Score your zero trust maturity across identity, device, network, application, data, visibility and automation pillars.
The pillar weights mirror the CISA Zero Trust Maturity Model's emphasis: identity carries the most weight because every other control depends on knowing who is asking, and network segmentation is next because it bounds the damage when identity fails. The weighted sum maps onto the traditional, initial, advanced and optimal stages. Zero trust programmes stall when they over-invest in one pillar — usually MFA — while segmentation, data classification and automation lag, leaving the weighted score, and the real blast radius, unchanged.
Zero Trust Readiness
score = 0.25·identity + 0.20·network + 0.15·device + 0.15·application + 0.10·data + 0.10·visibility + 0.05·automation.
score = 0.25·identity + 0.20·network + 0.15·device + 0.15·application + 0.10·data + 0.10·visibility + 0.05·automation. The pillar weights mirror the CISA Zero Trust Maturity Model's emphasis: identity carries the most weight because every other control depends on knowing who is asking, and network segmentation is next because it bounds the damage when identity fails. The weighted sum maps onto the traditional, initial, advanced and optimal stages.
Zero trust programmes stall when they over-invest in one pillar — usually MFA — while segmentation, data classification and automation lag, leaving the weighted score, and the real blast radius, unchanged.
This calculator takes 7 inputs: Accounts covered by phishing-resistant MFA, Endpoints with enforced compliance posture checks, Workloads under micro-segmentation policy, Applications behind per-request authorisation, Data assets classified and labelled, Estate covered by security telemetry, Response actions automated. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
No. The score measures coverage of the controls, not their configuration quality. A tenant with 100% MFA coverage using SMS codes scores the same as one using FIDO2 hardware keys, yet only the second resists phishing. Use the score to find gaps, then audit the strength of what is deployed.