Free Agentic AI Security Workshop Map your footprint, identify your highest-risk gaps, and leave with a customized security summary. Book a Workshop→
Start assessment

Zero Trust Maturity Model Resource Center

Purpose of this page

Security leaders often need practical guidance on applying the CISA Zero Trust Maturity Model within their own organizations. This site is created and maintained by Numberline Security to provide that guidance.

Zero Trust Maturity Models : Overview

Zero Trust is an ongoing journey, not a one-time implementation. Organizations need a reference point to identify their current state and their target state. A Zero Trust Maturity Model (ZTMM) provides this reference point. Completing a maturity self-assessment is a recommended first step for organizations beginning a Zero Trust journey, and is mandatory for US Federal Agencies.

The CISA Zero Trust Maturity Model

Multiple Zero Trust Maturity Models exist. The most widely referenced model is published by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Key facts about this model:

The CISA model is widely adopted across the cybersecurity industry and functions as a common baseline vocabulary and framework for Zero Trust. This page explains how to best use it, and introduces the free supporting tools provided by Numberline.

CISA Zero Trust 5 Pillars

The CISA Zero Trust Maturity Model introduces five pillars, three cross-cutting capabilities, and four maturity levels, shown in the image below.

CISA Zero Trust Maturity Model Five pillars (Identity, Devices, Networks, Applications and Workloads, and Data) each progress through four maturity stages: Traditional, Initial, Advanced, and Optimal. They rest on three cross-cutting capabilities: Visibility and Analytics, Automation and Orchestration, and Governance. Identity Devices Networks Applications& Workloads Data Optimal Advanced Initial Traditional Visibility and Analytics Automation and Orchestration Governance

CISA Zero Trust Maturity Model

CISA’s Zero Trust Maturity Model is built around five pillars, as shown above: Identity, Devices, Networks, Applications and Workloads, and Data. Each of these pillars progresses through four maturity stages: Traditional, Initial, Advanced, and Optimal. Layered across all five pillars are three cross-cutting capabilities, Visibility and Analytics, Automation and Orchestration, and Governance, which support and enable maturity within each pillar. Figure 4 below summarizes what each pillar looks like at every maturity stage, giving organizations a high-level view of the full model before drilling into the specifics of any one pillar or capability.

Identity

Devices

Networks

Applications and Workloads

Data

Optimal
Optimal, Identity:
  • Continuous validation and risk analysis
  • Enterprise-wide identity integration
  • Tailored, as-needed automated access
Optimal, Devices:
  • Continuous physical and virtual asset analysis including automated supply chain risk management and integrated threat protections
  • Resource access depends on real-time device risk analytics
Optimal, Networks:
  • Distributed micro-perimeters with just-in-time and just-enough access controls and proportionate resilience
  • Configurations evolve to meet application profile needs
  • Integrates best practices for cryptographic agility
Optimal, Applications and Workloads:
  • Applications available over public networks with continuously authorized access
  • Protections against sophisticated attacks in all workflows
  • Immutable workloads with security testing integrated throughout lifecycle
Optimal, Data:
  • Continuous data inventorying
  • Automated data categorization and labeling enterprise-wide
  • Optimized data availability
  • DLP exfil blocking
  • Dynamic access controls
  • Encrypts data in use
Advanced
Advanced, Identity:
  • Phishing-resistant MFA
  • Consolidation and secure integration of identity stores
  • Automated identity risk assessments
  • Need/session-based access
Advanced, Devices:
  • Most physical and virtual assets are tracked
  • Enforced compliance implemented with integrated threat protections
  • Initial resource access depends on device posture
Advanced, Networks:
  • Expanded isolation and resilience mechanisms
  • Configurations adapt based on automated risk-aware application profile assessments
  • Encrypts applicable network traffic and manages issuance and rotation of keys
Advanced, Applications and Workloads:
  • Most mission critical applications available over public networks to authorized users
  • Protections integrated in all application workflows with context-based access controls
  • Coordinated teams for development, security, and operations
Advanced, Data:
  • Consistent, tiered, targeted categorization and labeling
  • Redundant, highly available data stores
  • Static DLP
  • Automated context-based access
  • Encrypts data at rest
Initial
Initial, Identity:
  • MFA with passwords
  • Self-managed and hosted identity stores
  • Manual identity risk assessments
  • Access expires with automated review
Initial, Devices:
  • All physical assets tracked
  • Limited device-based access control and compliance enforcement
  • Some protections delivered via automation
Initial, Networks:
  • Initial isolation of critical workloads
  • Network capabilities manage availability demands for more applications
  • Dynamic configurations for some portions of the network
  • Encrypt more traffic and formalize key management policies
Initial, Applications and Workloads:
  • Some mission critical workflows have integrated protections and are accessible over public networks to authorized users
  • Formal code deployment mechanisms through CI/CD pipelines
  • Static and dynamic security testing prior to deployment
Initial, Data:
  • Limited automation to inventory data and control access
  • Begin to implement a strategy for data categorization
  • Some highly available data stores
  • Encrypts data in transit
  • Initial centralized key management policies
Traditional
Traditional, Identity:
  • Passwords or MFA
  • On-premises identity stores
  • Limited identity risk assessments
  • Permanent access with periodic review
Traditional, Devices:
  • Manually tracking device inventory
  • Limited compliance visibility
  • No device criteria for resource access
  • Manual deployment of threat protections to some devices
Traditional, Networks:
  • Large perimeter/macro-segmentation
  • Limited resilience and manually managed rulesets and configurations
  • Minimal traffic encryption with ad hoc key management
Traditional, Applications and Workloads:
  • Mission critical applications accessible via private networks
  • Protections have minimal workflow integration
  • Ad hoc development, testing, and production environments
Traditional, Data:
  • Manually inventory and categorize data
  • On-prem data stores
  • Static access controls
  • Minimal encryption of data at rest and in transit with ad hoc key management

High-Level Zero Trust Maturity Model Overview (Source: CISA Zero Trust Maturity Model v2.0)

Assessing Your Maturity

CISAs model is built on a detailed set of approximately 40 functions that they’ve defined across the five pillars, and for each of these they’ve provided a description of at each level of maturity.

Zero Trust Maturity Model

Five pillars, each with its own functions, all resting on three capabilities that span every pillar.

Identity

  • Authentication
  • Identity Stores
  • Risk Assessments
  • Access Management

Devices

  • Policy Enforcement & Compliance Monitoring
  • Asset & Supply Chain Risk Management
  • Resource Access
  • Device Threat Protection

Networks

  • Network Segmentation
  • Network Traffic Management
  • Traffic Encryption
  • Network Resilience

Applications & Workloads

  • Application Access
  • Application Threat Protections
  • Accessible Applications
  • Secure Application Development & Deployment Workflow
  • Application Security Testing

Data

  • Data Inventory Management
  • Data Categorization
  • Data Availability
  • Data Access
  • Data Encryption
Cross-cutting capabilities Apply to every pillar above
Visibility & AnalyticsSee activity across all pillars to detect risk and inform decisions
Automation & OrchestrationCoordinate and automate responses across pillars
GovernanceDefine, enforce, and audit policy across pillars

For example, the Network Segmentation function maturity levels are defined as follows:

Network Segmentation

Networks pillar maturity progression
  1. Traditional

    Agency defines their network architecture using large perimeter/macro-segmentation with minimal restrictions on reachability within network segments. Agency may also rely on multi-service interconnections (e.g., bulk traffic VPN tunnels).

  2. Initial

    Agency begins to deploy network architecture with the isolation of critical workloads, constraining connectivity to least function principles, and a transition toward service-specific interconnections.

  3. Advanced

    Agency expands deployment of endpoint and application profile isolation mechanisms to more of their network architecture with ingress/egress micro-perimeters and service-specific interconnections.

  4. Optimal

    Agency network architecture consists of fully distributed ingress/egress micro-perimeters and extensive micro-segmentation based around application profiles with dynamic just-in-time and just-enough connectivity for service-specific interconnections.

As such, this detailed view represents the best starting point by which organizations can perform a Zero Trust self-assessment, and is the model for which we’ve created an interactive spreadsheet, described below.

Start with CISA, go further with ZTMM+

The CISA model is a strong foundation and a great place to start your Zero Trust self-assessment. But it has gaps when applied outside the federal space, and is getting a bit dated. Numberline Security built ZTMM+, an enhanced and extended version of the CISA model, from our experience running maturity assessments in both the private and public sectors. Within ZTMM+, we

Learn more about ZTMM+ here.


Want to use the original CISA ZTMM? Learn about our free spreadsheet below to assess your organization against the CISA model today.

CISA Zero Trust Maturity Model Spreadsheet Tool

Numberline Security has developed a free, interactive spreadsheet version of the CISA Zero Trust Maturity Model. Instead of reading through static tables, you can assess your organization’s maturity interactively: select a level for each function and watch your results update automatically.

The Google Sheet is read-only; choose File → Make a copy to use it.
For Excel, download the Excel file using the link above. Exporting the Google Sheet as Excel will cause errors in the formatting and formulas.


The spreadsheet contains the following tabs:

Introduction

Start here. This worksheet covers:

  • An overview of the spreadsheet and how it maps to the CISA model
  • Step-by-step instructions for completing your self-assessment
  • Details of the formulas behind the automatic shading

Select a tab above to preview each worksheet.

CISA Zero Trust Maturity Model

All 40 functions and their maturity levels in a plain-text table, ready to copy, edit, and adapt for your organization.

CISA Zero Trust Maturity Model worksheet showing Identity functions across Traditional, Initial, Advanced, and Optimal levels

Click any image to view it full size.

Interactive

Self-assess your organization one function at a time. We’ve added Unknown to CISA’s four levels for areas where you don’t yet have enough information to decide.

1Pick a level in column F Dropdown in column F with options Unknown, Traditional, Initial, Advanced, and Optimal
2Columns G–J shade to match Interactive worksheet with maturity selections in column F and matching green shading in columns G through J

Click any image to view it full size.

Maturity Model Assessment

A compact summary of your results, formatted for easy viewing and sharing. It updates automatically from the Interactive worksheet, and functions marked Unknown stay unshaded.

Maturity Model Assessment worksheet showing shaded maturity blocks for Identity and Devices functions

Click any image to view it full size.

Is this applicable to Enterprises (Non-Federal Agencies)?

Yes. The CISA Zero Trust Maturity Model (ZTMM) was written for U.S. federal agencies, so it uses phrases like “Agencies should…” throughout. But CISA makes clear that it isn’t only for government. In its introduction, the model states: “While the ZTMM is specifically tailored for federal agencies… all organizations should review and consider adoption of the approaches outlined in this document.” (Emphasis ours.)

In practice, enterprises and other organizations can apply the model by reading “agency” as “enterprise” or “organization.”

Other Zero Trust Maturity Models

The CISA model has become the most widely used vendor-neutral Zero Trust maturity model, but it isn’t the only one worth knowing.

U.S. Department of War

The DoW has published its own Zero Trust guidance for defense organizations:

Vendor models

Several security vendors have published their own Zero Trust maturity models. They can be useful references, but none has achieved widespread industry adoption.

Numberline ZTMM+

Our enhanced version of the CISA model, built for enterprises. ZTMM+ defines all 40 functions, refines maturity levels for enterprise environments, adds new functions, and includes a structured assessment methodology.

Explore ZTMM+

Questions?

We’d love to hear how you’re using the spreadsheet and what would make it better.

info@NumberlineSecurity.com