DoD Zero Trust Reference Architecture
Evidence request list. 45 controls, 45 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
DoD ZT Pillar 1: User
Maintain an authoritative inventory of all privileged and non-privileged users and non-person entities, connected to identity lifecycle (joiner/mover/leaver) management.
- Authoritative user/NPE inventory from enterprise identity sources
- Identity lifecycle management records
- No authoritative user inventory
- Identity not tied to lifecycle management
Enforce attribute-based, conditional user access to applications and data using vetted enterprise roles/attributes through ICAM governance.
- Attribute/role-based conditional access policies
- ICAM governance of attributes
- Static access not conditioned on attributes/context
Require phishing-resistant multi-factor authentication for users, integrated with the enterprise IdP and PKI.
- MFA enforcement records integrated with the enterprise IdP
- Phishing-resistant authenticator deployment
- Single-factor authentication
- MFA not phishing-resistant
Manage privileged access with Just-in-Time / Just-Enough-Administration through a PAM solution.
- PAM solution with JIT/JEA enforcement
- Privileged-session records
- Standing privileged access
- No PAM/JIT-JEA
Provide enterprise identity federation and standardized user credentialing across DoD components.
- Federated identity configuration
- Standard credentialing records
- Siloed, non-federated identity
Incorporate behavioral, contextual and biometric signals into authentication and access decisions.
- Behavioral/contextual/biometric signals feeding access decisions
- Access decisions ignore behavioral/contextual signals
Grant users the least privilege necessary, reviewed and enforced dynamically.
- Least-privilege role definitions and periodic review
- Dynamic privilege enforcement
- Over-provisioned access
- No least-privilege review
Continuously authenticate and authorize users throughout a session rather than only at logon.
- Continuous/periodic re-authentication configuration
- Session-risk re-evaluation records
- Authenticate-once-at-logon only
Operate an integrated Identity, Credential and Access Management platform as the enterprise authority for identity.
- Integrated ICAM platform serving enterprise identity
- Fragmented ICAM tooling
DoD ZT Pillar 2: Device
Maintain a complete inventory of all devices (managed and unmanaged) connecting to the network.
- Authoritative device inventory
- Discovery of unmanaged devices
- Incomplete device inventory
Detect devices and continuously assess their compliance posture before and during access.
- Device compliance posture checks
- Comply-to-connect enforcement
- No device-compliance gate
Authorize devices using real-time inspection of device health and posture.
- Real-time device health/posture inspection at access
- Authorization without real-time device inspection
Secure remote access for devices consistent with zero-trust principles.
- Zero-trust remote-access enforcement
- VPN-only flat remote access
Automate asset, vulnerability and patch management across devices.
- Automated asset/vuln/patch pipelines
- Patch SLAs and coverage reports
- Manual, incomplete patch/vuln management
Manage endpoints and mobile devices through UEM/MDM.
- UEM/MDM enrolment and policy enforcement
- Unmanaged endpoints/mobile devices
Deploy EDR and integrate into XDR for detection and response across the environment.
- EDR/XDR deployment and coverage
- Detection/response telemetry
- No EDR/XDR on endpoints
DoD ZT Pillar 3: Application and Workload
Maintain an inventory of applications and their components.
- Authoritative application inventory
- No application inventory
Apply secure software development and integration practices (DevSecOps) for applications.
- DevSecOps pipeline with security gates
- Application security testing results
- No secure SDLC/DevSecOps
Manage software supply-chain and component risk for applications.
- Software bill of materials and component risk assessment
- Unmanaged software supply-chain risk
Authorize access to application resources dynamically and integrate authorization across the enterprise.
- Resource-level authorization integrated with policy decision points
- Coarse, static application authorization
Continuously monitor applications and move to ongoing authorization (cATO).
- Continuous monitoring feeding ongoing authorization (cATO)
- Point-in-time ATO with no continuous monitoring
DoD ZT Pillar 4: Data
Catalog data and align protection to data risk.
- Data catalog with risk alignment
- Uncatalogued data with no risk alignment
Establish enterprise data governance for zero trust.
- Enterprise data governance structure and policies
- No enterprise data governance
Label and tag data to enable attribute-based protection and access.
- Data labeling/tagging applied to data assets
- Untagged data
Monitor and sense data access and movement.
- Data access/movement monitoring
- No data monitoring/sensing
Encrypt data and apply digital rights management.
- Encryption at rest/in transit
- Digital rights management on sensitive data
- Unencrypted sensitive data
Deploy data loss prevention controls.
- DLP policy and enforcement
- No DLP controls
Enforce fine-grained, per-session, attribute-based access to data.
- Attribute-based, per-session data access enforcement
- Coarse data access not per-session
DoD ZT Pillar 5: Network and Environment
Map data flows across the network and environment.
- Documented data-flow maps
- Unknown data flows
Use software-defined networking to enable dynamic, policy-driven network control.
- SDN deployment enabling policy-driven control
- Static network with no SDN
Implement macro-segmentation of the network.
- Macro-segmentation architecture
- Flat network with no segmentation
Implement micro-segmentation down to the workload/host level.
- Micro-segmentation policies at workload/host level
- No micro-segmentation
DoD ZT Pillar 6: Automation and Orchestration
Operate a policy decision point and orchestrate policy across the enterprise (the zero-trust policy engine).
- Policy decision point / policy engine deployment
- Policy orchestration across pillars
- No central policy decision point
Automate critical security processes.
- Automation of critical security processes
- Manual critical processes
Apply machine learning to support zero-trust decisions.
- ML models supporting ZT decisions
- No ML augmentation where beneficial
Apply artificial intelligence to support zero-trust decisions and operations.
- AI augmentation of ZT operations
- No AI augmentation where beneficial
Deploy SOAR to automate detection and response workflows.
- SOAR playbooks and automated response
- Manual-only incident response
Standardize APIs to enable interoperability and automation.
- Standardized, documented APIs
- Ad-hoc non-standard APIs
Operate a SOC and integrated incident response.
- SOC operations and IR integration
- No SOC/IR integration
DoD ZT Pillar 7: Visibility and Analytics
Log all network, data, application and user traffic.
- Comprehensive logging across network/data/apps/users
- Incomplete logging coverage
Aggregate and correlate logs in a SIEM.
- SIEM with log aggregation and correlation
- No SIEM/centralized correlation
Perform common security and risk analytics across pillars.
- Cross-pillar security/risk analytics
- Siloed analytics
Apply UEBA to detect anomalous user and entity behavior.
- UEBA detections and tuning
- No behavioral analytics
Integrate threat intelligence into monitoring and decisions.
- Threat-intel feeds integrated into detection/decisions
- Threat intel not operationalized
Drive automated, dynamic policy updates from analytics and telemetry.
- Automated dynamic policy updates from telemetry
- Static policies not informed by telemetry
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the DoD Zero Trust Reference Architecture framework page.