Zero Trust Maturity Model: CISA's Stages Explained
- #Zero Trust
- #CISA
- #Zero Trust Maturity Model
- #Cloud Security
- #ZTNA
Related reading: CCSP and Zero Trust Cloud Security: What the Exam Tests in 2026.
Zero trust is easy to state as a principle — never trust, always verify — and hard to operationalize. CISA’s Zero Trust Maturity Model exists to close that gap: it gives organizations a common vocabulary and a staged path for moving from perimeter-based security toward a fully zero-trust architecture, instead of treating “zero trust” as a single yes/no destination.
This guide walks through what the model measures, its five pillars, its four maturity stages, and how to use it to benchmark where your own architecture actually stands.
What the Maturity Model Measures
CISA published the Zero Trust Maturity Model as part of its response to Executive Order 14028 (Improving the Nation’s Cybersecurity), which directed U.S. federal civilian executive branch agencies to develop plans for adopting zero trust architecture. Version 2.0, released in April 2023, is the current version and the one referenced throughout this guide.
The model is not a checklist of products to buy. It measures maturity across independent pillars, on the premise that no organization moves from legacy perimeter security to full zero trust in one step, and that different parts of an environment will mature at different rates. A company might have strong identity controls (SSO, MFA, conditional access) while its network segmentation and data classification are still catching up — that unevenness is expected, not a failure state.
Two structural ideas make the model useful as a self-assessment tool rather than just a diagram:
- Pillars are scored independently. You don’t get a single organization-wide “zero trust score.” You assess each pillar on its own maturity curve.
- Cross-cutting capabilities tie the pillars together. Three capabilities — visibility and analytics, automation and orchestration, and governance — sit underneath all five pillars and determine how well they interoperate, rather than being scored as a sixth silo.
Source: CISA, Zero Trust Maturity Model (Version 2.0, April 2023 — PDF).
The Five Pillars
CISA’s model organizes zero trust into five pillars:
- Identity — how users and non-person entities (service accounts, workloads) are verified before they’re granted access. Maturity here moves from static, password-based authentication toward continuous, risk-based identity verification.
- Devices — visibility into and control over every device that connects to enterprise resources, including compliance state and real-time posture checks, not just a point-in-time inventory.
- Networks — the shift from broad, perimeter-defined network zones to identity- and context-aware segmentation, including encrypted traffic and micro-segmentation down to the workload level.
- Applications and Workloads — securing access to applications based on identity and context rather than network location, and extending that same scrutiny to the workloads and APIs behind them.
- Data — the pillar most organizations lag on. It covers data inventory, classification, and access controls that follow the data itself rather than relying on the network perimeter to keep it contained.
Supporting all five are the three cross-cutting capabilities mentioned above: visibility and analytics (continuous monitoring and telemetry across pillars), automation and orchestration (policy enforcement without manual intervention), and governance (the policies, procedures, and risk management that keep the other capabilities aligned with organizational risk tolerance).
The Four Maturity Stages (Traditional to Optimal)
Within each pillar, CISA defines four maturity stages. Version 2.0 added the “Initial” stage that wasn’t present in the original 2021 draft, giving organizations a more realistic, incremental gradient instead of a large jump from legacy to advanced practices.
- Traditional — manually configured lifecycles and static policies; security relies on the network perimeter; minimal cross-pillar integration.
- Initial — early automation of attribute assignment and policy configuration begins; some cross-pillar solutions are integrated with external systems; least-privilege starts to be applied case by case.
- Advanced — centralized visibility and identity control; policy enforcement is automated across most pillars; least-privilege access decisions incorporate device and application posture in addition to identity.
- Optimal — fully automated, just-in-time lifecycles and policy enforcement based on continuous, real-time risk analysis; dynamic least-privilege access adjusts automatically as risk signals change; cross-pillar interoperability is complete.
The progression is intentionally gradual. CISA describes it as a multi-year journey rather than a project with a fixed end date — most agencies and enterprises alike will operate with a mix of stages across pillars for years.
How to Self-Assess Your Current Stage
A practical self-assessment doesn’t try to produce one number. It scores each pillar against CISA’s stage descriptions independently, then looks at the pattern across pillars.
A workable approach:
- Score each pillar separately (Traditional / Initial / Advanced / Optimal) using CISA’s published stage descriptions for that pillar specifically — the criteria differ meaningfully pillar to pillar, so don’t reuse one rubric across all five.
- Score the three cross-cutting capabilities separately from the pillars. A pillar can look mature on paper while weak visibility or manual policy enforcement quietly caps how far it can actually go.
- Identify your lowest-scoring pillar first. Because the pillars are interdependent through the cross-cutting capabilities, the weakest pillar often constrains what the others can achieve — a mature Identity pillar delivers less risk reduction if the Data pillar has no classification to act on.
- Re-run the assessment on a fixed cadence (annually is common for federal agencies under CISA’s guidance) rather than treating it as a one-time exercise, since maturity in each pillar shifts as tooling and processes change.
A Practical Roadmap Between Stages
Moving a pillar from one stage to the next is rarely a single project — it’s a sequence of smaller changes that compound. A few patterns that generalize across pillars:
- Traditional → Initial is mostly about replacing static, manually maintained configuration with the first layer of automation and cross-system integration — for example, moving from local device inventories to a device management platform that other pillars can query.
- Initial → Advanced is where centralization pays off: consolidating identity providers, unifying policy enforcement points, and making device/application posture a routine input to access decisions rather than an occasional check.
- Advanced → Optimal is the hardest and slowest jump for most organizations, because it depends on real-time telemetry and automated response maturing together — you can’t automate just-in-time access decisions on data you aren’t yet collecting continuously.
Because pillars mature independently, a roadmap should prioritize the pillar with the highest risk exposure relative to its current stage, not the pillar that’s easiest to advance. A Traditional-stage Data pillar sitting behind an Optimal-stage Identity pillar is often a bigger residual risk than an Initial-stage Network pillar, because unclassified, unmonitored data is exposed to anyone who successfully authenticates.
This guide covers CISA’s Zero Trust Maturity Model v2.0 (April 2023), the current published version as of this writing. For how zero trust concepts map onto the CCSP exam specifically, see CCSP and Zero Trust Cloud Security.
FAQ
What are the five pillars of CISA's Zero Trust Maturity Model?
Identity, Devices, Networks, Applications and Workloads, and Data. Three cross-cutting capabilities — visibility and analytics, automation and orchestration, and governance — support interoperability across all five.
What are the four maturity stages in CISA's model?
Traditional, Initial, Advanced, and Optimal. Version 2.0 (April 2023) added the Initial stage between Traditional and Advanced, giving organizations a more granular gradient for tracking incremental progress in each pillar.
Is the CISA Zero Trust Maturity Model mandatory for private companies?
No. It was written for U.S. federal civilian executive branch agencies implementing Executive Order 14028, but private-sector organizations widely use it as a free, vendor-neutral framework for structuring their own zero trust roadmap and self-assessment.
Do all five pillars have to reach the same maturity stage at the same time?
No. CISA explicitly designed the model so pillars can mature independently and at different speeds. An organization might be Advanced in Identity while still Traditional in Data, and that unevenness is expected rather than a sign of failure.
About the authors
Sekiko Jo
"Sekiko Jo" is the pen name used by Team Creative Lab’s security editorial desk. Articles are written and reviewed by an editor-in-chief who holds CISSP, CCSP and the Registered Information Security Specialist (情報処理安全確保支援士) credential, with a focus on cloud threat modeling and security governance.
Registered Information Security Specialist (情報処理安全確保支援士), Japan