Skip to content
Calcrivo

Zero Trust Readiness Calculator

Score your zero trust maturity across identity, device, network, application, data, visibility and automation pillars.

Inputs

%
%
%
%
%
%
%

Zero Trust Readiness Score

58.8/100

Maturity Stage

Initial

Grade

D — Weak

Weakest Pillar

Response automation

Points to Advanced Stage

11.3

Step by step

  1. Values used

    Accounts covered by phishing-resistant MFA = 78 %; Endpoints with enforced compliance posture checks = 65 %; Workloads under micro-segmentation policy = 40 %; Applications behind per-request authorisation = 55 %; Data assets classified and labelled = 45 %; Estate covered by security telemetry = 70 %; Response actions automated = 35 %

  2. Zero Trust Readiness

    score = 0.25·identity + 0.20·network + 0.15·device + 0.15·application + 0.10·data + 0.10·visibility + 0.05·automation.

  3. Zero Trust Readiness Score

    = 58.8 /100

  4. Maturity Stage

    = Initial

  5. Grade

    = D — Weak

  6. Weakest Pillar

    = Response automation

  7. Points to Advanced Stage

    = 11.3

How it works

The pillar weights mirror the CISA Zero Trust Maturity Model's emphasis: identity carries the most weight because every other control depends on knowing who is asking, and network segmentation is next because it bounds the damage when identity fails. The weighted sum maps onto the traditional, initial, advanced and optimal stages. Zero trust programmes stall when they over-invest in one pillar — usually MFA — while segmentation, data classification and automation lag, leaving the weighted score, and the real blast radius, unchanged.

Formula

Zero Trust Readiness

score = 0.25·identity + 0.20·network + 0.15·device + 0.15·application + 0.10·data + 0.10·visibility + 0.05·automation.

identity
Phishing-resistant MFA coverage across accounts
network
Share of workloads under micro-segmentation policy
automation
Share of response actions that run without a human

Frequently Asked Questions

How is Zero Trust Readiness calculated?

score = 0.25·identity + 0.20·network + 0.15·device + 0.15·application + 0.10·data + 0.10·visibility + 0.05·automation. The pillar weights mirror the CISA Zero Trust Maturity Model's emphasis: identity carries the most weight because every other control depends on knowing who is asking, and network segmentation is next because it bounds the damage when identity fails. The weighted sum maps onto the traditional, initial, advanced and optimal stages.

Why does Zero Trust Readiness matter?

Zero trust programmes stall when they over-invest in one pillar — usually MFA — while segmentation, data classification and automation lag, leaving the weighted score, and the real blast radius, unchanged.

What values do I need to enter?

This calculator takes 7 inputs: Accounts covered by phishing-resistant MFA, Endpoints with enforced compliance posture checks, Workloads under micro-segmentation policy, Applications behind per-request authorisation, Data assets classified and labelled, Estate covered by security telemetry, Response actions automated. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Is a high score the same as being breach-proof?

No. The score measures coverage of the controls, not their configuration quality. A tenant with 100% MFA coverage using SMS codes scores the same as one using FIDO2 hardware keys, yet only the second resists phishing. Use the score to find gaps, then audit the strength of what is deployed.

You might also need