Crawl, Walk, and Run Maturity Across the Systems Development Lifecycle (SDLC) - Systems Development Lifecycle (SDLC) Best Practices
Crawl, Walk, and Run Maturity Across the Systems Development Lifecycle (SDLC)
(Chapter 45 of Systems Development Lifecycle (SDLC) Best Practices)
Executive Summary: Chapter Overview
IF4ITThe Bottom Line
Core Concepts
| Concept | Definition & Strategic Role |
|---|---|
| Canonical Maturity Model | SDLC maturity is the degree to which lifecycle capabilities are defined, governed, consistently applied, integrated, automated, measured, understood, and continuously improved. Crawl uses minimum viable but controlled practices; Walk standardizes and integrates recurring practices; Run uses connected, automated, measurable, adaptive, and continuously improved capabilities. |
| Assess Capabilities, Not One Enterprise Label | Maturity should be assessed by capability, phase, discipline, portfolio, or operating area. An enterprise may be at Run for automated Build and Deployment, Walk for Release Management, and Crawl for supplier exit planning or retirement documentation. Target maturity should reflect value, risk, frequency, cost, and recurring burden. |
| Maturity, Risk, Conformance, and Formality | Maturity is distinct from Solution risk, conformance, and process formality. Low maturity does not justify weak control for high-risk work, and sophisticated automation does not prove conformance. A manual Crawl implementation may be conformant, while a highly automated capability may still bypass required ownership, evidence, or decisions. |
| Progressive Improvement | Establish essential ownership, outcomes, documentation, evidence, records, and decisions at Crawl; standardize Paths, knowledge packages, workflows, repositories, and measures at Walk; then automate understood processes, synchronize authoritative systems, generate continuous evidence, and use governed AI at Run. Simplify the mechanism before eliminating the obligation. |
Quick Q&A
Question: Must an enterprise reach Run maturity for every SDLC capability?
Question: Does Crawl maturity allow lifecycle obligations to be skipped?
Read More Below
This chapter establishes Crawl, Walk, and Run as a practical capability-maturity model for progressively improving the SDLC without eliminating essential lifecycle obligations.
Canonical Maturity Model
SDLC maturity is the degree to which lifecycle capabilities are defined, governed, consistently applied, integrated, automated, measured, understood, and continuously improved. Crawl uses minimum viable but controlled practices; Walk standardizes and integrates recurring practices; Run uses connected, automated, measurable, adaptive, and continuously improved capabilities.
Assess Capabilities, Not One Enterprise Label
Maturity should be assessed by capability, phase, discipline, portfolio, or operating area. An enterprise may be at Run for automated Build and Deployment, Walk for Release Management, and Crawl for supplier exit planning or retirement documentation. Target maturity should reflect value, risk, frequency, cost, and recurring burden.
Maturity, Risk, Conformance, and Formality
Maturity is distinct from Solution risk, conformance, and process formality. Low maturity does not justify weak control for high-risk work, and sophisticated automation does not prove conformance. A manual Crawl implementation may be conformant, while a highly automated capability may still bypass required ownership, evidence, or decisions.
Progressive Improvement
Establish essential ownership, outcomes, documentation, evidence, records, and decisions at Crawl; standardize Paths, knowledge packages, workflows, repositories, and measures at Walk; then automate understood processes, synchronize authoritative systems, generate continuous evidence, and use governed AI at Run. Simplify the mechanism before eliminating the obligation.

Common Antipatterns
Enterprises should avoid assigning one enterprise-wide maturity label instead of assessing by capability. An enterprise’s actual maturity varies by capability — Run for automated Build, Crawl for supplier exit planning — so assigning one single enterprise-wide maturity label obscures genuine strengths and weaknesses that only a capability-by-capability assessment would reveal.
| Antipattern | Why it fails |
|---|---|
| Assigning one enterprise-wide maturity label instead of assessing by capability | Maturity varies by capability, so a single enterprise-wide label obscures genuine strengths and weaknesses that only a capability-by-capability assessment would reveal. |
Connections to Related IF4IT Practices and Inventories
Align SDLC governance with the IF4IT Enterprise Model, Enterprise Capability Models, and the Enterprise Architecture Value Model so lifecycle decisions remain connected to business architecture, enterprise outcomes, and accountable management practices. Use Application Portfolio Management (APM) Best Practices and the Applications Inventory and Attributes to place this SDLC decision in the context of application ownership, portfolio value, lifecycle state, and dependencies.
For Crawl, Walk, and Run Maturity Across the Systems Development Lifecycle (SDLC), IT leaders and managers should establish explicit decision rights, accountable ownership, proportional controls, evidence expectations, performance measures, and continuous-improvement feedback tied to enterprise value.
Use the Non-Functional Requirements (NFRs) Framework for Software Systems to tie quality expectations to validation methods, test evidence, acceptance criteria, readiness gates, and Production assurance.
How to cite this page
When referencing this page in academic work, internal standards, or external publications, include the page title, IF4IT as author and publisher (The International Foundation for Information Technology (IF4IT), LLC), the URL, and your access date.
Example (informal web citation):
The International Foundation for Information Technology (IF4IT), LLC. Crawl, Walk, and Run Maturity Across the Systems Development Lifecycle (SDLC) | Systems Development Lifecycle (SDLC) Best Practices. https://if4it.org/best-practices/systems-development-lifecycle-sdlc/crawl-walk-and-run-maturity-across-the-systems-development-lifecycle-sdlc/ (accessed 2026-08-25).
See About Us for content governance and site-wide citation guidance.
Copyright for The International Foundation for Information Technology (IF4IT), LLC: 2008 - Present
Legal Disclaimers