being used in a structured way.
Level 2: Documented: license baseline known, cadence missing
At the second level, the license baseline is documented. License types are recorded, FUE purchase volumes are known, termination notice periods and renewal dates are captured. USMM is run internally at least once a year. LAW consolidation exists. Misclassifications are known or became visible during the last self-audit, but are not yet systematically addressed.
This represents meaningful progress over level 1: the organization knows what it has. It is no longer entirely dependent on what SAP finds in the next audit.
What is still missing at level 2: cadence. Running USMM once a year is no longer sufficient in a PCE environment, because SAP measures monthly. And the connection between consumption, role structure, and FUE calculation is not yet made on an ongoing basis. The governance moment around authorizations remains reactive.
Typical characteristics of level 2:
- License types, FUE pool, and contract data are captured in a document or spreadsheet
- USMM is run internally once a year
- LAW consolidation is produced when there is a need
- Misclassifications are known but not yet systematically remediated
- Renewal deadlines are on the calendar, but renewal preparation often starts too late
For organizations in a PCE environment, level 2 is a waypoint, not a stable steady state. The move to level 3 is effectively required by monthly PCE metering.
Level 3: Actively governed: self-audits as operational standard
At the third level, license governance is embedded in the operational rhythm. Quarterly self-audits with USMM and SAM4U are standard practice. Role optimizations are scheduled ahead of the PCE metering cycle. Inactive accounts are systematically cleaned up after the 90-day threshold. FUE consumption is reconciled monthly against the contractual FUE pool. Classification changes triggered by SAP upgrades are reviewed proactively.
The core difference from level 2: it is no longer about documenting the current state. It is about actively managing it on an ongoing basis.
SAM4U at level 3 is an active governance instrument, not an occasionally consulted analysis tool. The PCE metering dashboard in SAP for Me is reviewed monthly. Discrepancies between the organization's own FUE understanding and the metering result are documented: not silently accepted.
Typical characteristics of level 3:
- Quarterly self-audits with USMM and SAM4U as operational standard
- SAM4U installed and actively used, including Enhanced Usage Tracking
- Role optimizations scheduled ahead of the monthly PCE metering cycle
- Inactive accounts systematically cleaned up after the 90-day threshold
- FUE consumption reconciled monthly against the contractual FUE pool
- PCE metering results compared against internal calculations; discrepancies documented
The primary benefit of this level: the governance moment around authorizations and the governance moment around usage are managed in a planned and repeatable way. Surprises in the next audit become significantly less likely. The negotiating position at renewal is stronger because a clean data foundation is in place.
Level 4: Strategically embedded: FUE optimization as negotiating foundation
At the fourth level, license governance is part of IT strategy and budget planning. FUE optimization is systematically built as the negotiating foundation ahead of each renewal. Scenario models for usage growth and classification changes are available. Cross-product license coordination, meaning the alignment across RISE, SuccessFactors, BTP, and other product types, is operational standard. The SAM4U Data API is integrated into an overarching reporting platform.
At this level, governance moments are not just recognized: they are planned for. The renewal process begins 12 months before the contract date, with a full FUE optimization analysis as the starting point. That analysis answers: which users could be reclassified from Advanced to Core? What FUE volume is realistic for the next contract period? Which clauses should be renegotiated at renewal?
Typical characteristics of level 4:
- License governance is anchored in IT strategy and the budget planning process
- Scenario models for usage growth and price adjustments are established
- FUE optimization analysis starts 12 months before the renewal date
- Cross-product coordination across all SAP product types in the portfolio
- SAM4U Data API integrated into an overarching reporting platform
- Four roles, Contract Manager, Procurement, Controlling, and Executive, are strategically aligned and work from a shared data foundation
Level 4 is most relevant for organizations with larger SAP portfolios and multiple product types. For an organization with a single RISE contract, a well-established level 3 can be entirely sufficient.
Self-assessment: 8 questions to determine where you stand
The following eight questions provide an initial orientation. Answer each question for your organization with yes or no.
Question 1: Is it documented which named user types or FUE types are licensed in your current contract, and at what price per type?
Question 2: Is USMM run internally at least once a year, independent of an SAP request?
Question 3: Is a LAW-consolidated report produced for all systems in your SAP landscape?
Question 4: Are inactive accounts systematically cleaned up according to a defined process and threshold: for example, 90 days without a login?
Question 5: Is SAM4U installed and actively used for classification optimization?
Question 6: Is FUE consumption reconciled monthly against the contractual FUE pool?
Question 7: Are role optimizations scheduled ahead of the PCE metering cycle?
Question 8: Is the license situation included in IT budget planning and the renewal preparation process, with a lead time of 12 months or more?
How to interpret your answers:
- 1 to 2 yes answers: Level 1 (Reactive)
- 3 to 4 yes answers: Level 2 (Documented)
- 5 to 6 yes answers: Level 3 (Actively governed)
- 7 to 8 yes answers: Level 4 (Strategically embedded)
Many organizations in the DACH region answer questions 1 through 3 with yes and questions 4 through 6 with no or partially. That places them somewhere between level 2 and level 3. This is not a verdict: it is a starting point.
How to move up one level
The path from one level to the next follows no universal playbook. But there are typical first steps for each starting situation.
From level 1 to level 2: The most efficient entry point is a structured contract check that fully maps the license baseline: license types, FUE pool, termination notice periods, relevant clauses. In parallel, SAM4U should be installed. It is free, the data stays within your own network, and the first SAM4U report gives a concrete overview of classification discrepancies.
From level 2 to level 3: This is the transition from occasional measurement to ongoing governance. Two prerequisites need to be in place. First, a defined governance cadence: quarterly self-audits on the calendar, monthly FUE monitoring as standard practice. Second, a connection between role design and license classification. Organizations that review the PCE metering dashboard monthly and schedule role optimizations ahead of the next metering cycle have completed the move to level 3.
From level 3 to level 4: The step to strategic governance requires connecting license management to IT strategy. That means FUE optimization analyses start 12 months before renewal, not 60 days before. Scenario models are established. Cross-product coordination becomes a standing agenda item in governance reviews.
One option for organizations with limited internal capacity: the transition from level 1 to level 3 does not have to happen exclusively through internal capability building. A managed service approach makes it possible to capture the benefits of actively governed license management immediately, while building internal expertise step by step. Documentation, consumption history, and negotiating foundation are fully preserved, regardless of which model you choose.
FAQ
What is the most common starting point when organizations begin improving their license governance?
Most organizations start somewhere between level 1 and level 2: a basic documentation of the license baseline exists, but no ongoing governance cadence. USMM is run occasionally, SAM4U is not installed or not actively used. Misclassifications are known or suspected but not systematically addressed. A structured contract check is typically the first concrete step to clarify this starting situation.
How does this maturity model differ from the general SAP Contract Governance maturity model?
The general model (described in Pillar 1 of this content series) covers all four governance moment areas: usage, authorizations, infrastructure, and costs, as well as the coordination of all four roles. The license maturity model goes deeper on the license dimension specifically: named users, FUE, measurement tools, authorizations, and audit readiness. Both models complement each other: running both self-assessments gives you a complete picture.
How does PCE metering affect the value of the different levels?
Significantly. In an on-premise environment, level 2 (annual USMM) was long considered an acceptable baseline. In a PCE context, with monthly automated metering by SAP, level 2 is structurally insufficient: classification errors become visible 12 times faster. The governance moment around authorizations effectively becomes a monthly governance moment. For PCE customers, the move to level 3 is more urgent than for on-premise organizations.
What does a misclassification actually cost?
It depends on the price difference between license types and the duration of under-licensing. A practical example from SAP compliance: 100 users with a Limited license who are actually performing Professional transactions, at a price difference of roughly EUR 1,500 per user, results in EUR 150,000 in additional purchase cost. Add three years of back-maintenance at 22 percent per year and the total exposure reaches approximately EUR 249,000. This illustrates why ongoing classification review is more economically sound than reactive remediation in an audit context.
Related articles:
- SAP License Management: Overview and Fundamentals: Pillar 6 Hub covering all dimensions of SAP license management
- SAP Contract Governance Maturity Model: All Four Governance Moment Areas: Pillar 1 Cluster 6
- SAP Audit Preparation: What Needs to Be in Place on an Ongoing Basis: Cluster 4
Next Steps
Would you like your SAP contracts reviewed for deadlines, clause risks, and available commercial levers?
This article is part of our topic hub on SAP license management and maturity model. To have one specific contract assessed, the FinOptory Contract Check delivers a structured basis within four weeks.
Last updated: July 2026