Skip to main content
zopnightlearn

FinOps Maturity Model: From Crawl to Run

The FinOps Foundation defines three maturity phases. Crawl, Walk, Run, that describe how organizations progress from basic cloud cost awareness to automated, continuous optimization. Most organizations start at Crawl (reactive cost management) and take 12-18 months to reach Run (proactive, automated optimization).

Understanding where your organization sits on the maturity spectrum helps prioritize investments. At Crawl, the focus is visibility, who is spending what. At Walk, the focus is optimization, acting on waste. At Run, the focus is automation and governance, making optimization self-sustaining.

The maturity model is not a linear progression. Organizations often reach Walk maturity for some capabilities (like scheduling) while remaining at Crawl for others (like commitment management). The goal is to identify which capabilities deliver the most value at your current stage and invest accordingly.

This guide keeps the theory short and spends most of its length on what you can actually do. Every recommendation here is one ZopNight can help you execute, starting from a read-only connection.

Crawl phase: visibility and awareness

At Crawl, the organization has connected cloud billing data but lacks consistent tagging, per-team cost attribution, and optimization automation. The focus is on building the foundation: implement a tagging strategy, connect all accounts to a cost management tool, create dashboards that show spending by team and environment, and identify the top 10 waste sources. Most organizations can move through Crawl in 2-4 weeks with the right tooling.

Walk phase: optimization and action

At Walk, teams have visibility into their costs and are actively optimizing. Non-production resources are scheduled, idle resources are detected and addressed, and rightsizing recommendations are reviewed regularly. Per-team budgets exist, and cost is discussed in engineering reviews. The focus shifts from finding waste to systematically eliminating it. Scheduling and idle detection are the primary Walk-phase tools.

Run phase: automation and governance

At Run, optimization is automated and governance ensures it persists. New resources are automatically included in scheduling groups through tag-based rules. Idle detection runs continuously. Budget alerts route to the right people. Commitment purchases are data-driven and regularly reviewed. The FinOps practice has executive support, a regular review cadence, and metrics that demonstrate ongoing value. Few organizations reach Run for all capabilities, but reaching it for scheduling and idle detection is achievable within 3-6 months.

Measuring maturity

Track these metrics quarterly to measure progress and identify areas that need investment.

Key takeaways

  • Most organizations take 12-18 months to progress from Crawl to Run across all capabilities.
  • Scheduling and idle detection can reach Run maturity faster than commitment management.
  • Each phase builds on the previous: visibility enables optimization, optimization enables automation.
  • Measure maturity by coverage percentages, automation rates, and governance compliance.

Where ZopNight fits

ZopNight turns this from reading into doing. It ships 490 built-in audit rules across AWS (216), GCP (127), and Azure (147), 124 of those recommendations are wired to act end to end, 28 one-click and 96 guided, and it starts read-only so you can see the opportunity before you act on any of it. The most direct place to begin is scheduling non-production resources to your working hours, which is covered in the FinOps guide and shown concretely for AWS EC2.

How ZopNight schedules non-production resources

The loop that does this is deliberately mechanical, and it starts read-only. You connect your cloud provider with a read-only role, and ZopNight discovers every non-production resources across your regions and accounts. It records a per-action permission verdict for each one, so you can see where it can list a resource but not yet stop it, and you review that inventory, filter it by status or type, and search for the specific resources you care about before anything is scheduled.

Scheduling itself is a cron you write once in plain terms, stop at 7 PM, start at 8 AM on weekdays, pinned to your timezone so the jobs fire at local business hours rather than UTC. A weekly 24-hour grid shows the schedule visually so you catch gaps and overlaps before you save, and an estimate of active versus inactive hours appears before you commit. Resources attach individually or bundle into groups like “dev-cluster” or “staging-db” so a whole environment follows one cadence.

Actions run in dependency order, so a database comes up before the app server that depends on it. When something needs to stay up, an override forces a non-production resources ON or OFF for a defined window, carries a reason so teammates understand why it exists, and expires automatically so nothing is left running by accident. If a start or stop fails, ZopNight retries up to three times and falls back to a dead-letter queue rather than silently dropping the action, and every state change lands in an audit trail that records whether a schedule, an override, or a specific user triggered it.

Getting started

Getting started is intentionally low-stakes:

  • Connect your cloud provider with a read-only role. Nothing is scheduled or changed at this stage.
  • Let ZopNight discover your non-production resources and review exactly what it found, filtered by account, region, and status.
  • Create a schedule in your timezone and attach the non-production resources or groups you want it to cover.
  • Watch the first cycle run, with Slack, Teams, or Google Chat notifications on every start, stop, and failure, then layer in idle cleanup and guided rightsizing.

Production stays excluded by default throughout, and because discovery and recommendations are read-only, you can prove the value before you enable a single action.

faq

Questions we get a lot.

If yours isn't here, email us and we'll answer directly.

How long does it take to reach Walk maturity?

For scheduling specifically, most teams reach Walk in 1-2 weeks: connect accounts, create schedules, assign resources. For broader FinOps maturity (including commitment management, chargeback, and governance), Walk typically takes 2-3 months.

Do I need a dedicated FinOps team to progress through the maturity model?

Not initially. A single FinOps champion can drive Crawl and Walk phases. A dedicated team or role becomes valuable at Run, when maintaining automation, managing commitments, and governing policies requires ongoing attention.

Stop watching the waste.
Start cutting it.

See. Find. Fix. Automatic.

Connect your first cloud account in under 5 minutes. See your first remediation in under 7. No credit card required.

CDCR connect detect classify remediate
full audit every action traceable
read-only default access
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·