What is the CISA Zero Trust Maturity Model 2.0?
The CISA Zero Trust Maturity Model Version 2.0 is a roadmap for federal agencies to assess and advance Zero Trust capabilities. CISA Zero Trust maturity describes staged organizational progress; unlike NIST SP 800-207, which defines a logical Zero Trust Architecture, this model focuses on capability maturity and implementation outcomes.
It organizes improvement across five pillars: Identity; Devices; Networks; Applications and Workloads; and Data. Visibility and Analytics, Automation and Orchestration, and Governance operate as cross-cutting capabilities. Each capability progresses through Traditional, Initial, Advanced, and Optimal stages, allowing gaps and dependencies to be described consistently.
What is the CISA Zero Trust Maturity Model 2.0 used for?
Agencies can use the model to assess current state, define a target state, sequence investments, and communicate capability gaps across technical and governance stakeholders. It supports roadmap discussions by showing that progress in one pillar depends on telemetry, automation, policy, and operating practices shared with other pillars.
The model was designed for US federal agencies, although non-federal organizations can use its structure as a reference. For leaders, it connects CISA guidance with Zero Trust, Identity and Access Management, Zero Trust Network Access, and measurable governance. It does not prescribe a single architecture or guarantee security at any maturity stage.