Zero Trust Architecture ·

Zero trust, from strategy to operations. One playbook for architecture, roadmap, technology and governance.

Aligned to NIST SP 800-207, SP 800-53 Rev 5 and the CISA Zero Trust Maturity Model. Change the stage or click any component below.

Zero trust architecture · NIST SP 800-207 reference model
Maturity Stage

Explore the playbook

Executive summary

What zero trust means for the business

A one-screen brief: why we are doing this, which way we could go, and the decisions leadership has to make.

Why now

    What changes for people

      Decisions needed

        Where we are

        Taken live from the self-assessment page.

        Top capability priorities

        From the prioritization scoring, using the current weights and maturity gaps.

          Executive brief

          Delivery options & business case

          Three common ways to source the platform. None is right for everyone; the tradeoffs are what matter.

          Business case template

          Fill one of these in for each funded initiative so investment and sequencing decisions can be compared like for like.

          Foundation

          People, architecture & protected estate

          The three layers everything else in this model builds on. Click a tab to jump to it.

          Assess

          Pillar questionnaire & gap analysis

          Nine questions per pillar, three at each stage. Your answers work out where each pillar stands today and what is missing to reach the next stage. Apply a result and it becomes that pillar's current state on the self-assessment, and stays in sync as you change answers.

          Answers are saved in this browser only. To combine answers from several people, copy the CSV from each and merge them in a spreadsheet.

          Assess

          Where are we, and where do we need to be?

          Set current and target maturity for each pillar. Stages follow the CISA Zero Trust Maturity Model v2.0, with MO1–MO3 shown alongside. The gap view and the priority list update as you go.

          Presets
          Fill in from the questionnaire →
          PillarCurrentTargetGap

          Plan

          Prioritization scoring

          Score each capability or initiative on risk, strategic, operational and financial value against cost and level of effort. Gap fit is worked out from the self-assessment, so items that close your next maturity gap rise to the top. Adjust the weights to match what leadership cares about.

          Weights

          Each attribute is scored 1–5. Benefits score higher when the rating is higher; cost and level of effort score higher when the rating is lower. Priority = Σ (weight × normalized rating) ÷ Σ weights, shown 0–100. Weights are relative, so they don't need to add up to anything.

          Value vs effort

          Top 10

            Default ratings are starting estimates for a typical enterprise, not measurements. Edited ratings are outlined and saved in this browser; replace the defaults with your own team's judgment before using the ranking for funding decisions.

            Maturity Model

            Three maturity objectives, seven domains

            Pick a stage to see what changes in each domain as the program matures.

            Domain
            Maturity model

            Crosswalk to the CISA Zero Trust Maturity Model v2.0

            This page uses 7 pillars and 3 stages. CISA uses 5 pillars, 3 cross-cutting capabilities and 4 stages. Use this table to read one in terms of the other.

            Roadmap

            Pillars & initiatives

            Seven pillars, each progressing through the same three phases. Pick a pillar to see all of its initiatives; the current stage is highlighted.

            Pillar
            Continuous across all phases
            Plan

            Timeline & schedule

            A first-cut schedule built from your self-assessment and the prioritization scores. Each pillar works through the stages it still needs, highest-priority initiatives first, with a limit on how many run at once. Durations come from each initiative's level of effort. Pin any initiative to a quarter and everything else schedules around it.

            Start Parallel per pillar
            MO1 · FoundationMO2 · AdvancedMO3 · Optimized Stage complete for the pillarDashed outline = pinned by you

            This is a planning model, not a committed plan: it assumes each pillar team can run the chosen number of initiatives in parallel and that a stage can start once half of the previous stage's initiatives are finished. The CSV imports into Microsoft Project, Planner, Smartsheet or Excel for detailed planning. Settings and pins are saved in this browser.

            Sequencing

            Dependencies & milestone gates

            The roadmap only works in the right order. Each gate has entry requirements, what it unlocks and the evidence that it is done. The current stage's gates are highlighted.

            Sequencing

            Critical dependency chains

            Starting a later step before an earlier one is finished is the most common reason zero trust programs stall.

            End-to-end

            How zero trust works, request by request

            Click a step to see what happens at that stage of every single access request.

            Continuous feedback loop: telemetry & logs → analytics → threat intelligence → policy tuning → automation — feeding straight back into Verify.
            Technology options

            Capabilities, Microsoft and alternatives

            Each capability, the Microsoft option and established alternatives. Use it to spot what you already own, where tools overlap and where a specialist product earns its place. Vendor lists are examples, not endorsements.

            Pillar
            G5 in Microsoft 365 G5 / E5 Add-on separate license Azure usage-based Azure service Gap no full native equivalent

            Licensing and product names change often. Confirm current Microsoft 365 G5/E5 inclusions and vendor capabilities before using this for a purchase decision.

            Technology options

            Overlap to watch

            Places where a mixed Microsoft and third-party estate most often pays twice or enforces policy in two places.

            Workstream playbooks

            CASB, BYOD, SASE & SOAR

            The four workstreams that most often need architectural direction. Each one covers the phases, the decisions to settle early and the teams it depends on.

            Governance

            Architecture review, ownership & exceptions

            How designs get approved, who owns what, and how to say "not yet" safely when a control can't be met.

            Architecture review

            Every design that changes an access path goes through the same five steps.

            Exception process

            Exceptions are time-limited risk decisions, not permanent waivers.

            Governance

            Ownership & decision records

            Who is responsible for what, and how decisions are captured so later teams know what was decided and why.

            RACI

            R = responsible · A = accountable · C = consulted · I = informed. Adjust roles to your organization.

            Decision record template

            Log every significant architecture decision so later teams know what was decided and why.

            Measure

            Metrics & traceability

            Measurable criteria for progress and maturity, with a target at each stage. The current stage's targets are highlighted.

            MetricDefinitionMO1 targetMO2 targetMO3 target
            Measure

            Traceability thread

            Every delivered capability should trace back to an objective and forward to a control and a metric. Pick an example.

            Standards alignment

            NIST SP 800-207 & SP 800-53 Rev 5

            SP 800-207 defines the zero trust architecture; SP 800-53 supplies the controls that prove it. Each pillar below lists the controls that phase implements. Move the stage rail to see what each stage adds.

            SP 800-53 Rev 5 controls by pillar & stage

            Controls are cumulative: MO2 inherits MO1, MO3 inherits both. Enhancements are shown in parentheses, e.g. AC-2(1).

            Pillar

            This is an indicative mapping and does not replace your system security plan (SSP). Confirm control selection and tailoring against your SP 800-53B baseline and your organization's policies.

            Reference

            SP 800-207 · The seven tenets of zero trust

            What every tag on this page means. Hover a tag such as Tenet 6 or IA-2 anywhere on the page for a quick definition, or click it to jump here.

            From NIST SP 800-207 Zero Trust Architecture (2020), section 2.1, with what each tenet means in practice.

            Reference

            SP 800-207 · Components & deployment approaches

            The building blocks behind the architecture diagram, and the three ways NIST describes building it.

            Logical components

            The building blocks from section 3 that appear in the architecture diagram.

            SP 800-207 · Deployment approaches

            Section 3.1 describes three ways to build a zero trust architecture. Most enterprises combine them.

            Reference

            SP 800-53 Rev 5 · Control index

            Every control cited on this page, grouped by family, with where it is used. Numbers in parentheses are control enhancements.

            Control titles follow NIST SP 800-53 Rev 5. See the NIST publications for full control text, discussion and related controls.

            Why it matters

            Business value & outcomes

            Six outcomes the architecture delivers, each tracked by a metric — and the foundations every one of them depends on.