Zero Trust Maturity Calculator
Score zero trust maturity across identity, device, network, application, data, visibility and automation on the CISA model.
Inputs
Zero Trust Maturity
51.0/ 100
CISA Maturity Stage
Initial
Weakest Pillar
Device — access decisions cannot consider posture
Implicit Trust Penalty
7.0points
Pillars at Advanced or Better
2pillars
Next Investment
Enforce device compliance at access time, not just at enrolment
Step by step
Values used
Identity pillar = Advanced — phishing-resistant MFA, central identity; Device pillar = Initial — inventory with basic compliance; Network pillar = Initial — coarse VLAN segmentation; Application and workload pillar = Initial — some applications behind a proxy; Data pillar = Initial — classification defined, partly applied; Visibility and analytics = Advanced — correlated analytics across pillars; Automation and orchestration = Initial — scripted tasks; Systems still reachable on implicit trust = 35 %
Zero Trust Maturity
maturity = (0.22×identity + 0.16×device + 0.15×network + 0.15×application + 0.14×data + 0.10×visibility + 0.08×automation) ÷ 4 × 100, minus up to 20 points for implicit trust zones.
Zero Trust Maturity
= 51.0 / 100
CISA Maturity Stage
= Initial
Weakest Pillar
= Device — access decisions cannot consider posture
Implicit Trust Penalty
= 7.0 points
Pillars at Advanced or Better
= 2 pillars
Next Investment
= Enforce device compliance at access time, not just at enrolment
How it works
The seven pillars follow CISA's Zero Trust Maturity Model, weighted by dependency: identity carries the most because device, application and data decisions all consume it, while automation carries the least because it accelerates policy rather than creating it. Systems still reachable on implicit network trust are deducted separately, since one flat zone undermines the enforcement everywhere else. The result is a prioritisation estimate for sequencing investment, not a certification of maturity. Zero trust programmes fail by buying products per pillar in parallel; the weighting shows that identity first, then device posture, is the only sequence where each step actually works.
Formula
Zero Trust Maturity
maturity = (0.22×identity + 0.16×device + 0.15×network + 0.15×application + 0.14×data + 0.10×visibility + 0.08×automation) ÷ 4 × 100, minus up to 20 points for implicit trust zones.
- identity
- 1 traditional … 4 optimal on the CISA scale
- implicitTrustZones
- Share of systems still reachable purely by network position
- ÷ 4
- Normalises the 1–4 stage scale to a percentage
Frequently Asked Questions
How is Zero Trust Maturity calculated?
maturity = (0.22×identity + 0.16×device + 0.15×network + 0.15×application + 0.14×data + 0.10×visibility + 0.08×automation) ÷ 4 × 100, minus up to 20 points for implicit trust zones. The seven pillars follow CISA's Zero Trust Maturity Model, weighted by dependency: identity carries the most because device, application and data decisions all consume it, while automation carries the least because it accelerates policy rather than creating it. Systems still reachable on implicit network trust are deducted separately, since one flat zone undermines the enforcement everywhere else. The result is a prioritisation estimate for sequencing investment, not a certification of maturity.
Why does Zero Trust Maturity matter?
Zero trust programmes fail by buying products per pillar in parallel; the weighting shows that identity first, then device posture, is the only sequence where each step actually works.
What values do I need to enter?
This calculator takes 8 inputs: Identity pillar, Device pillar, Network pillar, Application and workload pillar, Data pillar, Visibility and analytics, Automation and orchestration, Systems still reachable on implicit trust. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why is identity weighted highest?
Because every other control consumes an identity decision. Microsegmentation, conditional access and data labelling all reduce to 'who is this' — and if that answer is a reusable password, the rest is decoration.
Can you reach optimal without automation?
Not in practice. Continuous verification means re-evaluating access as posture and risk change, and no team does that manually at estate scale. Automation is weighted low because it comes last, not because it is optional.
You might also need
- Breach and Attack Simulation Score CalculatorCommonly used together
- Enterprise Security Readiness CalculatorCommonly used together
- Insider Threat Risk CalculatorCommonly used together
- LLM Prompt Injection Risk CalculatorAlso in Forensics & Emerging Threats
- Enterprise Cybersecurity Health Score CalculatorAlso in Forensics & Emerging Threats
- Quantum Threat Readiness CalculatorAlso in Forensics & Emerging Threats