Highest-NPV cumulative stage
Stage 1 · Identity
Sequence identity, device, application/data, and network/visibility stages, then compare complete migration costs with marginal expected-loss reduction, NPV, ROI, payback, and priority.
Defaults are not market prices, incident statistics, or product-effect claims. Replace them with your risk register, BIA, pilot logs, operating evidence, and vendor quotes.
Establish IAM, MFA, PAM, identity lifecycle, and least-privilege foundations.
Connect inventory, EDR/UEM, posture checks, and device-aware access.
Refine workload, API, service-identity, and data-access policy.
Connect ZTNA and segmentation with cross-stage visibility, analytics, and orchestration.
Baseline annual expected loss
$800,000
Steady cumulative risk reduction
39.06%
Analysis-horizon base NPV
-$396,350
Sustained payback
Not recovered in horizon
Stage 1 · Identity
Stage 1 · Identity
-$471,402
Target missed · Additional benefit needed $471,402
| Stage | Maturity | Schedule | Stage TCO | Marginal risk reduction | Marginal NPV | NPV-zero annual license ceiling | Economic rank |
|---|---|---|---|---|---|---|---|
| Stage 1 · Identity | Traditional → Initial | 1–3 | $443,537 | 14% | $66,318 | $59,403 | 1 |
| Stage 2 · Devices and endpoints | Traditional → Initial | 4–6 | $399,781 | 8.94% | -$56,359 | $27,061 | 2 |
| Stage 3 · Applications and data | Traditional → Initial | 7–10 | $448,204 | 9.25% | -$113,526 | $13,800 | 3 |
| Stage 4 · Network and visibility | Traditional → Initial | 11–15 | $543,676 | 6.87% | -$292,782 | $0 | 4 |
| Scenario | Cumulative risk reduction | Analysis-horizon base NPV | PV ROI | Benefit-cost ratio | Sustained payback | Discounted payback |
|---|---|---|---|---|---|---|
| Conservative | 32.37% | -$621,542 | -36.68% | 0.63× | Not recovered in horizon | Not recovered in horizon |
| Base | 39.06% | -$396,350 | -23.39% | 0.77× | Not recovered in horizon | Not recovered in horizon |
| Upside | 45.24% | -$186,774 | -11.02% | 0.89× | Not recovered in horizon | Not recovered in horizon |
| Year | Month range | Avoided expected loss | Initial cost | Recurring cost | Net cash flow | Cumulative net value | Discounted cumulative |
|---|---|---|---|---|---|---|---|
| 1 | 1–12 | $134,630 | $582,000 | $105,957 | -$553,327 | -$553,327 | -$542,125 |
| 2 | 13–24 | $312,044 | $0 | $271,470 | $40,574 | -$512,753 | -$504,296 |
| 3 | 25–36 | $336,013 | $0 | $294,662 | $41,351 | -$471,402 | -$467,620 |
| 4 | 37–48 | $346,093 | $0 | $303,502 | $42,591 | -$428,811 | -$431,642 |
| 5 | 49–60 | $356,476 | $0 | $312,607 | $43,869 | -$384,942 | -$396,350 |
Sources checked 2026-08-12. KISA Zero Trust Guideline 2.0 and its maturity explainer, NIST SP 800-207, SP 1800-35, IR 8286A Rev. 1, CISA ZTMM v2, and NIST HB 135e2022 Update 1 support architecture, risk, and present-value boundaries only. Official maturity is never converted into effectiveness, and none provides a price, incident rate, loss, control effect, or acceptable ROI.
A zero trust migration is not a one-product purchase.
It is an operating transition that connects identity, devices and endpoints, applications and data, and network controls with visibility, analytics, automation, and orchestration.
The appropriate sequence and cost depend on the organization's users, devices, applications, sites, current IAM, MFA, EDR, segmentation, policy, and logging capabilities.
A common business-case error is to convert a maturity label into a fixed incident reduction or add several control effects together.
That can count the same event as fully prevented by multiple controls.
This calculator applies each later-stage effect to the risk that remains after earlier stages, places stage cost and benefit on a monthly timeline, and recomputes each cumulative portfolio to expose marginal NPV and an NPV-zero license ceiling.
KISA's December 18, 2025 zero trust maturity explainer describes four levels: Traditional, Initial, Advanced, and Optimal.
It organizes the Korean model around six core elements—identity, devices and endpoints, networks, systems, applications and workloads, and data—and two cross-cutting functions: visibility and analytics, plus automation and orchestration.
The guidance also stresses that organizations should adjust assessment scope and set realistic short- and long-term targets based on assets, regulation, budget, people, and execution capacity.
| Level | High-level meaning | Use in this calculator |
|---|---|---|
| 1. Traditional | Static perimeter, manual configuration, limited visibility | Current checklist label |
| 2. Initial | Partial automation, partial linkage, basic monitoring | Near-term target label |
| 3. Advanced | Broader automation, centralized integration, interaction-aware policy | Longer-term target label |
| 4. Optimal | Dynamic policy, extensive automation, continuous verification | Highest target candidate |
Official maturity is a framework for assessing policy, technology, process, and operating capability.
Financial inputs—incident frequency, impact, exposure coverage, conditional reduction, and evidence realization—must come separately from the organization's risk register, BIA, representative pilot, and operating records.
The calculator never converts a maturity number into incident probability or economic effect.
Users can include employees, administrators, service operators, and partners actually covered by policy and licensing.
Align device counts with quote definitions for endpoints, mobile assets, servers, and IoT devices.
State whether application counts include workloads and APIs, and count offices, facilities, and cloud environments consistently as sites.
Annual frequency and average impact must describe the same event, assets, and observation window.
Impact can include direct response, downtime, recovery, professional support, customer, and contract consequences, but overlapping components must be removed.
Materially different ransomware, account-takeover, and data-loss paths should be modeled separately when necessary.
Separate initial license and setup, directory, policy, logging, business-system and network integration, pilot work, training, and change management.
Recurring cost includes vendor license and support plus loaded internal work for policy, alerts, exceptions, tuning, and evidence.
Put architecture assessment and PMO work shared by all stages into the shared-cost field once.
Exposure coverage is the share of baseline risk that the stage actually reaches.
Conditional reduction is the share of covered residual risk reduced in the pilot or other documented analysis.
Evidence realization is the share that remains after exceptions, operating constraints, false positives, and user behavior.
Baseline annual expected loss = annual incident frequency × average loss per incident
Standalone effective stage reduction = coverage × conditional reduction × realization
Pre-stage residual rate = product of (1 - effect) for earlier stages
Marginal stage reduction = pre-stage residual rate × stage effect
Cumulative reduction through stage N = 1 - product of (1 - effect) through stage N
If all four standalone stage effects equal 20%, their simple sum is 80%, but the residual-risk result is 59.04%.
Stage 1 reduces 20%; stage 2 reduces 20% of the remaining 80%, or 16%; stages 3 and 4 add 12.8% and 10.24%.
This does not prove independence between controls.
It is a conservative budgeting device that avoids simple addition; common-cause failure and correlation still require qualitative and technical analysis.
Go-live month = start month + implementation months - 1
Monthly net cash flow = avoided expected loss - initial cost - recurring cost
Discounted net cash flow = monthly net cash flow ÷ (1 + annual discount rate)^((month - 1) ÷ 12)
NPV = sum of discounted net cash flow over the horizon
Initial cost is placed at stage start; recurring cost and risk reduction begin at modeled go-live.
Effect rises linearly during the entered ramp period, while risk-loss and recurring-cost growth are compounded on a monthly exponent.
Because a later initial outlay can make cumulative value negative after an early crossing, the calculator separates first payback from sustained payback and also reports sustained discounted payback.
Consider a unitless audit example with two incidents per year and average loss of 600, producing baseline annual expected loss of 1,200.
Four stages go live in months 1, 2, 3, and 4.
Each has initial cost 100, annual license 12, no operating-cost growth, no discounting, and a one-month ramp.
Coverage of 50%, conditional reduction of 40%, and realization of 100% produce a 20% standalone effect for each stage.
| Cumulative scope | Marginal reduction | Cumulative reduction | Cumulative NPV | Marginal NPV |
|---|---|---|---|---|
| Through stage 1 | 20% | 20% | 128 | 128 |
| Through stage 2 | 16% | 36% | 193 | 65 |
| Through stage 3 | 12.8% | 48.8% | 211 | 18 |
| Through stage 4 | 10.24% | 59.04% | 194.16 | -16.84 |
Twelve-month total benefit is 636.16, total cost is 442, NPV is 194.16, PV ROI is approximately 43.93%, and sustained payback is approximately 8.47 months.
Cumulative NPV is highest after stage 3 at 211, while stage 4 has marginal NPV of -16.84.
That is not a finding that stage 4 is unnecessary.
It only says that incremental economic benefit is below incremental cost under this risk, effect, timing, and cost scenario; architecture dependency, regulation, critical assets, and risk tolerance remain separate decisions.
With a 20% scenario spread, the calculator multiplies every standalone stage effect by 0.8, 1.0, and 1.2, capped at 100%.
In the worked example, conservative NPV is 96.085376, base NPV is 194.16, and upside NPV is 280.082816.
These are deterministic sensitivities chosen by the user, not statistical confidence bounds or forecasts.
Use lower pilot performance, narrower coverage, and more operating exceptions.
Use the most defensible representative evidence and approved execution plan.
Model successful expansion and stabilization without presenting it as a contractual guarantee.
If NPV moves from negative to positive between conservative and upside cases, the decision is sensitive to effect assumptions.
Extend the pilot or improve measurement of exposure denominators, bypasses, exceptions, false positives, user behavior, and operating response rather than selecting the most favorable case.
No. Economic rank only orders marginal NPV under the entered assumptions. Weak identity foundations can constrain device, application, and network policy, so architecture dependency and security priority come first.
Review observation length and data quality. No recorded incident may not mean zero likelihood. Document risk-register evidence and expert judgment, then compare conservative and base inputs.
No. Maturity is descriptive, while cost and effect are calculated independently. A project can expand coverage within one maturity level, but document that scope because the calculator warns when the target is not higher.
No. It is the annual license amount that makes that stage marginal NPV equal zero under the current model. It is distinct from market price, quality, security necessity, and contract value.
The DLP calculator analyzes one data-leakage control funnel in depth. This calculator compares the timing, complete cost, residual-risk effect, and cumulative portfolio economics of four migration bundles.
Sources were checked on August 12, 2026.
KISA Zero Trust Guideline 2.0, published December 3, 2024, and the maturity explainer published December 18, 2025, support Korean maturity and adoption context only.
NIST SP 800-207, published August 2020, supports architecture principles; final SP 1800-35, published June 2025 with 19 example implementations, shows that integration paths vary.
Final NIST IR 8286A Rev. 1, published December 18, 2025, supports coherent likelihood-and-impact scenarios; NIST Handbook 135e2022 Update 1, updated November 29, 2022, supports present-value methodology only.
CISA ZTMM v2, published April 2023 with five pillars, is an international comparison reference, and U.S. federal targets are not treated as Korean or private-sector obligations.
Start with a coherent risk-register and BIA scenario, then replace illustrative stage costs and effects with proposal and pilot evidence.
Review conservative, base, and upside NPV together with marginal benefit, license ceilings, and target-month gaps before choosing the next approval, pilot, or negotiation action.