Zero trust, from strategy to operations. One playbook for architecture, roadmap, technology and governance.
Aligned to NIST SP 800-207, SP 800-53 Rev 5 and the CISA Zero Trust Maturity Model. Change the stage or click any component below.
Explore the playbook
What zero trust means for the business
A one-screen brief: why we are doing this, which way we could go, and the decisions leadership has to make.
Why now
What changes for people
Decisions needed
Where we are
Taken live from the self-assessment page.
Delivery options & business case
Three common ways to source the platform. None is right for everyone; the tradeoffs are what matter.
Business case template
Fill one of these in for each funded initiative so investment and sequencing decisions can be compared like for like.
People, architecture & protected estate
The three layers everything else in this model builds on. Click a tab to jump to it.
Where are we, and where do we need to be?
Set current and target maturity for each pillar. Stages follow the CISA Zero Trust Maturity Model v2.0, with MO1–MO3 shown alongside. The gap view and the priority list update as you go.
Three maturity objectives, seven domains
Pick a stage to see what changes in each domain as the program matures.
| Domain |
|---|
Crosswalk to the CISA Zero Trust Maturity Model v2.0
This page uses 7 pillars and 3 stages. CISA uses 5 pillars, 3 cross-cutting capabilities and 4 stages. Use this table to read one in terms of the other.
Pillars & initiatives
Seven pillars, each progressing through the same three phases. Pick a pillar to see all of its initiatives; the current stage is highlighted.
Dependencies & milestone gates
The roadmap only works in the right order. Each gate has entry requirements, what it unlocks and the evidence that it is done. The current stage's gates are highlighted.
Critical dependency chains
Starting a later step before an earlier one is finished is the most common reason zero trust programs stall.
How zero trust works, request by request
Click a step to see what happens at that stage of every single access request.
Capabilities, Microsoft and alternatives
Each capability, the Microsoft option and established alternatives. Use it to spot what you already own, where tools overlap and where a specialist product earns its place. Vendor lists are examples, not endorsements.
Licensing and product names change often. Confirm current Microsoft 365 G5/E5 inclusions and vendor capabilities before using this for a purchase decision.
Overlap to watch
Places where a mixed Microsoft and third-party estate most often pays twice or enforces policy in two places.
CASB, BYOD, SASE & SOAR
The four workstreams that most often need architectural direction. Each one covers the phases, the decisions to settle early and the teams it depends on.
Architecture review, ownership & exceptions
How designs get approved, who owns what, and how to say "not yet" safely when a control can't be met.
Architecture review
Every design that changes an access path goes through the same five steps.
Exception process
Exceptions are time-limited risk decisions, not permanent waivers.
Ownership & decision records
Who is responsible for what, and how decisions are captured so later teams know what was decided and why.
RACI
R = responsible · A = accountable · C = consulted · I = informed. Adjust roles to your organization.
Decision record template
Log every significant architecture decision so later teams know what was decided and why.
Metrics & traceability
Measurable criteria for progress and maturity, with a target at each stage. The current stage's targets are highlighted.
| Metric | Definition | MO1 target | MO2 target | MO3 target |
|---|
Traceability thread
Every delivered capability should trace back to an objective and forward to a control and a metric. Pick an example.
NIST SP 800-207 & SP 800-53 Rev 5
SP 800-207 defines the zero trust architecture; SP 800-53 supplies the controls that prove it. Each pillar below lists the controls that phase implements. Move the stage rail to see what each stage adds.
SP 800-53 Rev 5 controls by pillar & stage
Controls are cumulative: MO2 inherits MO1, MO3 inherits both. Enhancements are shown in parentheses, e.g. AC-2(1).
This is an indicative mapping and does not replace your system security plan (SSP). Confirm control selection and tailoring against your SP 800-53B baseline and your organization's policies.
SP 800-207 · The seven tenets of zero trust
What every tag on this page means. Hover a tag such as Tenet 6 or IA-2 anywhere on the page for a quick definition, or click it to jump here.
From NIST SP 800-207 Zero Trust Architecture (2020), section 2.1, with what each tenet means in practice.
SP 800-207 · Components & deployment approaches
The building blocks behind the architecture diagram, and the three ways NIST describes building it.
Logical components
The building blocks from section 3 that appear in the architecture diagram.
SP 800-207 · Deployment approaches
Section 3.1 describes three ways to build a zero trust architecture. Most enterprises combine them.
SP 800-53 Rev 5 · Control index
Every control cited on this page, grouped by family, with where it is used. Numbers in parentheses are control enhancements.
Control titles follow NIST SP 800-53 Rev 5. See the NIST publications for full control text, discussion and related controls.
Business value & outcomes
Six outcomes the architecture delivers, each tracked by a metric — and the foundations every one of them depends on.