Zero Trust Readiness Calculator
Score your zero trust maturity across identity, device, network, application, data, visibility and automation pillars.
Inputs
Zero Trust Readiness Score
58.8/100
Maturity Stage
Initial
Grade
D — Weak
Weakest Pillar
Response automation
Points to Advanced Stage
11.3
Step by step
Values used
Accounts covered by phishing-resistant MFA = 78 %; Endpoints with enforced compliance posture checks = 65 %; Workloads under micro-segmentation policy = 40 %; Applications behind per-request authorisation = 55 %; Data assets classified and labelled = 45 %; Estate covered by security telemetry = 70 %; Response actions automated = 35 %
Zero Trust Readiness
score = 0.25·identity + 0.20·network + 0.15·device + 0.15·application + 0.10·data + 0.10·visibility + 0.05·automation.
Zero Trust Readiness Score
= 58.8 /100
Maturity Stage
= Initial
Grade
= D — Weak
Weakest Pillar
= Response automation
Points to Advanced Stage
= 11.3
How it works
The pillar weights mirror the CISA Zero Trust Maturity Model's emphasis: identity carries the most weight because every other control depends on knowing who is asking, and network segmentation is next because it bounds the damage when identity fails. The weighted sum maps onto the traditional, initial, advanced and optimal stages. Zero trust programmes stall when they over-invest in one pillar — usually MFA — while segmentation, data classification and automation lag, leaving the weighted score, and the real blast radius, unchanged.
Formula
Zero Trust Readiness
score = 0.25·identity + 0.20·network + 0.15·device + 0.15·application + 0.10·data + 0.10·visibility + 0.05·automation.
- identity
- Phishing-resistant MFA coverage across accounts
- network
- Share of workloads under micro-segmentation policy
- automation
- Share of response actions that run without a human
Frequently Asked Questions
How is Zero Trust Readiness calculated?
score = 0.25·identity + 0.20·network + 0.15·device + 0.15·application + 0.10·data + 0.10·visibility + 0.05·automation. The pillar weights mirror the CISA Zero Trust Maturity Model's emphasis: identity carries the most weight because every other control depends on knowing who is asking, and network segmentation is next because it bounds the damage when identity fails. The weighted sum maps onto the traditional, initial, advanced and optimal stages.
Why does Zero Trust Readiness matter?
Zero trust programmes stall when they over-invest in one pillar — usually MFA — while segmentation, data classification and automation lag, leaving the weighted score, and the real blast radius, unchanged.
What values do I need to enter?
This calculator takes 7 inputs: Accounts covered by phishing-resistant MFA, Endpoints with enforced compliance posture checks, Workloads under micro-segmentation policy, Applications behind per-request authorisation, Data assets classified and labelled, Estate covered by security telemetry, Response actions automated. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is a high score the same as being breach-proof?
No. The score measures coverage of the controls, not their configuration quality. A tenant with 100% MFA coverage using SMS codes scores the same as one using FIDO2 hardware keys, yet only the second resists phishing. Use the score to find gaps, then audit the strength of what is deployed.
You might also need
- Network Security Score CalculatorCommonly used together
- Micro-Segmentation CalculatorCommonly used together
- East-West Security CalculatorCommonly used together
- ARP Spoofing Risk CalculatorAlso in Network Security
- ACL Rule CalculatorAlso in Network Security
- DDoS Capacity CalculatorAlso in Network Security