# The CISA Zero Trust Maturity Model, Explained > CISA's Zero Trust Maturity Model maps the journey to zero trust across five pillars and four maturity stages. What the pillars and stages are, and how to assess where you sit. Source: https://playciso.com/blog/zero-trust-maturity-model-cisa-explained · Published: 2026-09-26 · Publisher: PlayCISO (https://playciso.com) --- "How do we do zero trust?" is a strategy question, and CISA's Zero Trust Maturity Model (ZTMM) is one of the most useful maps for answering it. Rather than a product or a checklist, it describes zero trust across five pillars and four stages of maturity, so you can see where you are and plan where to go. ## The five pillars - Identity — authenticating and authorising users and services (the highest-leverage pillar). - Devices — the security posture of the endpoints accessing resources. - Networks — segmentation and control of network traffic. - Applications & Workloads — securing apps and the workloads they run on. - Data — classifying, protecting and governing data itself. Three cross-cutting capabilities support all five: **Visibility & Analytics, Automation & Orchestration, and Governance**. ## The four maturity stages - Traditional — manual, static, perimeter-based controls. - Initial — starting to automate and apply zero-trust principles in places. - Advanced — coordinated, largely automated controls with centralised visibility. - Optimal — fully automated, dynamic, policy-driven controls with continuous validation. Each pillar can sit at a different stage — most organisations are uneven, which is exactly what the model is meant to reveal. ## How to use it Assess each pillar's current stage, find the pillars that are both behind and high-risk, set a realistic target per pillar, and build an incremental roadmap. Identity is usually the place to start: strong, phishing-resistant identity underpins the other four pillars. Assess your posture with the free [Zero Trust Maturity tool →](/tools/zero-trust), and start on the Identity pillar with the [Identity Risk tool](/tools/identity-risk). ## Frequently asked questions **The five pillars?** Identity, Devices, Networks, Applications & Workloads, Data — plus cross-cutting Visibility, Automation and Governance. **The four stages?** Traditional, Initial, Advanced, Optimal. **Is it a compliance requirement?** Mostly a planning/self-assessment framework (federal agencies have zero-trust directives that reference it). **How to self-assess?** Rate each pillar, target realistically, prioritise — start with Identity.