← All posts

17 Aug 2026 · 4 min read

DPDPA Maturity Model vs Gap Assessment: Which One Do You Need First?

Both tools answer “where do we stand on DPDP compliance?” But they answer it differently, and running them in the wrong order usually costs a quarter. This piece sets out what a DPDPA maturity model and a gap assessment each measure, where each one misleads you, and the sequence we see work in Indian companies preparing for the DPDP Rules 2025.

DPDPA maturity model versus gap assessment compared: gap assessment shows what is missing, maturity model shows how reliably controls run
They answer different questions. Running them in the wrong order wastes a quarter.

Quick answer: a gap assessment compares you against the Act’s requirements, obligation by obligation: in place, partial or missing. A maturity model rates how well and how repeatably you meet each obligation, on a scale. Run the gap assessment first. Move to a maturity model once the gaps are closed and you need to show that controls keep working.


DPDPA maturity model vs gap assessment at a glance

Gap assessmentMaturity model
Question it answersWhich DPDP obligations are we not meeting?How reliably do we meet each one, and is it improving?
ScoringIn place / partial / missingA level on a ladder, usually five steps
Main outputA prioritised remediation list with owners and datesA per-capability score and an improvement roadmap
Evidence it needsDoes the policy, process or control exist?Does it run every time, and can you prove it?
Best momentProgramme start, or before a Rules deadlineAfter remediation, for boards and auditors
CadenceOnce, then after major changeQuarterly or half-yearly
Typical ownerDPO or compliance lead, often with legal counselDPO with process owners in each function
Where it misleadsA spreadsheet and an automated workflow both score “in place”A high score on a capability you never needed hides a real gap elsewhere

What a DPDP gap assessment actually checks

A gap assessment walks the obligations in the Digital Personal Data Protection Act, 2023 and the Rules notified in November 2025, and marks each one. The areas that matter for almost every Data Fiduciary:

The output is binary on purpose. It tells leadership what is missing, what it could cost under the Act’s penalty schedule, and who fixes it by when. If you have never done one, our DPDP gap analysis guide walks through the method, and the DPDP compliance assessment explains how to scope it.

How a DPDPA maturity model scores you

There is no official DPDP maturity model. Most borrow the five-level ladder from CMMI, the capability maturity framework used in software and security. Applied to a DPDP capability such as consent, it reads like this:

  1. Ad hoc. Consent is collected, but differently by each team. Nobody could produce last month’s consent records on request.
  2. Documented. A policy and a notice template exist. Whether teams follow them depends on who is asking.
  3. Managed. Consent runs through one workflow with an owner, versioned notices and a record for every grant and withdrawal.
  4. Measured. You track withdrawal turnaround, stale consents and notice coverage, and you review the numbers on a schedule.
  5. Optimised. Findings from audits, complaints and incidents feed back into the process, and the metrics show it.

That is why a maturity model tells the truth where a gap assessment cannot. Two organisations can both “have consent management”. One keeps it in a spreadsheet someone updates by hand. The other runs an automated workflow with tamper-evident records. A gap assessment marks both as done. A maturity model puts the first at level one and the second at three or four.

Where each approach goes wrong

Starting with a maturity model. This is the more common mistake, because maturity scores look good in a board deck. Teams spend weeks debating whether consent is at level two or three while the RoPA does not exist yet. You cannot score the reliability of a control you have not built.

Staying on gap assessments forever. Once every line says “in place”, a gap assessment has nothing left to tell you. It will not notice that rights requests now take 40 days instead of 20, or that half the vendor questionnaires came back blank. Those are maturity problems, and they are what a regulator or auditor finds first.

Self-scoring without evidence. Both tools fail when the answers are opinions. “Yes, we have a breach process” means little unless you can show the last drill, the timestamps and who signed off.

The sequence that works

  1. Gap assessment against the Act and the Rules 2025 timeline. Four to six weeks for a mid-sized company, most of it spent building the data inventory.
  2. Remediation, ordered by penalty exposure and effort. The DPDP compliance checklist is the working document.
  3. Baseline maturity score once the gaps are closed, so the first score measures real controls.
  4. Quarterly maturity reviews that push each capability from documented to managed, then measured.
  5. Aim for “measured” if you expect to be notified as a Significant Data Fiduciary. Periodic DPIAs and independent audits expect evidence of controls that run, not controls that exist.

Which one do you need first?

How ProtectComply supports both

ProtectComply starts with a 35-question readiness check across nine weighted domains, scored green, amber or red. The full DPDP question bank goes deeper, with 440 questions across three levels, and there are sector-specific banks for industries such as healthcare. That covers the gap phase.

For maturity, the useful part is that the evidence comes from the workflows themselves: consent and RoPA changes are written to tamper-evident records, DPIAs are triggered by risk and carry DPO sign-off, and rights requests carry their own audit trail and deadline. That makes a maturity score something you can show rather than assert. See how the leading DPDP platforms compare, or talk to us about scoping an assessment.

Frequently asked questions

Is a DPDP maturity model mandatory?

No. Neither the Act nor the Rules require a maturity model or name one. They require the obligations to be met. A maturity model is a management tool for showing that they keep being met.

Can a gap assessment and a maturity assessment be run together?

Yes, and larger organisations often do. The practical version is one exercise: mark each obligation in place, partial or missing, and give the “in place” items a maturity level. Keep the missing items out of the maturity score, or the average hides them.

How long does a DPDP gap assessment take?

For a mid-sized company, usually four to six weeks. The questionnaire is quick. Building the inventory of what personal data you hold, where, and who receives it takes most of the time.

What maturity level should we target?

“Managed” for most Data Fiduciaries: one owned process, versioned records, evidence on request. “Measured” if you are likely to be a Significant Data Fiduciary or you process sensitive data at scale.