Measure zero-trust maturity across five pillars before buying more tools

CISA’s maturity model organizes zero-trust progress across Identity, Devices, Networks, Applications and Workloads, and Data with visibility, automation, and governance spanning each pillar.

Executive summary

What you need to know

CISA’s maturity model organizes zero-trust progress across Identity, Devices, Networks, Applications and Workloads, and Data with visibility, automation, and governance spanning each pillar.

Potentially affected

Leaders, architects, identity teams, endpoint teams, network defenders, application owners, data owners, and governance teams planning a staged zero-trust program.

DSE recommendation

Rate current practices with evidence, set risk-based targets by pillar, identify dependencies, prioritize measurable improvements, and reassess after material changes.

A zero-trust roadmap can become a shopping list when an organization has not described its current state or desired security outcomes. CISA’s maturity model supplies a common structure for examining progress without pretending that every pillar moves at the same speed.

How CISA organizes maturity

Source fact: CISA Zero Trust Maturity Model Version 2.0 is organized into five pillars: Identity, Devices, Networks, Applications and Workloads, and Data. Three capabilities—Visibility and Analytics, Automation and Orchestration, and Governance—cut across the pillars.

Source fact: The model describes Traditional, Initial, Advanced, and Optimal stages. CISA explains that maturity can differ across pillars and that the model is intended to help federal agencies develop zero-trust strategies and implementation plans. It is a reference model, not evidence that an organization is secure merely because it selects a maturity label.

Rate practices with evidence

DSE recommendation: assess a defined service or environment before attempting an enterprise-wide score. For each pillar and cross-cutting capability, record the operating practice, scope, owner, evidence, dependencies, exceptions, and last validation date. A purchased license or enabled feature is not enough; evidence should show that the intended access decision, telemetry, automation, or governance process actually operates.

  1. Identity: review identity lifecycle, authentication, privilege, service identities, federation, and session decisions.
  2. Devices: review inventory, ownership, health signals, configuration, isolation, and unsupported devices.
  3. Networks: review discovery, segmentation, encrypted paths, policy enforcement, and traffic visibility.
  4. Applications and workloads: review inventory, access, secure delivery, workload identity, dependencies, and runtime visibility.
  5. Data: review inventory, classification, access, encryption, rights, loss controls, lifecycle, and recovery.

Select targets by risk

DSE recommendation: choose target outcomes based on the service’s impact, credible threats, obligations, architecture, feasibility, and operational constraints. Identify which improvements benefit several pillars—for example, reliable asset and identity inventories can strengthen policy, visibility, incident response, and governance.

Give every roadmap item an accountable owner, dependency, milestone, validation method, operational safeguard, and rollback approach. Reassess after implementation, incidents, major architecture changes, provider changes, or evidence that a rating is no longer accurate.

Applicability and limits

CISA designed the model for federal agencies. Other organizations may adapt it, but should not imply CISA approval or certification. “Optimal” is a model stage, not zero residual risk, and forcing every environment toward the same target can create cost or operational harm. Use NIST SP 800-207 for architecture concepts and current product documentation for implementation.

Official reference

CISA Zero Trust Maturity Model Version 2.0 — five-pillar maturity and cross-cutting capability guidance.

Primary reference

Review the official source

CISA Zero Trust Maturity Model, Version 2.0 · Verified July 19, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE