Zero trust is not a product. NIST SP 800-207 (August 2020) describes it as a set of principles in which no user, device or network location is trusted by default, and every access request is evaluated based on identity, device state and context. CISA's Zero Trust Maturity Model, Version 2.0 (April 2023), organizes the work into five pillars — Identity, Devices, Networks, Applications & Workloads, and Data — plus three cross-cutting capabilities: Visibility & Analytics, Automation & Orchestration, and Governance. Use this checklist to see where you are and pick the next realistic step.
Cendien Marketing
Practice Research Team
Download this resource free — no credit card required. Delivered instantly to your inbox.
Based on NIST SP 800-207 and the CISA Zero Trust Maturity Model 2.0
Zero trust is not a product. NIST SP 800-207 (August 2020) describes it as a set of principles in which no user, device or network location is trusted by default, and every access request is evaluated based on identity, device state and context. CISA's Zero Trust Maturity Model, Version 2.0 (April 2023), organizes the work into five pillars — Identity, Devices, Networks, Applications & Workloads, and Data — plus three cross-cutting capabilities: Visibility & Analytics, Automation & Orchestration, and Governance. It describes four maturity stages: Traditional, Initial, Advanced and Optimal. Use this checklist to see where you are and pick the next realistic step; most organizations progress pillar by pillar over several budget cycles. Check cisa.gov for the latest version of the maturity model before formal planning.
This page shows a summary. The complete checklist is in the branded PDF — download it above, it is free.
Cendien helps public-sector and mid-market organizations assess their current state, build a phased roadmap, and operate identity, endpoint and monitoring controls as part of managed IT services. Contact us at (214) 245-4580 or cendien.com/contact.
Topics Covered
Download the complete resource — free, no credit card required.
Get personalized guidance for your organization's specific situation from a Cendien practice expert.
Schedule a Free CallHIPAA Security Rule Compliance Checklist 2025 — Updated for Proposed Rule Changes
2025 Cybersecurity Threat Landscape: Enterprise Risk Infographic
Incident Response Playbook & Checklist
New resources delivered to your inbox monthly.