Score zero trust maturity across identity, device, network, application, data, visibility and automation on the CISA model.
The seven pillars follow CISA's Zero Trust Maturity Model, weighted by dependency: identity carries the most because device, application and data decisions all consume it, while automation carries the least because it accelerates policy rather than creating it. Systems still reachable on implicit network trust are deducted separately, since one flat zone undermines the enforcement everywhere else. The result is a prioritisation estimate for sequencing investment, not a certification of maturity. Zero trust programmes fail by buying products per pillar in parallel; the weighting shows that identity first, then device posture, is the only sequence where each step actually works.
Zero Trust Maturity
maturity = (0.22×identity + 0.16×device + 0.15×network + 0.15×application + 0.14×data + 0.10×visibility + 0.08×automation) ÷ 4 × 100, minus up to 20 points for implicit trust zones.
maturity = (0.22×identity + 0.16×device + 0.15×network + 0.15×application + 0.14×data + 0.10×visibility + 0.08×automation) ÷ 4 × 100, minus up to 20 points for implicit trust zones. The seven pillars follow CISA's Zero Trust Maturity Model, weighted by dependency: identity carries the most because device, application and data decisions all consume it, while automation carries the least because it accelerates policy rather than creating it. Systems still reachable on implicit network trust are deducted separately, since one flat zone undermines the enforcement everywhere else. The result is a prioritisation estimate for sequencing investment, not a certification of maturity.
Zero trust programmes fail by buying products per pillar in parallel; the weighting shows that identity first, then device posture, is the only sequence where each step actually works.
This calculator takes 8 inputs: Identity pillar, Device pillar, Network pillar, Application and workload pillar, Data pillar, Visibility and analytics, Automation and orchestration, Systems still reachable on implicit trust. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because every other control consumes an identity decision. Microsegmentation, conditional access and data labelling all reduce to 'who is this' — and if that answer is a reusable password, the rest is decoration.
Not in practice. Continuous verification means re-evaluating access as posture and risk change, and no team does that manually at estate scale. Automation is weighted low because it comes last, not because it is optional.