United States

CISA Zero Trust Maturity Model

46 controls. 1 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

46 controls 1 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

CISA Zero Trust Maturity Model Evidence & Implementation Kit

46 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

If you runShared controls
NIST SP 800-53 Rev 524measure it →

Every control

CodeControlAlso in
ZTMM-APP-1Application Access0
ZTMM-APP-2Application Threat Protection0
ZTMM-APP-3Secure Application Development and Deployment0
ZTMM-APP-4Application Visibility and Analytics0
ZTMM-APP-AOApplications Pillar: Automation and Orchestration1
ZTMM-APP-GOVApplications Pillar: Governance1
ZTMM-APP-TESTApplications Pillar: Application Security Testing1
ZTMM-APP-VAApplications Pillar: Visibility and Analytics1
ZTMM-CROSS-1Visibility and Analytics0
ZTMM-CROSS-2Automation and Orchestration0
ZTMM-CROSS-3Governance for Zero Trust0
ZTMM-DAT-1Data Inventory and Classification0
ZTMM-DAT-2Data Access Control0
ZTMM-DAT-3Data Encryption0
ZTMM-DAT-4Data Loss Prevention0
ZTMM-DAT-AOData Pillar: Automation and Orchestration1
ZTMM-DAT-AVAILData Pillar: Data Availability1
ZTMM-DAT-CATData Pillar: Data Categorization1
ZTMM-DAT-GOVData Pillar: Governance1
ZTMM-DAT-VAData Pillar: Visibility and Analytics1
ZTMM-DEV-1Device Inventory0
ZTMM-DEV-2Device Compliance and Posture0
ZTMM-DEV-3Device Threat Protection0
ZTMM-DEV-AODevices Pillar: Automation and Orchestration1
ZTMM-DEV-GOVDevices Pillar: Governance1
ZTMM-DEV-SCRMDevices Pillar: Asset and Supply Chain Risk Management1
ZTMM-DEV-VADevices Pillar: Visibility and Analytics1
ZTMM-ID-1Identity Authentication0
ZTMM-ID-2Identity Stores0
ZTMM-ID-3Risk Assessments for Identity0
ZTMM-ID-4Access Management0
ZTMM-ID-AOIdentity Pillar: Automation and Orchestration1
ZTMM-ID-GOVIdentity Pillar: Governance1
ZTMM-ID-VAIdentity Pillar: Visibility and Analytics1
ZTMM-MAT-1Maturity Stage Self-Assessment0
ZTMM-NET-1Network Segmentation0
ZTMM-NET-2Network Traffic Management0
ZTMM-NET-3Resilience and Availability0
ZTMM-NET-AONetworks Pillar: Automation and Orchestration1
ZTMM-NET-ENCNetworks Pillar: Traffic Encryption1
ZTMM-NET-GOVNetworks Pillar: Governance1
ZTMM-NET-VANetworks Pillar: Visibility and Analytics1
ZTMM-STAGE-ADVMaturity Stage: Advanced1
ZTMM-STAGE-INITMaturity Stage: Initial1
ZTMM-STAGE-OPTMaturity Stage: Optimal1
ZTMM-STAGE-TRADMaturity Stage: Traditional1

Tell me when CISA Zero Trust Maturity Model files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Segmentation diagram
  • DMARC reject record
  • Encrypted DNS policy
  • Firewall rule review
  • Network segmentation diagram
  • Network segmentation (VPC/subnets/security groups)
  • Access control matrices
  • KMS configuration
  • Encryption coverage report
  • Key rotation records

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for CISA Zero Trust Maturity Model, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition