Reimagining DevSecOps: A Modern Capability Model for How Teams Actually Work Today
DevSecOps was due for a fresh look.
Reimagining DevSecOps: A Modern Capability Model for How Teams Actually Work Today
DevSecOps was due for a fresh look.
DevOps — and later DevSecOps — came into focus more than a decade ago because organizations were trying to solve a very real problem: how do we ship software faster without giving up reliability, quality, or trust?
That problem still matters; in fact, it has become a critical factor in the adoption of AI. And the environment around it has changed in significant ways.
- AI is reshaping how developers work
- AI has amplified automation efforts
- Security threats are more sophisticated and constant
- Platform engineering is redefining ownership boundaries
- Toolchains are expanding — and fragmenting
As we stepped back in the Developer Division at Microsoft, and asked, “What does DevSecOps mean now?” one thing became clear: the industry has evolved, but many of our shared models have not kept up.
The Modern DevSecOps Customer Capability Model (CCM) came out of that gap. We wanted a practical way to help organizations understand where they are today, what might be getting in their way, and what it could take to move forward. This work was developed in parallel with the Platform Engineering Customer Capability Model. I’ll share more about how we built it later, but first I want to start with what the model is trying to do.
At a basic level, the model helps teams talk through three questions:
- Where are we today?
- Where do we want to go?
- What capabilities do we need to get there?
Customer Capability Models are useful because they map a journey, not just a checklist of practices. They can help teams:
- Highlight current conditions and pain points
- Show progression toward higher levels of proficiency
- Align teams across product, strategy, and execution
What makes this DevSecOps model “modern”?
DevSecOps models have been around for 12–15 years. We intentionally redesigned this one for the environment teams are working in now.
Two key shifts informed the design:
1. The convergence of knowledge and ability
In modern environments, success is not just about whether a team has the right tools or policies. It also depends on:
· Whether teams understand what to do
· And whether they can operationalize it at scale
2. The expansion of the DevSecOps surface area
When we looked at where leaders are investing, it was clear that DevSecOps now reaches across:
· Developer experience
· Security posture
· Automation and orchestration
· AI-assisted workflows
A static, linear model does not really capture how organizations change. We needed a more complete view of the breadth and depth of DevSecOps as a capability area for a modern digital enterprise.
How the model works
The structure is simple on purpose:
- Rows = Core capabilities required for DevSecOps success
- Columns = Stages of maturity
- Cells = What’s happening at each stage, including:
- Realized capabilities
- Gaps and challenges
What this model enables
The model is not just a visualization. It can be used in a few practical ways:
- Helps organizations identify inflection points in their DevSecOps journey
- Supports product and offering alignment across Microsoft
- Surfaces common pain points and gaps across customers
- Acts as a tool for onboarding and education
At Microsoft, it has already been used to:
- Support strategic planning
- Map Microsoft’s portfolio to real customer needs
- Align internal teams on where to invest
How we built it: research, synthesis, and a lot of collaboration
This model was not created in isolation. While I’m authoring this piece, the work reflects the input, expertise, and thinking of many people. I especially want to recognize Nate Listrom, Adrian Diglio, James Duncan, Mark Simos, and Nick Courad for the knowledge and partnership they brought to the process.
The process included:
Secondary research
- Reviewing and synthesizing dozens of existing DevOps and DevSecOps models
- Analyzing internal and external best practices
Primary research
- Interviews with enterprise customers
- Conversations with Microsoft MVPs
- Surveys across multiple audiences
Internal collaboration
- Workshops with subject matter experts
- Alignment with Microsoft security frameworks and messaging
- Iterative design and validation cycles
That mix of inputs helped us make sure the model was:
- Grounded in real-world practice
- Aligned with Microsoft strategy
- Validated across multiple perspectives
After several months of research, workshops, synthesis, and iteration, we landed on a model with:
- Six core capability swim lanes
- Five stages of progression
The swim lanes are meant to capture the breadth of modern DevSecOps. The stages are meant to reflect how organizations tend to mature over time — often unevenly, and rarely in a straight line.
What we learned along the way
One of the clearest lessons was that organizations do not move through DevSecOps maturity in a neat, linear way.
We observed that:
- Capabilities within a single area can vary widely
- Progress is uneven across teams and functions
- Many organizations struggle to move past early-mid maturity stages
One pattern stood out: a lot of the hardest work seems to happen in the middle stages, where complexity increases and alignment gets harder.
Introducing the Modern DevSecOps Model
To make the model easier to approach, we also created a simplified view. This version is meant to help teams quickly orient themselves, identify where they may be today, and start a more concrete conversation about what might come next.

Simplified version of the model.
In the simplified view, you can see a progression from limited activity and tooling, to more localized efforts, then to more orchestrated and streamlined approaches, and finally to pioneering practices in organizations that are ready to push further. The top two rows point to the importance of organizational buy-in — both culturally and through policies and priorities. The remaining rows follow the software development lifecycle, which is still the foundation many teams use today. AI may change parts of that lifecycle over time, but these fundamentals still matter because they create the conditions for shipping digital products and services responsibly.

Partial section of the full model. See full model further below.
In the full detailed model (download full image below), the modernization shows up in a few ways: security is carried through the model rather than treated as a late-stage activity, and AI appears across phases instead of being isolated as a separate topic. Those choices reflect what we heard and observed: teams are trying to make sense of DevSecOps in a world where security, AI, automation, and developer experience are increasingly connected.
Final thought
DevSecOps is no longer just a set of practices. It is a complex, evolving capability system.
To make meaningful progress, organizations need more than tools or isolated guidance. They need:
- A shared understanding of where they are
- A clear vision of where they’re going
- And a roadmap grounded in real-world complexity
My hope is that this model makes that journey easier to see, easier to discuss, and easier to act on. Next, I will write about the ProductOps model that I developed.
April Reagan
Senior Design Researcher at Microsoft

The full Modern DevSecOps CCM.
메타데이터
- post_id
- 3a069a552ff3
- slug
- reimagining-devsecops-a-modern-capability-model-for-how-teams-actually-work-today-3a069a552ff3
- url
- https://medium.com/uxr-microsoft/reimagining-devsecops-a-modern-capability-model-for-how-teams-actually-work-today-3a069a552ff3
- canonical_url
- https://medium.com/uxr-microsoft/reimagining-devsecops-a-modern-capability-model-for-how-teams-actually-work-today-3a069a552ff3
- author_url
- https://medium.com/@palmtreesandrobots
- status
- ok
- fetched_at
- 2026-07-15 14:13:45