Multi-CloudHow-To & HardeningRetrospectives

Zero Trust Maturity Self-Assessment Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2021, written in 2026 with the benefit of hindsight.

Use this self-assessment to estimate your zero trust maturity across five pillars. Score each item: 0 = not started, 1 = partial, 2 = complete.

Identity

  • MFA required for all users.
  • Phishing-resistant MFA for administrators.
  • Single identity provider with SSO for major apps (including AWS).
  • Risk-based Conditional Access.
  • Just-in-time privileged access.

Devices

  • All corporate devices managed (Intune or equivalent).
  • EDR deployed on all endpoints and servers.
  • Access to sensitive data requires a compliant device.
  • Unsupported operating systems removed or isolated.

Networks

  • No management ports exposed to the internet.
  • Private access to internal apps without broad VPN.
  • Cloud data services on private endpoints.
  • Outbound traffic filtered for sensitive workloads.

Applications and workloads

  • Workload identities instead of stored secrets.
  • Cloud posture management with findings tracked to closure.
  • Least-privilege roles reviewed at least annually.
  • Secure software development practices (code scanning, dependency scanning).

Data

  • Sensitive data discovered and classified.
  • Sensitivity labels and DLP in use.
  • Encryption at rest and in transit.
  • Retention and deletion enforced.

Visibility and response

  • Centralized logging of identity, endpoint, email and cloud.
  • 24/7 monitoring (in-house or managed).
  • Tested incident response plan.

Interpreting results

Under 40% of available points: focus on identity and devices first. 40–70%: address networks and data. Over 70%: optimize and automate.

zero trust maturity assessment checklistExecutive Order 140282021

More on this story