The Architecture
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) organizes Zero Trust adoption into five pillars, tied together by three capabilities that cut across all of them. Federal agencies were required to build a transition plan around this model following Executive Order 14028 and OMB memo M-22-09.
What Gets Verified
Each pillar covers a category of "thing" that has to prove itself before it's trusted with access — none of them ranked above another; a mature Zero Trust program advances all five together.
Identity
Confirming who or what is asking — continuously, and with strong signals like phishing-resistant multi-factor authentication rather than a password alone.
Devices
Knowing the health and integrity of every device connecting in, from an employee's laptop to an unattended server, before it's trusted with a session.
Networks
Segmenting traffic into small, encrypted zones instead of trusting something simply because it's "inside" — see Article IV, Microsegmentation.
Applications & Workloads
Securing the software itself, including the pipelines that build and deploy it, with access checked at the application layer, not the network edge.
Data
Classifying, tagging, and encrypting information so its protection travels with the data itself, wherever it ends up.
What Ties the Pillars Together
Three capabilities run underneath all five pillars rather than belonging to any one of them.
Visibility & Analytics
The telemetry and context that every access decision is actually based on — without it, "continuous verification" has nothing to verify against.
Automation & Orchestration
Turning policy into something enforced by systems in real time, rather than a document reviewed once a quarter.
Governance
The policies, roles, and risk decisions that define what "least privilege" and "verified" actually mean for a given organization.
Four Stages, One Direction
CISA's Zero Trust Maturity Model scores each pillar along the same four stages. Most organizations don't sit at one stage across the board — a pillar can be Advanced while another is still Initial.
Traditional
Manual processes, static policies, and perimeter tools like firewalls and VPNs doing most of the work.
Initial
Early automation and risk-based decisions begin, with identity and access policy expanding past a simple password check.
Advanced
Centralized visibility and dynamic policy enforcement across most pillars, with coordination starting to happen between them.
Optimal
Fully automated, continuously verified access, with least privilege enforced in real time across every pillar at once.
Look Up a Term
Part Three collects the vocabulary from this briefing in one glossary, plus a short FAQ.
Open Resources