The CISA Zero Trust Maturity Model, Explained
CISA's Zero Trust Maturity Model (ZTMM) is a widely-used framework for planning a zero-trust journey. It organises zero trust into five pillars โ Identity, Devices, Networks, Applications & Workloads, and Data โ supported by cross-cutting capabilities (Visibility & Analytics, Automation & Orchestration, and Governance). For each pillar it defines four maturity stages: Traditional, Initial, Advanced, and Optimal. The model is a planning and self-assessment tool, not a compliance checklist: you assess where each pillar sits today, decide a target stage appropriate to your risk, and drive incremental progress. This explainer covers the pillars, the stages, and how to run a ZTMM self-assessment.
"How do we do zero trust?" is a strategy question, and CISA's Zero Trust Maturity Model (ZTMM) is one of the most useful maps for answering it. Rather than a product or a checklist, it describes zero trust across five pillars and four stages of maturity, so you can see where you are and plan where to go.
The five pillars
- Identity โ authenticating and authorising users and services (the highest-leverage pillar).
- Devices โ the security posture of the endpoints accessing resources.
- Networks โ segmentation and control of network traffic.
- Applications & Workloads โ securing apps and the workloads they run on.
- Data โ classifying, protecting and governing data itself.
Three cross-cutting capabilities support all five: Visibility & Analytics, Automation & Orchestration, and Governance.
The four maturity stages
- Traditional โ manual, static, perimeter-based controls.
- Initial โ starting to automate and apply zero-trust principles in places.
- Advanced โ coordinated, largely automated controls with centralised visibility.
- Optimal โ fully automated, dynamic, policy-driven controls with continuous validation.
Each pillar can sit at a different stage โ most organisations are uneven, which is exactly what the model is meant to reveal.
How to use it
Assess each pillar's current stage, find the pillars that are both behind and high-risk, set a realistic target per pillar, and build an incremental roadmap. Identity is usually the place to start: strong, phishing-resistant identity underpins the other four pillars.
Assess your posture with the free Zero Trust Maturity tool โ, and start on the Identity pillar with the Identity Risk tool.
Frequently asked questions
The five pillars? Identity, Devices, Networks, Applications & Workloads, Data โ plus cross-cutting Visibility, Automation and Governance.
The four stages? Traditional, Initial, Advanced, Optimal.
Is it a compliance requirement? Mostly a planning/self-assessment framework (federal agencies have zero-trust directives that reference it).
How to self-assess? Rate each pillar, target realistically, prioritise โ start with Identity.
Ready to practise the decisions these articles describe?
Run a free War Room โ