Rate cloud security maturity across seven domains on a 1-5 scale, weight them into a single level and show the gap and effort to your target.
Identity carries the heaviest weight because it is the control plane for everything else in cloud, and governance and automation carry the least — not because they matter less, but because they are enablers whose value shows up as improvements in the other five. The one-level-per-year assumption behind the effort estimate is conservative and matches what funded programmes actually achieve. Maturity assessments are how cloud security work gets funded, and a weighted model stops a team from reporting level 4 on the strength of one excellent domain while incident response is still improvised.
Cloud Security Maturity
Current level = identity × 0.20 + data protection × 0.15 + infrastructure × 0.15 + detection × 0.15 + response × 0.15 + governance × 0.10 + automation × 0.10, on a 1–5 scale.
Effort estimate
Estimated time to target = ceil(level gap × 4) quarters, assuming a sustained programme advances roughly one maturity level per year.
Current level = identity × 0.20 + data protection × 0.15 + infrastructure × 0.15 + detection × 0.15 + response × 0.15 + governance × 0.10 + automation × 0.10, on a 1–5 scale. Identity carries the heaviest weight because it is the control plane for everything else in cloud, and governance and automation carry the least — not because they matter less, but because they are enablers whose value shows up as improvements in the other five. The one-level-per-year assumption behind the effort estimate is conservative and matches what funded programmes actually achieve.
Maturity assessments are how cloud security work gets funded, and a weighted model stops a team from reporting level 4 on the strength of one excellent domain while incident response is still improvised.
This calculator takes 8 inputs: Identity and access management, Data protection and encryption, Infrastructure and network hardening, Detection and monitoring, Incident response, Governance and compliance, Security automation, Target maturity level. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
No. Level 5 costs disproportionately and only pays off where the risk justifies it. Most organisations should target 3 across the board and 4 in identity, data protection and detection. A uniform level 3 is a genuinely defensible posture; a level 5 in one domain next to a level 1 in another is not.
Twice a year, with the same assessor and the same evidence standard. More often and you measure noise; less often and the assessment stops driving the roadmap. Requiring evidence rather than opinion for each level is what keeps the numbers comparable between rounds.