Rate six vulnerability-management domains 1–5 and get a weighted maturity score, a level, your weakest domain and the next step.
The four heavily weighted domains form a dependency chain: you cannot scan what is not inventoried, cannot prioritise what is not scanned, and cannot remediate what is not prioritised. Automation and metrics carry half the weight because they multiply an existing capability rather than create one — automating a programme with a broken inventory just produces wrong tickets faster. Maturity scoring turns 'we should do better at patching' into a ranked list of investments, and the weakest-domain output usually contradicts the domain the team wanted to spend money on.
Vulnerability Management Maturity
Score = (20 × inventory + 20 × scanning + 20 × prioritisation + 20 × remediation + 10 × automation + 10 × metrics) ÷ 5, giving 0–100 from six 1–5 ratings.
Maturity levels
Levels: below 36 Initial, 36–55 Repeatable, 56–71 Defined, 72–87 Managed, 88+ Optimising.
Score = (20 × inventory + 20 × scanning + 20 × prioritisation + 20 × remediation + 10 × automation + 10 × metrics) ÷ 5, giving 0–100 from six 1–5 ratings. The four heavily weighted domains form a dependency chain: you cannot scan what is not inventoried, cannot prioritise what is not scanned, and cannot remediate what is not prioritised. Automation and metrics carry half the weight because they multiply an existing capability rather than create one — automating a programme with a broken inventory just produces wrong tickets faster.
Maturity scoring turns 'we should do better at patching' into a ranked list of investments, and the weakest-domain output usually contradicts the domain the team wanted to spend money on.
This calculator takes 6 inputs: Asset inventory and ownership, Scanning coverage and depth, Risk-based prioritisation, Remediation and SLA discipline, Automation and integration, Metrics and governance. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
No. Level 4 across inventory, scanning, prioritisation and remediation beats Level 5 in one domain and Level 2 in another, because the chain is only as strong as its weakest link. Balance first, then optimise.
Twice a year, with the same rater and the same evidence standard. Self-assessment drifts upward, so require evidence for any rating of 4 or 5 — a report, a coverage figure, a rescan record.