NIST SP 800-207
The reference definition of Zero Trust Architecture — tenets, logical components
(policy engine, policy administrator, policy enforcement point), deployment variations, and
the trust algorithm. This is the vocabulary the rest of the models assume.
CISA Zero Trust Maturity Model v2
Five pillars — Identity, Devices, Networks, Applications & Workloads, Data —
plus visibility and analytics, automation and orchestration, and governance across all of
them. Its four stages give a per-capability current and target state instead of one
subjective score.
OMB M-22-09
The federal Zero Trust strategy memorandum and its specific expectations — enterprise
identity with phishing-resistant MFA, a device inventory, encrypted traffic, application
testing and internal accessibility, and data categorization. Where federal customers get
their questions.
DoD Zero Trust Strategy
Seven pillars and the target-level capability activities defense programs are being measured
against. Relevant to primes and subcontractors whose programme plans now have to state a
Zero Trust position.
Commercial framework mapping
The same design decisions are mapped to SOC 2 logical-access criteria, ISO/IEC 27001
Annex A access and network controls, and CIS Controls v8 — so one architecture
answers the auditor and the enterprise security questionnaire rather than needing a second
story.
NIST SP 800-171 and CMMC
Neither requires Zero Trust. But the access-control, identification-and-authentication and
audit families ask for exactly what a Zero Trust design produces, so the two are sequenced
together rather than as competing programmes.
See CMMC & NIST 800-171 readiness →