Skip to content
Calcrivo

Zero Trust Maturity Calculator

Score zero trust maturity across identity, device, network, application, data, visibility and automation on the CISA model.

Inputs

%

Zero Trust Maturity

51.0/ 100

CISA Maturity Stage

Initial

Weakest Pillar

Device — access decisions cannot consider posture

Implicit Trust Penalty

7.0points

Pillars at Advanced or Better

2pillars

Next Investment

Enforce device compliance at access time, not just at enrolment

Step by step

  1. Values used

    Identity pillar = Advanced — phishing-resistant MFA, central identity; Device pillar = Initial — inventory with basic compliance; Network pillar = Initial — coarse VLAN segmentation; Application and workload pillar = Initial — some applications behind a proxy; Data pillar = Initial — classification defined, partly applied; Visibility and analytics = Advanced — correlated analytics across pillars; Automation and orchestration = Initial — scripted tasks; Systems still reachable on implicit trust = 35 %

  2. Zero Trust Maturity

    maturity = (0.22×identity + 0.16×device + 0.15×network + 0.15×application + 0.14×data + 0.10×visibility + 0.08×automation) ÷ 4 × 100, minus up to 20 points for implicit trust zones.

  3. Zero Trust Maturity

    = 51.0 / 100

  4. CISA Maturity Stage

    = Initial

  5. Weakest Pillar

    = Device — access decisions cannot consider posture

  6. Implicit Trust Penalty

    = 7.0 points

  7. Pillars at Advanced or Better

    = 2 pillars

  8. Next Investment

    = Enforce device compliance at access time, not just at enrolment

How it works

The seven pillars follow CISA's Zero Trust Maturity Model, weighted by dependency: identity carries the most because device, application and data decisions all consume it, while automation carries the least because it accelerates policy rather than creating it. Systems still reachable on implicit network trust are deducted separately, since one flat zone undermines the enforcement everywhere else. The result is a prioritisation estimate for sequencing investment, not a certification of maturity. Zero trust programmes fail by buying products per pillar in parallel; the weighting shows that identity first, then device posture, is the only sequence where each step actually works.

Formula

Zero Trust Maturity

maturity = (0.22×identity + 0.16×device + 0.15×network + 0.15×application + 0.14×data + 0.10×visibility + 0.08×automation) ÷ 4 × 100, minus up to 20 points for implicit trust zones.

identity
1 traditional … 4 optimal on the CISA scale
implicitTrustZones
Share of systems still reachable purely by network position
÷ 4
Normalises the 1–4 stage scale to a percentage

Frequently Asked Questions

How is Zero Trust Maturity calculated?

maturity = (0.22×identity + 0.16×device + 0.15×network + 0.15×application + 0.14×data + 0.10×visibility + 0.08×automation) ÷ 4 × 100, minus up to 20 points for implicit trust zones. The seven pillars follow CISA's Zero Trust Maturity Model, weighted by dependency: identity carries the most because device, application and data decisions all consume it, while automation carries the least because it accelerates policy rather than creating it. Systems still reachable on implicit network trust are deducted separately, since one flat zone undermines the enforcement everywhere else. The result is a prioritisation estimate for sequencing investment, not a certification of maturity.

Why does Zero Trust Maturity matter?

Zero trust programmes fail by buying products per pillar in parallel; the weighting shows that identity first, then device posture, is the only sequence where each step actually works.

What values do I need to enter?

This calculator takes 8 inputs: Identity pillar, Device pillar, Network pillar, Application and workload pillar, Data pillar, Visibility and analytics, Automation and orchestration, Systems still reachable on implicit trust. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why is identity weighted highest?

Because every other control consumes an identity decision. Microsegmentation, conditional access and data labelling all reduce to 'who is this' — and if that answer is a reusable password, the rest is decoration.

Can you reach optimal without automation?

Not in practice. Continuous verification means re-evaluating access as posture and risk change, and no team does that manually at estate scale. Automation is weighted low because it comes last, not because it is optional.

You might also need