Vulnerability Management Maturity Calculator
Rate six vulnerability-management domains 1–5 and get a weighted maturity score, a level, your weakest domain and the next step.
Inputs
Maturity Score
54.0%
Maturity Level
Level 2 — Repeatable
Grade
D — Weak
Weighted Points
270.0of 500
Weakest Domain
Risk-based prioritisation
Next Step
Join EPSS and KEV to asset criticality so the queue is ordered by real risk
Step by step
Values used
Asset inventory and ownership = 3 — CMDB with known gaps; Scanning coverage and depth = 3 — Authenticated scans on most assets; Risk-based prioritisation = 2 — CVSS plus manual judgement; Remediation and SLA discipline = 3 — Measured, frequently breached; Automation and integration = 2 — Tickets raised by hand; Metrics and governance = 3 — Regular operational reporting
Vulnerability Management Maturity
Score = (20 × inventory + 20 × scanning + 20 × prioritisation + 20 × remediation + 10 × automation + 10 × metrics) ÷ 5, giving 0–100 from six 1–5 ratings.
Maturity levels
Levels: below 36 Initial, 36–55 Repeatable, 56–71 Defined, 72–87 Managed, 88+ Optimising.
Maturity Score
= 54.0
Maturity Level
= Level 2 — Repeatable
Grade
= D — Weak
Weighted Points
= 270.0 of 500
Weakest Domain
= Risk-based prioritisation
Next Step
= Join EPSS and KEV to asset criticality so the queue is ordered by real risk
How it works
The four heavily weighted domains form a dependency chain: you cannot scan what is not inventoried, cannot prioritise what is not scanned, and cannot remediate what is not prioritised. Automation and metrics carry half the weight because they multiply an existing capability rather than create one — automating a programme with a broken inventory just produces wrong tickets faster. Maturity scoring turns 'we should do better at patching' into a ranked list of investments, and the weakest-domain output usually contradicts the domain the team wanted to spend money on.
Formulas
Vulnerability Management Maturity
Score = (20 × inventory + 20 × scanning + 20 × prioritisation + 20 × remediation + 10 × automation + 10 × metrics) ÷ 5, giving 0–100 from six 1–5 ratings.
- 20-point domains
- Inventory, scanning, prioritisation and remediation — the four that decide outcomes
- 10-point domains
- Automation and metrics — force multipliers rather than prerequisites
- ÷ 5
- Converts the 100–500 weighted points to a 20–100 percentage
Maturity levels
Levels: below 36 Initial, 36–55 Repeatable, 56–71 Defined, 72–87 Managed, 88+ Optimising.
Frequently Asked Questions
How is Vulnerability Management Maturity calculated?
Score = (20 × inventory + 20 × scanning + 20 × prioritisation + 20 × remediation + 10 × automation + 10 × metrics) ÷ 5, giving 0–100 from six 1–5 ratings. The four heavily weighted domains form a dependency chain: you cannot scan what is not inventoried, cannot prioritise what is not scanned, and cannot remediate what is not prioritised. Automation and metrics carry half the weight because they multiply an existing capability rather than create one — automating a programme with a broken inventory just produces wrong tickets faster.
Why does Vulnerability Management Maturity matter?
Maturity scoring turns 'we should do better at patching' into a ranked list of investments, and the weakest-domain output usually contradicts the domain the team wanted to spend money on.
What values do I need to enter?
This calculator takes 6 inputs: Asset inventory and ownership, Scanning coverage and depth, Risk-based prioritisation, Remediation and SLA discipline, Automation and integration, Metrics and governance. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Should I aim for Level 5 everywhere?
No. Level 4 across inventory, scanning, prioritisation and remediation beats Level 5 in one domain and Level 2 in another, because the chain is only as strong as its weakest link. Balance first, then optimise.
How often should this be reassessed?
Twice a year, with the same rater and the same evidence standard. Self-assessment drifts upward, so require evidence for any rating of 4 or 5 — a report, a coverage figure, a rescan record.
You might also need
- Vulnerability Health Score CalculatorCommonly used together
- Scanner Coverage CalculatorCommonly used together
- Threat Intelligence Coverage CalculatorCommonly used together
- Patch Compliance CalculatorCommonly used together
- Technical Debt Risk CalculatorCommonly used together
- Patch Priority CalculatorAlso in Vulnerability Management