Zero Trust Phased Migration & Risk-Reduction ROI Calculator

Sequence identity, device, application/data, and network/visibility stages, then compare complete migration costs with marginal expected-loss reduction, NPV, ROI, payback, and priority.

Defaults are not market prices, incident statistics, or product-effect claims. Replace them with your risk register, BIA, pilot logs, operating evidence, and vendor quotes.

Organization scope

Risk baseline and shared initial cost

Analysis and sensitivity

Stage 1 · Identity

Establish IAM, MFA, PAM, identity lifecycle, and least-privilege foundations.

Stage 2 · Devices and endpoints

Connect inventory, EDR/UEM, posture checks, and device-aware access.

Stage 3 · Applications and data

Refine workload, API, service-identity, and data-access policy.

Stage 4 · Network and visibility

Connect ZTNA and segmentation with cross-stage visibility, analytics, and orchestration.

Phased zero trust ROI results

Baseline annual expected loss

$800,000

Steady cumulative risk reduction

39.06%

Analysis-horizon base NPV

-$396,350

Sustained payback

Not recovered in horizon

Highest-NPV cumulative stage

Stage 1 · Identity

Highest marginal-NPV stage

Stage 1 · Identity

Cumulative net value at target

-$471,402

Target missed · Additional benefit needed $471,402

Marginal economics by stage

Marginal economics by stage
StageMaturityScheduleStage TCOMarginal risk reductionMarginal NPVNPV-zero annual license ceilingEconomic rank
Stage 1 · IdentityTraditionalInitial13$443,53714%$66,318$59,4031
Stage 2 · Devices and endpointsTraditionalInitial46$399,7818.94%-$56,359$27,0612
Stage 3 · Applications and dataTraditionalInitial710$448,2049.25%-$113,526$13,8003
Stage 4 · Network and visibilityTraditionalInitial1115$543,6766.87%-$292,782$04

Three effect scenarios

Three effect scenarios
ScenarioCumulative risk reductionAnalysis-horizon base NPVPV ROIBenefit-cost ratioSustained paybackDiscounted payback
Conservative32.37%-$621,542-36.68%0.63×Not recovered in horizonNot recovered in horizon
Base39.06%-$396,350-23.39%0.77×Not recovered in horizonNot recovered in horizon
Upside45.24%-$186,774-11.02%0.89×Not recovered in horizonNot recovered in horizon

Nominal TCO per scope unit

Per user
$1,870
Per device
$1,558
Per application
$18,702
Per site
$187,020

Assumptions to recheck before deciding

  • The base case does not achieve sustained payback within the horizon.
  • Base-case cumulative net value remains negative at the target month.
  • At least one stage has negative marginal NPV. This is an economic result under current assumptions, not a security-need verdict.

Base annual cash flow

Base annual cash flow
YearMonth rangeAvoided expected lossInitial costRecurring costNet cash flowCumulative net valueDiscounted cumulative
1112$134,630$582,000$105,957-$553,327-$553,327-$542,125
21324$312,044$0$271,470$40,574-$512,753-$504,296
32536$336,013$0$294,662$41,351-$471,402-$467,620
43748$346,093$0$303,502$42,591-$428,811-$431,642
54960$356,476$0$312,607$43,869-$384,942-$396,350

Sources and model boundary

Sources checked 2026-08-12. KISA Zero Trust Guideline 2.0 and its maturity explainer, NIST SP 800-207, SP 1800-35, IR 8286A Rev. 1, CISA ZTMM v2, and NIST HB 135e2022 Update 1 support architecture, risk, and present-value boundaries only. Official maturity is never converted into effectiveness, and none provides a price, incident rate, loss, control effect, or acceptable ROI.

Related calculators

Why a phased zero trust ROI model matters

A zero trust migration is not a one-product purchase.
It is an operating transition that connects identity, devices and endpoints, applications and data, and network controls with visibility, analytics, automation, and orchestration.
The appropriate sequence and cost depend on the organization's users, devices, applications, sites, current IAM, MFA, EDR, segmentation, policy, and logging capabilities.

A common business-case error is to convert a maturity label into a fixed incident reduction or add several control effects together.
That can count the same event as fully prevented by multiple controls.
This calculator applies each later-stage effect to the risk that remains after earlier stages, places stage cost and benefit on a monthly timeline, and recomputes each cumulative portfolio to expose marginal NPV and an NPV-zero license ceiling.

Questions the model can support

  • What is the baseline annual expected loss and the modeled residual loss after four stages
  • What are five-year NPV, ROI, and first, sustained, and discounted payback after timing complete costs
  • How much incremental risk reduction and marginal NPV does each later stage add after earlier controls
  • What annual license ceiling makes a stage's marginal NPV equal zero under the current assumptions
  • Does the result remain stable when control effects move through conservative, base, and upside cases

Keep official maturity separate from financial effectiveness

KISA's December 18, 2025 zero trust maturity explainer describes four levels: Traditional, Initial, Advanced, and Optimal.
It organizes the Korean model around six core elements—identity, devices and endpoints, networks, systems, applications and workloads, and data—and two cross-cutting functions: visibility and analytics, plus automation and orchestration.
The guidance also stresses that organizations should adjust assessment scope and set realistic short- and long-term targets based on assets, regulation, budget, people, and execution capacity.

KISA four-level zero trust maturity and the calculator boundary
LevelHigh-level meaningUse in this calculator
1. TraditionalStatic perimeter, manual configuration, limited visibilityCurrent checklist label
2. InitialPartial automation, partial linkage, basic monitoringNear-term target label
3. AdvancedBroader automation, centralized integration, interaction-aware policyLonger-term target label
4. OptimalDynamic policy, extensive automation, continuous verificationHighest target candidate

Initial maturity does not mean 20% risk reduction

Official maturity is a framework for assessing policy, technology, process, and operating capability.
Financial inputs—incident frequency, impact, exposure coverage, conditional reduction, and evidence realization—must come separately from the organization's risk register, BIA, representative pilot, and operating records.
The calculator never converts a maturity number into incident probability or economic effect.

Normalize every input to one scope

Organization scope

Users can include employees, administrators, service operators, and partners actually covered by policy and licensing.
Align device counts with quote definitions for endpoints, mobile assets, servers, and IoT devices.
State whether application counts include workloads and APIs, and count offices, facilities, and cloud environments consistently as sites.

Risk baseline

Annual frequency and average impact must describe the same event, assets, and observation window.
Impact can include direct response, downtime, recovery, professional support, customer, and contract consequences, but overlapping components must be removed.
Materially different ransomware, account-takeover, and data-loss paths should be modeled separately when necessary.

Complete stage cost

Separate initial license and setup, directory, policy, logging, business-system and network integration, pilot work, training, and change management.
Recurring cost includes vendor license and support plus loaded internal work for policy, alerts, exceptions, tuning, and evidence.
Put architecture assessment and PMO work shared by all stages into the shared-cost field once.

Evidence-based stage effect

Exposure coverage is the share of baseline risk that the stage actually reaches.
Conditional reduction is the share of covered residual risk reduced in the pilot or other documented analysis.
Evidence realization is the share that remains after exceptions, operating constraints, false positives, and user behavior.

Residual-risk formulas for phased migration

1. Baseline expected loss

Baseline annual expected loss = annual incident frequency × average loss per incident
Standalone effective stage reduction = coverage × conditional reduction × realization

2. Marginal effect of a later stage

Pre-stage residual rate = product of (1 - effect) for earlier stages
Marginal stage reduction = pre-stage residual rate × stage effect
Cumulative reduction through stage N = 1 - product of (1 - effect) through stage N

If all four standalone stage effects equal 20%, their simple sum is 80%, but the residual-risk result is 59.04%.
Stage 1 reduces 20%; stage 2 reduces 20% of the remaining 80%, or 16%; stages 3 and 4 add 12.8% and 10.24%.
This does not prove independence between controls.
It is a conservative budgeting device that avoids simple addition; common-cause failure and correlation still require qualitative and technical analysis.

3. Monthly cash flow and present value

Go-live month = start month + implementation months - 1
Monthly net cash flow = avoided expected loss - initial cost - recurring cost
Discounted net cash flow = monthly net cash flow ÷ (1 + annual discount rate)^((month - 1) ÷ 12)
NPV = sum of discounted net cash flow over the horizon

Initial cost is placed at stage start; recurring cost and risk reduction begin at modeled go-live.
Effect rises linearly during the entered ramp period, while risk-loss and recurring-cost growth are compounded on a monthly exponent.
Because a later initial outlay can make cumulative value negative after an early crossing, the calculator separates first payback from sustained payback and also reports sustained discounted payback.

Worked example: marginal NPV by stage

Consider a unitless audit example with two incidents per year and average loss of 600, producing baseline annual expected loss of 1,200.
Four stages go live in months 1, 2, 3, and 4.
Each has initial cost 100, annual license 12, no operating-cost growth, no discounting, and a one-month ramp.
Coverage of 50%, conditional reduction of 40%, and realization of 100% produce a 20% standalone effect for each stage.

Marginal risk reduction and NPV for four stages with 20 percent standalone effects
Cumulative scopeMarginal reductionCumulative reductionCumulative NPVMarginal NPV
Through stage 120%20%128128
Through stage 216%36%19365
Through stage 312.8%48.8%21118
Through stage 410.24%59.04%194.16-16.84

Twelve-month total benefit is 636.16, total cost is 442, NPV is 194.16, PV ROI is approximately 43.93%, and sustained payback is approximately 8.47 months.
Cumulative NPV is highest after stage 3 at 211, while stage 4 has marginal NPV of -16.84.
That is not a finding that stage 4 is unnecessary.
It only says that incremental economic benefit is below incremental cost under this risk, effect, timing, and cost scenario; architecture dependency, regulation, critical assets, and risk tolerance remain separate decisions.

Interpret conservative, base, and upside effects

With a 20% scenario spread, the calculator multiplies every standalone stage effect by 0.8, 1.0, and 1.2, capped at 100%.
In the worked example, conservative NPV is 96.085376, base NPV is 194.16, and upside NPV is 280.082816.
These are deterministic sensitivities chosen by the user, not statistical confidence bounds or forecasts.

Conservative

Use lower pilot performance, narrower coverage, and more operating exceptions.

Base

Use the most defensible representative evidence and approved execution plan.

Upside

Model successful expansion and stabilization without presenting it as a contractual guarantee.

Investigate effect before deciding when NPV changes sign

If NPV moves from negative to positive between conservative and upside cases, the decision is sensitive to effect assumptions.
Extend the pilot or improve measurement of exposure denominators, bypasses, exceptions, false positives, user behavior, and operating response rather than selecting the most favorable case.

Practical decision workflows

  1. Annual funding: separate identity and device work deliverable in the first year from application, data, network, and visibility work that belongs in a three- to five-year roadmap
  2. Proposal normalization: apply the same user, device, application, site, retained-work, support, tax, and integration scope to every vendor proposal
  3. Pilot design: measure coverage, conditional reduction, and realization separately, then define the residual event population that a later stage can address
  4. Commercial threshold: use the NPV-zero license ceiling as a negotiation reference while keeping security obligation and risk tolerance in a separate approval track
  5. Quarterly refresh: replace planned go-live, recurring cost, alert work, exception rate, and incident inputs with operating evidence and recompute payback

Accuracy tips and boundaries

Recommended input discipline

  • Use one risk scenario, asset boundary, and time window for frequency and impact
  • Normalize proposal features, support, integration, currency, and pre- or post-tax treatment
  • Value retained internal work with one loaded-cost or opportunity-value convention
  • Record explicit pilot denominators, duration, bypasses, and operating exceptions
  • Subtract only confirmed discounts or support, keeping expected grants in a separate case

What the calculator does not determine

  • KISA checklist completion, certification, or security adequacy
  • Market-average license price, incident cost, frequency, or effectiveness
  • Selection of an IAM, EDR, ZTNA, SASE, or microsegmentation product
  • Legal, privacy, regulatory, insurance, accounting, or tax treatment
  • Acceptable residual risk or an automatic investment approval

Frequently asked questions

Should stages be reordered by economic rank?

No. Economic rank only orders marginal NPV under the entered assumptions. Weak identity foundations can constrain device, application, and network policy, so architecture dependency and security priority come first.

Should annual frequency be zero if no incident was observed?

Review observation length and data quality. No recorded incident may not mean zero likelihood. Document risk-register evidence and expert judgment, then compare conservative and base inputs.

Does keeping current and target maturity equal remove the cost?

No. Maturity is descriptive, while cost and effect are calculated independently. A project can expand coverage within one maturity level, but document that scope because the calculator warns when the target is not higher.

Is the maximum annual license cost a fair market price?

No. It is the annual license amount that makes that stage marginal NPV equal zero under the current model. It is distinct from market price, quality, security necessity, and contract value.

How does this differ from the DLP expected-loss ROI calculator?

The DLP calculator analyzes one data-leakage control funnel in depth. This calculator compares the timing, complete cost, residual-risk effect, and cumulative portfolio economics of four migration bundles.

Primary sources and update boundary

Sources were checked on August 12, 2026.
KISA Zero Trust Guideline 2.0, published December 3, 2024, and the maturity explainer published December 18, 2025, support Korean maturity and adoption context only.
NIST SP 800-207, published August 2020, supports architecture principles; final SP 1800-35, published June 2025 with 19 example implementations, shows that integration paths vary.
Final NIST IR 8286A Rev. 1, published December 18, 2025, supports coherent likelihood-and-impact scenarios; NIST Handbook 135e2022 Update 1, updated November 29, 2022, supports present-value methodology only.
CISA ZTMM v2, published April 2023 with five pillars, is an international comparison reference, and U.S. federal targets are not treated as Korean or private-sector obligations.

Compare every next-stage quote against the same residual risk

Start with a coherent risk-register and BIA scenario, then replace illustrative stage costs and effects with proposal and pilot evidence.
Review conservative, base, and upside NPV together with marginal benefit, license ceilings, and target-month gaps before choosing the next approval, pilot, or negotiation action.