Skip to content
Calcrivo

Vulnerability Management Maturity Calculator

Rate six vulnerability-management domains 1–5 and get a weighted maturity score, a level, your weakest domain and the next step.

Inputs

Maturity Score

54.0%

Maturity Level

Level 2 — Repeatable

Grade

D — Weak

Weighted Points

270.0of 500

Weakest Domain

Risk-based prioritisation

Next Step

Join EPSS and KEV to asset criticality so the queue is ordered by real risk

Step by step

  1. Values used

    Asset inventory and ownership = 3 — CMDB with known gaps; Scanning coverage and depth = 3 — Authenticated scans on most assets; Risk-based prioritisation = 2 — CVSS plus manual judgement; Remediation and SLA discipline = 3 — Measured, frequently breached; Automation and integration = 2 — Tickets raised by hand; Metrics and governance = 3 — Regular operational reporting

  2. Vulnerability Management Maturity

    Score = (20 × inventory + 20 × scanning + 20 × prioritisation + 20 × remediation + 10 × automation + 10 × metrics) ÷ 5, giving 0–100 from six 1–5 ratings.

  3. Maturity levels

    Levels: below 36 Initial, 36–55 Repeatable, 56–71 Defined, 72–87 Managed, 88+ Optimising.

  4. Maturity Score

    = 54.0

  5. Maturity Level

    = Level 2 — Repeatable

  6. Grade

    = D — Weak

  7. Weighted Points

    = 270.0 of 500

  8. Weakest Domain

    = Risk-based prioritisation

  9. Next Step

    = Join EPSS and KEV to asset criticality so the queue is ordered by real risk

How it works

The four heavily weighted domains form a dependency chain: you cannot scan what is not inventoried, cannot prioritise what is not scanned, and cannot remediate what is not prioritised. Automation and metrics carry half the weight because they multiply an existing capability rather than create one — automating a programme with a broken inventory just produces wrong tickets faster. Maturity scoring turns 'we should do better at patching' into a ranked list of investments, and the weakest-domain output usually contradicts the domain the team wanted to spend money on.

Formulas

Vulnerability Management Maturity

Score = (20 × inventory + 20 × scanning + 20 × prioritisation + 20 × remediation + 10 × automation + 10 × metrics) ÷ 5, giving 0–100 from six 1–5 ratings.

20-point domains
Inventory, scanning, prioritisation and remediation — the four that decide outcomes
10-point domains
Automation and metrics — force multipliers rather than prerequisites
÷ 5
Converts the 100–500 weighted points to a 20–100 percentage

Maturity levels

Levels: below 36 Initial, 36–55 Repeatable, 56–71 Defined, 72–87 Managed, 88+ Optimising.

Frequently Asked Questions

How is Vulnerability Management Maturity calculated?

Score = (20 × inventory + 20 × scanning + 20 × prioritisation + 20 × remediation + 10 × automation + 10 × metrics) ÷ 5, giving 0–100 from six 1–5 ratings. The four heavily weighted domains form a dependency chain: you cannot scan what is not inventoried, cannot prioritise what is not scanned, and cannot remediate what is not prioritised. Automation and metrics carry half the weight because they multiply an existing capability rather than create one — automating a programme with a broken inventory just produces wrong tickets faster.

Why does Vulnerability Management Maturity matter?

Maturity scoring turns 'we should do better at patching' into a ranked list of investments, and the weakest-domain output usually contradicts the domain the team wanted to spend money on.

What values do I need to enter?

This calculator takes 6 inputs: Asset inventory and ownership, Scanning coverage and depth, Risk-based prioritisation, Remediation and SLA discipline, Automation and integration, Metrics and governance. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Should I aim for Level 5 everywhere?

No. Level 4 across inventory, scanning, prioritisation and remediation beats Level 5 in one domain and Level 2 in another, because the chain is only as strong as its weakest link. Balance first, then optimise.

How often should this be reassessed?

Twice a year, with the same rater and the same evidence standard. Self-assessment drifts upward, so require evidence for any rating of 4 or 5 — a report, a coverage figure, a rescan record.

You might also need