Putting the CISA Zero Trust Maturity Model into Practice

Posted: Monday May 1, 2023
Author: Jason Garbis

In the past few weeks since version 2 of the CISA Zero Trust Maturity Model (ZTMM) was released, I’ve had numerous conversations about how organizations can and should use it. That’s a big topic, and one that I’ll be elaborating on more in the future, but I wanted to address an immediate need I’m seeing: an interactive, easily manipulated spreadsheet version of the ZTMM. 

I’m pleased to release a free, interactive spreadsheet version of the CISA Zero Trust Maturity Model here https://numberlinesecurity.com/ztmm/

On this site – a perhaps ambitiously named Zero Trust Maturity Model Resource Center – I provide an overview of the CISA ZTMM, and an explanation of the interactive spreadsheet. You’ll also find a link to Google Sheets and Microsoft Excel versions. 

This spreadsheet contains:

  • The full set of CISA functions and maturity levels, in editable text form
  • An interactive worksheet, where you can select your organization’s maturity level
  • A results worksheet, where your selections are automatically rendered

I welcome your comments and suggestions.