Skip to content

Evidence request lists

CISA Zero Trust Maturity Model

Evidence request list. 46 controls, 46 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Applications and Workloads Pillar

ZTMM-APP-1
Application Access

Access to applications requires identity-aware, context-aware authorization regardless of network location.

Artefacts an auditor will ask for
  • IdP-protected app inventory
  • Reverse proxy or ZTNA config
  • Conditional access policies
Where this commonly fails
  • VPN-only access patterns
  • Apps bypassing SSO
ZTMM-APP-2
Application Threat Protection

Protect applications and workloads with runtime protection, WAF, and continuous threat monitoring.

Artefacts an auditor will ask for
  • WAF configuration and tuning records
  • Runtime protection coverage
  • Threat monitoring dashboards
Where this commonly fails
  • WAF in monitor-only mode
  • Legacy apps unprotected
ZTMM-APP-3
Secure Application Development and Deployment

Adopt secure development practices and continuous deployment with embedded security testing.

Artefacts an auditor will ask for
  • CI/CD pipeline with SAST, SCA, secret scanning
  • Policy-as-code
  • Pipeline gate evidence
Where this commonly fails
  • Manual deployments bypassing controls
ZTMM-APP-4
Application Visibility and Analytics

Instrument applications for security visibility, with telemetry feeding analytics and detection.

Artefacts an auditor will ask for
  • Application logging standard
  • Telemetry coverage report
  • Sample detections
Where this commonly fails
  • No app-layer logging for COTS

CISA Zero Trust Maturity Model: Access Control & Identity

ZTMM-ID-AO
Identity Pillar: Automation and Orchestration

Automate identity lifecycle, provisioning, and policy enforcement across the identity pillar.

Artefacts an auditor will ask for
  • Automated identity lifecycle and provisioning
Where this commonly fails
  • Manual provisioning/deprovisioning
ZTMM-ID-VA
Identity Pillar: Visibility and Analytics

Collect and analyze identity-related data (authentication patterns, account activity) to inform access decisions and detect anomalous identity behavior.

Artefacts an auditor will ask for
  • Identity analytics and anomaly detection coverage
Where this commonly fails
  • Authentication events not analyzed
ZTMM-STAGE-ADV
Maturity Stage: Advanced

Coordinated controls across pillars with centralized visibility and identity control, policy enforcement integrated across pillars, and response to predefined mitigations.

Artefacts an auditor will ask for
  • Evidence of coordinated controls and centralized visibility
Where this commonly fails
  • Pillars still siloed despite advanced claims
ZTMM-STAGE-INIT
Maturity Stage: Initial

Starting automation of attribute assignment and policy configuration, initial cross-pillar solutions, and aggregated visibility for internal systems.

Artefacts an auditor will ask for
  • Evidence of initial automation and cross-pillar solutions
Where this commonly fails
  • Automation claimed but not evidenced
ZTMM-STAGE-OPT
Maturity Stage: Optimal

Fully automated, just-in-time lifecycles and attribute assignments, dynamic policies tailored to automated risk decisions, and centralized visibility with comprehensive situational awareness.

Artefacts an auditor will ask for
  • Evidence of dynamic, automated policy and full situational awareness
Where this commonly fails
  • Dynamic policy not actually automated
ZTMM-STAGE-TRAD
Maturity Stage: Traditional

Baseline stage with manually configured lifecycles and attributes, static security policies, siloed pillars, manual response and mitigation, and limited correlation of dependencies.

Artefacts an auditor will ask for
  • Self-assessment showing Traditional-stage characteristics
Where this commonly fails
  • No baseline maturity assessment performed

CISA Zero Trust Maturity Model: Configuration Management

ZTMM-DAT-AVAIL
Data Pillar: Data Availability

Ensure resilient and redundant access to data, including off-site or redundant stores, to support availability requirements.

Artefacts an auditor will ask for
  • Data redundancy and resilient access design
Where this commonly fails
  • No redundant/off-site data availability
ZTMM-DAT-CAT
Data Pillar: Data Categorization

Categorize and label data based on sensitivity to drive granular, risk-based access and protection decisions.

Artefacts an auditor will ask for
  • Data categorization/labeling scheme and coverage
Where this commonly fails
  • Data not categorized by sensitivity

CISA Zero Trust Maturity Model: Incident Response

ZTMM-APP-GOV
Applications Pillar: Governance

Define and enforce application security, access, and secure development governance.

Artefacts an auditor will ask for
  • Secure development and app access governance
Where this commonly fails
  • No app security governance
ZTMM-APP-TEST
Applications Pillar: Application Security Testing

Integrate routine static, dynamic, and interactive application security testing throughout the development and deployment lifecycle.

Artefacts an auditor will ask for
  • Routine SAST/DAST/IAST integration evidence
Where this commonly fails
  • No application security testing in pipeline
ZTMM-DAT-AO
Data Pillar: Automation and Orchestration

Automate data categorization, labeling, and protection policy enforcement across the data pillar.

Artefacts an auditor will ask for
  • Automated data labeling and protection enforcement
Where this commonly fails
  • Manual data classification only
ZTMM-DAT-GOV
Data Pillar: Governance

Define and enforce data inventory, categorization, retention, and access governance.

Artefacts an auditor will ask for
  • Data inventory, retention, and access governance
Where this commonly fails
  • No data governance program
ZTMM-DAT-VA
Data Pillar: Visibility and Analytics

Collect and analyze data access and usage to detect anomalous access and inform data protection decisions.

Artefacts an auditor will ask for
  • Data access analytics and anomaly detection
Where this commonly fails
  • Data access not monitored

CISA Zero Trust Maturity Model: Risk Assessment & Management

ZTMM-APP-AO
Applications Pillar: Automation and Orchestration

Automate application access policy, testing, and deployment workflows across the applications pillar.

Artefacts an auditor will ask for
  • Automated app access policy and deployment workflows
Where this commonly fails
  • Manual app access provisioning
ZTMM-APP-VA
Applications Pillar: Visibility and Analytics

Collect and analyze application access and behavior data to detect threats and inform access decisions.

Artefacts an auditor will ask for
  • Application access/behavior analytics
Where this commonly fails
  • Application activity not monitored
ZTMM-NET-AO
Networks Pillar: Automation and Orchestration

Automate network configuration, segmentation, and traffic policy enforcement across the network pillar.

Artefacts an auditor will ask for
  • Automated segmentation and traffic policy enforcement
Where this commonly fails
  • Manual network changes only
ZTMM-NET-ENC
Networks Pillar: Traffic Encryption

Encrypt network traffic, progressing from limited encryption of some traffic toward encryption of all applicable enterprise traffic.

Artefacts an auditor will ask for
  • Traffic encryption coverage report
Where this commonly fails
  • Significant unencrypted internal traffic
ZTMM-NET-GOV
Networks Pillar: Governance

Define and enforce network segmentation, encryption, and traffic management policies.

Artefacts an auditor will ask for
  • Segmentation and traffic management policy
Where this commonly fails
  • Flat network
  • No segmentation governance

CISA Zero Trust Maturity Model: System & Communications Protection

ZTMM-DEV-AO
Devices Pillar: Automation and Orchestration

Automate device enrollment, compliance enforcement, and remediation across the device pillar.

Artefacts an auditor will ask for
  • Automated device compliance enforcement/remediation
Where this commonly fails
  • Manual device remediation
ZTMM-DEV-GOV
Devices Pillar: Governance

Define and enforce device policies, supply chain risk management, and configuration governance.

Artefacts an auditor will ask for
  • Device policy and configuration governance
Where this commonly fails
  • No enforced device baseline
ZTMM-DEV-SCRM
Devices Pillar: Asset and Supply Chain Risk Management

Manage the inventory, supply chain provenance, and lifecycle risk of devices accessing enterprise resources.

Artefacts an auditor will ask for
  • Device inventory with supply chain provenance
Where this commonly fails
  • No supply chain risk tracking for devices
ZTMM-DEV-VA
Devices Pillar: Visibility and Analytics

Collect and analyze device posture, compliance, and behavior data to inform access decisions and detect compromised devices.

Artefacts an auditor will ask for
  • Device posture and behavior analytics coverage
Where this commonly fails
  • Device posture not analyzed for access
ZTMM-ID-GOV
Identity Pillar: Governance

Define and enforce identity policies, entitlements, and access governance across the enterprise.

Artefacts an auditor will ask for
  • Identity entitlement and access governance policy
Where this commonly fails
  • Entitlements not reviewed
  • No access certification
ZTMM-NET-VA
Networks Pillar: Visibility and Analytics

Collect and analyze network traffic and telemetry to detect threats and inform segmentation and access decisions.

Artefacts an auditor will ask for
  • Network traffic analytics and threat detection
Where this commonly fails
  • East-west traffic not analyzed

Cross-Cutting Capability

ZTMM-CROSS-1
Visibility and Analytics

Unify telemetry across pillars into analytics that drive detection, response, and policy decisions.

Artefacts an auditor will ask for
  • Telemetry coverage map
  • Correlation rules across pillars
  • Detection coverage report
Where this commonly fails
  • Siloed tooling
  • No identity telemetry in SIEM
ZTMM-CROSS-2
Automation and Orchestration

Automate policy enforcement, response, and provisioning across pillars to reduce reaction time.

Artefacts an auditor will ask for
  • SOAR playbooks
  • Mean time to respond metrics
  • Automated provisioning evidence
Where this commonly fails
  • Manual ticket-driven response only
ZTMM-CROSS-3
Governance for Zero Trust

Establish zero trust governance including strategy, roadmap, funding, and measurement against maturity stages.

Artefacts an auditor will ask for
  • ZT strategy document
  • Maturity self-assessment
  • Roadmap with funding
Where this commonly fails
  • No single owner for ZT program

Data Pillar

ZTMM-DAT-1
Data Inventory and Classification

Discover and classify data across structured and unstructured stores, updating continuously.

Artefacts an auditor will ask for
  • Data discovery tool output
  • Classification scheme
  • Continuous classification evidence
Where this commonly fails
  • Unstructured data uncatalogued
ZTMM-DAT-2
Data Access Control

Apply attribute-based, dynamic access control to data based on classification and user context.

Artefacts an auditor will ask for
  • ABAC policies for data stores
  • Access review records
  • Sensitivity label enforcement
Where this commonly fails
  • File shares with broad access
  • No label-based controls
ZTMM-DAT-3
Data Encryption

Encrypt data at rest and in transit with managed keys and lifecycle rotation.

Artefacts an auditor will ask for
  • KMS configuration
  • Encryption coverage report
  • Key rotation records
Where this commonly fails
  • Backups unencrypted
  • Legacy systems without TLS
ZTMM-DAT-4
Data Loss Prevention

Detect and prevent unauthorized data movement across endpoint, network, and cloud channels.

Artefacts an auditor will ask for
  • DLP policies for endpoint, email, cloud
  • Incident records
  • Tuning history
Where this commonly fails
  • Monitor-only mode for sensitive data

Devices Pillar

ZTMM-DEV-1
Device Inventory

Maintain a real-time inventory of all devices including managed, unmanaged, and IoT/OT.

Artefacts an auditor will ask for
  • Unified device inventory
  • Reconciliation across MDM, EDR, NAC
  • IoT/OT coverage report
Where this commonly fails
  • BYOD and contractor devices unknown
ZTMM-DEV-2
Device Compliance and Posture

Verify device compliance and posture (patch level, encryption, EDR) before granting access; continuously re-evaluate.

Artefacts an auditor will ask for
  • Compliance policy in MDM
  • Conditional access requiring compliance
  • Posture telemetry
Where this commonly fails
  • Compliance checked only at enrollment
ZTMM-DEV-3
Device Threat Protection

Deploy EDR or equivalent across all endpoints with integrated response actions.

Artefacts an auditor will ask for
  • EDR coverage report
  • Automated response playbooks
  • Threat hunt records
Where this commonly fails
  • Servers without EDR
  • OT endpoints uncovered

Identity Pillar

ZTMM-ID-1
Identity Authentication

Authentication evolves from passwords to phishing-resistant MFA across all users and accounts, with continuous validation at the Optimal stage.

Artefacts an auditor will ask for
  • MFA coverage report
  • Phishing-resistant authenticator rollout plan
  • Continuous authentication signals (risk-based)
Where this commonly fails
  • Password-only legacy apps
  • SMS MFA for privileged users
ZTMM-ID-2
Identity Stores

Move from siloed identity stores to a consolidated, governed identity fabric supporting human and machine identities.

Artefacts an auditor will ask for
  • Identity store inventory
  • Consolidation roadmap
  • Machine identity register
Where this commonly fails
  • Multiple unsynced AD forests
  • Service accounts outside IdP
ZTMM-ID-3
Risk Assessments for Identity

Use real-time risk signals (device, location, behavior) to drive authentication and authorization decisions.

Artefacts an auditor will ask for
  • Conditional access policies
  • Risk policy decisions
  • Telemetry feeding policy engine
Where this commonly fails
  • Static policies regardless of context
ZTMM-ID-4
Access Management

Move from role-based to attribute-based or just-in-time access with continuous authorization.

Artefacts an auditor will ask for
  • ABAC or policy-as-code repository
  • JIT access requests
  • Access reviews
Where this commonly fails
  • Standing privileged access
  • Roles with broad entitlements

Maturity

ZTMM-MAT-1
Maturity Stage Self-Assessment

Conduct regular self-assessment against Traditional, Initial, Advanced, and Optimal stages across all pillars.

Artefacts an auditor will ask for
  • ZTMM self-assessment workbook
  • Year-over-year trend
  • Gap remediation backlog
Where this commonly fails
  • Assessment done once and shelved

Networks Pillar

ZTMM-NET-1
Network Segmentation

Move from perimeter-based segmentation to micro-segmentation enforced by identity and policy.

Artefacts an auditor will ask for
  • Segmentation policy
  • Micro-segmentation tool config
  • East-west traffic policies
Where this commonly fails
  • Flat data center networks
  • No east-west enforcement
ZTMM-NET-2
Network Traffic Management

Encrypt traffic by default, inspect where feasible, and apply policy-based routing for sensitive flows.

Artefacts an auditor will ask for
  • TLS coverage report
  • Decryption policy and exceptions
  • Sensitive-flow routing rules
Where this commonly fails
  • Internal traffic still cleartext
ZTMM-NET-3
Resilience and Availability

Design network for resilience, with adaptive routing and DDoS protection for critical services.

Artefacts an auditor will ask for
  • DDoS protection contracts
  • Failover test results
  • Multi-path architecture
Where this commonly fails
  • Single ISP
  • No DDoS protection on critical apps
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the CISA Zero Trust Maturity Model framework page.