CISA Zero Trust Maturity Model
Evidence request list. 46 controls, 46 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Applications and Workloads Pillar
Access to applications requires identity-aware, context-aware authorization regardless of network location.
- IdP-protected app inventory
- Reverse proxy or ZTNA config
- Conditional access policies
- VPN-only access patterns
- Apps bypassing SSO
Protect applications and workloads with runtime protection, WAF, and continuous threat monitoring.
- WAF configuration and tuning records
- Runtime protection coverage
- Threat monitoring dashboards
- WAF in monitor-only mode
- Legacy apps unprotected
Adopt secure development practices and continuous deployment with embedded security testing.
- CI/CD pipeline with SAST, SCA, secret scanning
- Policy-as-code
- Pipeline gate evidence
- Manual deployments bypassing controls
Instrument applications for security visibility, with telemetry feeding analytics and detection.
- Application logging standard
- Telemetry coverage report
- Sample detections
- No app-layer logging for COTS
CISA Zero Trust Maturity Model: Access Control & Identity
Automate identity lifecycle, provisioning, and policy enforcement across the identity pillar.
- Automated identity lifecycle and provisioning
- Manual provisioning/deprovisioning
Collect and analyze identity-related data (authentication patterns, account activity) to inform access decisions and detect anomalous identity behavior.
- Identity analytics and anomaly detection coverage
- Authentication events not analyzed
Coordinated controls across pillars with centralized visibility and identity control, policy enforcement integrated across pillars, and response to predefined mitigations.
- Evidence of coordinated controls and centralized visibility
- Pillars still siloed despite advanced claims
Starting automation of attribute assignment and policy configuration, initial cross-pillar solutions, and aggregated visibility for internal systems.
- Evidence of initial automation and cross-pillar solutions
- Automation claimed but not evidenced
Fully automated, just-in-time lifecycles and attribute assignments, dynamic policies tailored to automated risk decisions, and centralized visibility with comprehensive situational awareness.
- Evidence of dynamic, automated policy and full situational awareness
- Dynamic policy not actually automated
Baseline stage with manually configured lifecycles and attributes, static security policies, siloed pillars, manual response and mitigation, and limited correlation of dependencies.
- Self-assessment showing Traditional-stage characteristics
- No baseline maturity assessment performed
CISA Zero Trust Maturity Model: Configuration Management
Ensure resilient and redundant access to data, including off-site or redundant stores, to support availability requirements.
- Data redundancy and resilient access design
- No redundant/off-site data availability
Categorize and label data based on sensitivity to drive granular, risk-based access and protection decisions.
- Data categorization/labeling scheme and coverage
- Data not categorized by sensitivity
CISA Zero Trust Maturity Model: Incident Response
Define and enforce application security, access, and secure development governance.
- Secure development and app access governance
- No app security governance
Integrate routine static, dynamic, and interactive application security testing throughout the development and deployment lifecycle.
- Routine SAST/DAST/IAST integration evidence
- No application security testing in pipeline
Automate data categorization, labeling, and protection policy enforcement across the data pillar.
- Automated data labeling and protection enforcement
- Manual data classification only
Define and enforce data inventory, categorization, retention, and access governance.
- Data inventory, retention, and access governance
- No data governance program
Collect and analyze data access and usage to detect anomalous access and inform data protection decisions.
- Data access analytics and anomaly detection
- Data access not monitored
CISA Zero Trust Maturity Model: Risk Assessment & Management
Automate application access policy, testing, and deployment workflows across the applications pillar.
- Automated app access policy and deployment workflows
- Manual app access provisioning
Collect and analyze application access and behavior data to detect threats and inform access decisions.
- Application access/behavior analytics
- Application activity not monitored
Automate network configuration, segmentation, and traffic policy enforcement across the network pillar.
- Automated segmentation and traffic policy enforcement
- Manual network changes only
Encrypt network traffic, progressing from limited encryption of some traffic toward encryption of all applicable enterprise traffic.
- Traffic encryption coverage report
- Significant unencrypted internal traffic
Define and enforce network segmentation, encryption, and traffic management policies.
- Segmentation and traffic management policy
- Flat network
- No segmentation governance
CISA Zero Trust Maturity Model: System & Communications Protection
Automate device enrollment, compliance enforcement, and remediation across the device pillar.
- Automated device compliance enforcement/remediation
- Manual device remediation
Define and enforce device policies, supply chain risk management, and configuration governance.
- Device policy and configuration governance
- No enforced device baseline
Manage the inventory, supply chain provenance, and lifecycle risk of devices accessing enterprise resources.
- Device inventory with supply chain provenance
- No supply chain risk tracking for devices
Collect and analyze device posture, compliance, and behavior data to inform access decisions and detect compromised devices.
- Device posture and behavior analytics coverage
- Device posture not analyzed for access
Define and enforce identity policies, entitlements, and access governance across the enterprise.
- Identity entitlement and access governance policy
- Entitlements not reviewed
- No access certification
Collect and analyze network traffic and telemetry to detect threats and inform segmentation and access decisions.
- Network traffic analytics and threat detection
- East-west traffic not analyzed
Cross-Cutting Capability
Unify telemetry across pillars into analytics that drive detection, response, and policy decisions.
- Telemetry coverage map
- Correlation rules across pillars
- Detection coverage report
- Siloed tooling
- No identity telemetry in SIEM
Automate policy enforcement, response, and provisioning across pillars to reduce reaction time.
- SOAR playbooks
- Mean time to respond metrics
- Automated provisioning evidence
- Manual ticket-driven response only
Establish zero trust governance including strategy, roadmap, funding, and measurement against maturity stages.
- ZT strategy document
- Maturity self-assessment
- Roadmap with funding
- No single owner for ZT program
Data Pillar
Discover and classify data across structured and unstructured stores, updating continuously.
- Data discovery tool output
- Classification scheme
- Continuous classification evidence
- Unstructured data uncatalogued
Apply attribute-based, dynamic access control to data based on classification and user context.
- ABAC policies for data stores
- Access review records
- Sensitivity label enforcement
- File shares with broad access
- No label-based controls
Encrypt data at rest and in transit with managed keys and lifecycle rotation.
- KMS configuration
- Encryption coverage report
- Key rotation records
- Backups unencrypted
- Legacy systems without TLS
Detect and prevent unauthorized data movement across endpoint, network, and cloud channels.
- DLP policies for endpoint, email, cloud
- Incident records
- Tuning history
- Monitor-only mode for sensitive data
Devices Pillar
Maintain a real-time inventory of all devices including managed, unmanaged, and IoT/OT.
- Unified device inventory
- Reconciliation across MDM, EDR, NAC
- IoT/OT coverage report
- BYOD and contractor devices unknown
Verify device compliance and posture (patch level, encryption, EDR) before granting access; continuously re-evaluate.
- Compliance policy in MDM
- Conditional access requiring compliance
- Posture telemetry
- Compliance checked only at enrollment
Deploy EDR or equivalent across all endpoints with integrated response actions.
- EDR coverage report
- Automated response playbooks
- Threat hunt records
- Servers without EDR
- OT endpoints uncovered
Identity Pillar
Authentication evolves from passwords to phishing-resistant MFA across all users and accounts, with continuous validation at the Optimal stage.
- MFA coverage report
- Phishing-resistant authenticator rollout plan
- Continuous authentication signals (risk-based)
- Password-only legacy apps
- SMS MFA for privileged users
Move from siloed identity stores to a consolidated, governed identity fabric supporting human and machine identities.
- Identity store inventory
- Consolidation roadmap
- Machine identity register
- Multiple unsynced AD forests
- Service accounts outside IdP
Use real-time risk signals (device, location, behavior) to drive authentication and authorization decisions.
- Conditional access policies
- Risk policy decisions
- Telemetry feeding policy engine
- Static policies regardless of context
Move from role-based to attribute-based or just-in-time access with continuous authorization.
- ABAC or policy-as-code repository
- JIT access requests
- Access reviews
- Standing privileged access
- Roles with broad entitlements
Maturity
Conduct regular self-assessment against Traditional, Initial, Advanced, and Optimal stages across all pillars.
- ZTMM self-assessment workbook
- Year-over-year trend
- Gap remediation backlog
- Assessment done once and shelved
Networks Pillar
Move from perimeter-based segmentation to micro-segmentation enforced by identity and policy.
- Segmentation policy
- Micro-segmentation tool config
- East-west traffic policies
- Flat data center networks
- No east-west enforcement
Encrypt traffic by default, inspect where feasible, and apply policy-based routing for sensitive flows.
- TLS coverage report
- Decryption policy and exceptions
- Sensitive-flow routing rules
- Internal traffic still cleartext
Design network for resilience, with adaptive routing and DDoS protection for critical services.
- DDoS protection contracts
- Failover test results
- Multi-path architecture
- Single ISP
- No DDoS protection on critical apps
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the CISA Zero Trust Maturity Model framework page.