Skip to content

Evidence request lists

DoD Zero Trust Reference Architecture

Evidence request list. 45 controls, 45 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DoD ZT Pillar 1: User

DODZT-1.1
User Inventory

Maintain an authoritative inventory of all privileged and non-privileged users and non-person entities, connected to identity lifecycle (joiner/mover/leaver) management.

Artefacts an auditor will ask for
  • Authoritative user/NPE inventory from enterprise identity sources
  • Identity lifecycle management records
Where this commonly fails
  • No authoritative user inventory
  • Identity not tied to lifecycle management
DODZT-1.2
Conditional User Access

Enforce attribute-based, conditional user access to applications and data using vetted enterprise roles/attributes through ICAM governance.

Artefacts an auditor will ask for
  • Attribute/role-based conditional access policies
  • ICAM governance of attributes
Where this commonly fails
  • Static access not conditioned on attributes/context
DODZT-1.3
Multi-Factor Authentication

Require phishing-resistant multi-factor authentication for users, integrated with the enterprise IdP and PKI.

Artefacts an auditor will ask for
  • MFA enforcement records integrated with the enterprise IdP
  • Phishing-resistant authenticator deployment
Where this commonly fails
  • Single-factor authentication
  • MFA not phishing-resistant
DODZT-1.4
Privileged Access Management

Manage privileged access with Just-in-Time / Just-Enough-Administration through a PAM solution.

Artefacts an auditor will ask for
  • PAM solution with JIT/JEA enforcement
  • Privileged-session records
Where this commonly fails
  • Standing privileged access
  • No PAM/JIT-JEA
DODZT-1.5
Identity Federation and User Credentialing

Provide enterprise identity federation and standardized user credentialing across DoD components.

Artefacts an auditor will ask for
  • Federated identity configuration
  • Standard credentialing records
Where this commonly fails
  • Siloed, non-federated identity
DODZT-1.6
Behavioral, Contextual ID, and Biometrics

Incorporate behavioral, contextual and biometric signals into authentication and access decisions.

Artefacts an auditor will ask for
  • Behavioral/contextual/biometric signals feeding access decisions
Where this commonly fails
  • Access decisions ignore behavioral/contextual signals
DODZT-1.7
Least Privileged Access

Grant users the least privilege necessary, reviewed and enforced dynamically.

Artefacts an auditor will ask for
  • Least-privilege role definitions and periodic review
  • Dynamic privilege enforcement
Where this commonly fails
  • Over-provisioned access
  • No least-privilege review
DODZT-1.8
Continuous Authentication

Continuously authenticate and authorize users throughout a session rather than only at logon.

Artefacts an auditor will ask for
  • Continuous/periodic re-authentication configuration
  • Session-risk re-evaluation records
Where this commonly fails
  • Authenticate-once-at-logon only
DODZT-1.9
Integrated ICAM Platform

Operate an integrated Identity, Credential and Access Management platform as the enterprise authority for identity.

Artefacts an auditor will ask for
  • Integrated ICAM platform serving enterprise identity
Where this commonly fails
  • Fragmented ICAM tooling

DoD ZT Pillar 2: Device

DODZT-2.1
Device Inventory

Maintain a complete inventory of all devices (managed and unmanaged) connecting to the network.

Artefacts an auditor will ask for
  • Authoritative device inventory
  • Discovery of unmanaged devices
Where this commonly fails
  • Incomplete device inventory
DODZT-2.2
Device Detection and Compliance

Detect devices and continuously assess their compliance posture before and during access.

Artefacts an auditor will ask for
  • Device compliance posture checks
  • Comply-to-connect enforcement
Where this commonly fails
  • No device-compliance gate
DODZT-2.3
Device Authorization with Real-Time Inspection

Authorize devices using real-time inspection of device health and posture.

Artefacts an auditor will ask for
  • Real-time device health/posture inspection at access
Where this commonly fails
  • Authorization without real-time device inspection
DODZT-2.4
Remote Access

Secure remote access for devices consistent with zero-trust principles.

Artefacts an auditor will ask for
  • Zero-trust remote-access enforcement
Where this commonly fails
  • VPN-only flat remote access
DODZT-2.5
Partially and Fully Automated Asset, Vulnerability and Patch Management

Automate asset, vulnerability and patch management across devices.

Artefacts an auditor will ask for
  • Automated asset/vuln/patch pipelines
  • Patch SLAs and coverage reports
Where this commonly fails
  • Manual, incomplete patch/vuln management
DODZT-2.6
Unified Endpoint Management and Mobile Device Management

Manage endpoints and mobile devices through UEM/MDM.

Artefacts an auditor will ask for
  • UEM/MDM enrolment and policy enforcement
Where this commonly fails
  • Unmanaged endpoints/mobile devices
DODZT-2.7
Endpoint and Extended Detection and Response

Deploy EDR and integrate into XDR for detection and response across the environment.

Artefacts an auditor will ask for
  • EDR/XDR deployment and coverage
  • Detection/response telemetry
Where this commonly fails
  • No EDR/XDR on endpoints

DoD ZT Pillar 3: Application and Workload

DODZT-3.1
Application Inventory

Maintain an inventory of applications and their components.

Artefacts an auditor will ask for
  • Authoritative application inventory
Where this commonly fails
  • No application inventory
DODZT-3.2
Secure Software Development and Integration

Apply secure software development and integration practices (DevSecOps) for applications.

Artefacts an auditor will ask for
  • DevSecOps pipeline with security gates
  • Application security testing results
Where this commonly fails
  • No secure SDLC/DevSecOps
DODZT-3.3
Software Risk Management

Manage software supply-chain and component risk for applications.

Artefacts an auditor will ask for
  • Software bill of materials and component risk assessment
Where this commonly fails
  • Unmanaged software supply-chain risk
DODZT-3.4
Resource Authorization and Integration

Authorize access to application resources dynamically and integrate authorization across the enterprise.

Artefacts an auditor will ask for
  • Resource-level authorization integrated with policy decision points
Where this commonly fails
  • Coarse, static application authorization
DODZT-3.5
Continuous Monitoring and Ongoing Authorizations

Continuously monitor applications and move to ongoing authorization (cATO).

Artefacts an auditor will ask for
  • Continuous monitoring feeding ongoing authorization (cATO)
Where this commonly fails
  • Point-in-time ATO with no continuous monitoring

DoD ZT Pillar 4: Data

DODZT-4.1
Data Catalog Risk Alignment

Catalog data and align protection to data risk.

Artefacts an auditor will ask for
  • Data catalog with risk alignment
Where this commonly fails
  • Uncatalogued data with no risk alignment
DODZT-4.2
DoD Enterprise Data Governance

Establish enterprise data governance for zero trust.

Artefacts an auditor will ask for
  • Enterprise data governance structure and policies
Where this commonly fails
  • No enterprise data governance
DODZT-4.3
Data Labeling and Tagging

Label and tag data to enable attribute-based protection and access.

Artefacts an auditor will ask for
  • Data labeling/tagging applied to data assets
Where this commonly fails
  • Untagged data
DODZT-4.4
Data Monitoring and Sensing

Monitor and sense data access and movement.

Artefacts an auditor will ask for
  • Data access/movement monitoring
Where this commonly fails
  • No data monitoring/sensing
DODZT-4.5
Data Encryption and Rights Management

Encrypt data and apply digital rights management.

Artefacts an auditor will ask for
  • Encryption at rest/in transit
  • Digital rights management on sensitive data
Where this commonly fails
  • Unencrypted sensitive data
DODZT-4.6
Data Loss Prevention

Deploy data loss prevention controls.

Artefacts an auditor will ask for
  • DLP policy and enforcement
Where this commonly fails
  • No DLP controls
DODZT-4.7
Data Access Control

Enforce fine-grained, per-session, attribute-based access to data.

Artefacts an auditor will ask for
  • Attribute-based, per-session data access enforcement
Where this commonly fails
  • Coarse data access not per-session

DoD ZT Pillar 5: Network and Environment

DODZT-5.1
Data Flow Mapping

Map data flows across the network and environment.

Artefacts an auditor will ask for
  • Documented data-flow maps
Where this commonly fails
  • Unknown data flows
DODZT-5.2
Software Defined Networking

Use software-defined networking to enable dynamic, policy-driven network control.

Artefacts an auditor will ask for
  • SDN deployment enabling policy-driven control
Where this commonly fails
  • Static network with no SDN
DODZT-5.3
Macro Segmentation

Implement macro-segmentation of the network.

Artefacts an auditor will ask for
  • Macro-segmentation architecture
Where this commonly fails
  • Flat network with no segmentation
DODZT-5.4
Micro Segmentation

Implement micro-segmentation down to the workload/host level.

Artefacts an auditor will ask for
  • Micro-segmentation policies at workload/host level
Where this commonly fails
  • No micro-segmentation

DoD ZT Pillar 6: Automation and Orchestration

DODZT-6.1
Policy Decision Point and Policy Orchestration

Operate a policy decision point and orchestrate policy across the enterprise (the zero-trust policy engine).

Artefacts an auditor will ask for
  • Policy decision point / policy engine deployment
  • Policy orchestration across pillars
Where this commonly fails
  • No central policy decision point
DODZT-6.2
Critical Process Automation

Automate critical security processes.

Artefacts an auditor will ask for
  • Automation of critical security processes
Where this commonly fails
  • Manual critical processes
DODZT-6.3
Machine Learning

Apply machine learning to support zero-trust decisions.

Artefacts an auditor will ask for
  • ML models supporting ZT decisions
Where this commonly fails
  • No ML augmentation where beneficial
DODZT-6.4
Artificial Intelligence

Apply artificial intelligence to support zero-trust decisions and operations.

Artefacts an auditor will ask for
  • AI augmentation of ZT operations
Where this commonly fails
  • No AI augmentation where beneficial
DODZT-6.5
Security Orchestration, Automation and Response

Deploy SOAR to automate detection and response workflows.

Artefacts an auditor will ask for
  • SOAR playbooks and automated response
Where this commonly fails
  • Manual-only incident response
DODZT-6.6
API Standardization

Standardize APIs to enable interoperability and automation.

Artefacts an auditor will ask for
  • Standardized, documented APIs
Where this commonly fails
  • Ad-hoc non-standard APIs
DODZT-6.7
Security Operations Center and Incident Response

Operate a SOC and integrated incident response.

Artefacts an auditor will ask for
  • SOC operations and IR integration
Where this commonly fails
  • No SOC/IR integration

DoD ZT Pillar 7: Visibility and Analytics

DODZT-7.1
Log All Traffic

Log all network, data, application and user traffic.

Artefacts an auditor will ask for
  • Comprehensive logging across network/data/apps/users
Where this commonly fails
  • Incomplete logging coverage
DODZT-7.2
Security Information and Event Management

Aggregate and correlate logs in a SIEM.

Artefacts an auditor will ask for
  • SIEM with log aggregation and correlation
Where this commonly fails
  • No SIEM/centralized correlation
DODZT-7.3
Common Security and Risk Analytics

Perform common security and risk analytics across pillars.

Artefacts an auditor will ask for
  • Cross-pillar security/risk analytics
Where this commonly fails
  • Siloed analytics
DODZT-7.4
User and Entity Behavior Analytics

Apply UEBA to detect anomalous user and entity behavior.

Artefacts an auditor will ask for
  • UEBA detections and tuning
Where this commonly fails
  • No behavioral analytics
DODZT-7.5
Threat Intelligence Integration

Integrate threat intelligence into monitoring and decisions.

Artefacts an auditor will ask for
  • Threat-intel feeds integrated into detection/decisions
Where this commonly fails
  • Threat intel not operationalized
DODZT-7.6
Automated Dynamic Policies

Drive automated, dynamic policy updates from analytics and telemetry.

Artefacts an auditor will ask for
  • Automated dynamic policy updates from telemetry
Where this commonly fails
  • Static policies not informed by telemetry
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the DoD Zero Trust Reference Architecture framework page.