Zero Trust Maturity Self-Assessment Checklist
Retrospective: this article looks back at events from May 2021, written in 2026 with the benefit of hindsight.
Use this self-assessment to estimate your zero trust maturity across five pillars. Score each item: 0 = not started, 1 = partial, 2 = complete.
Identity
- MFA required for all users.
- Phishing-resistant MFA for administrators.
- Single identity provider with SSO for major apps (including AWS).
- Risk-based Conditional Access.
- Just-in-time privileged access.
Devices
- All corporate devices managed (Intune or equivalent).
- EDR deployed on all endpoints and servers.
- Access to sensitive data requires a compliant device.
- Unsupported operating systems removed or isolated.
Networks
- No management ports exposed to the internet.
- Private access to internal apps without broad VPN.
- Cloud data services on private endpoints.
- Outbound traffic filtered for sensitive workloads.
Applications and workloads
- Workload identities instead of stored secrets.
- Cloud posture management with findings tracked to closure.
- Least-privilege roles reviewed at least annually.
- Secure software development practices (code scanning, dependency scanning).
Data
- Sensitive data discovered and classified.
- Sensitivity labels and DLP in use.
- Encryption at rest and in transit.
- Retention and deletion enforced.
Visibility and response
- Centralized logging of identity, endpoint, email and cloud.
- 24/7 monitoring (in-house or managed).
- Tested incident response plan.
Interpreting results
Under 40% of available points: focus on identity and devices first. 40–70%: address networks and data. Over 70%: optimize and automate.