Zero trust is the most marketed term in enterprise security today. Every major security vendor has a zero trust product. Every analyst firm has a zero trust framework. Every conference has a zero trust track. And yet, surveys of enterprise security leaders consistently show that the vast majority of organizations that claim to be implementing zero trust are either in the earliest stages of a multi-year journey or applying the label to a much narrower set of controls than the term actually implies.

The gap between zero trust as it is marketed and zero trust as it is implemented is not a technology gap. It is a governance gap. Organizations that succeed with zero trust architecture treat it as a security governance model that requires executive commitment, organizational change, and sustained investment. Organizations that fail treat it as a product purchase.

What zero trust actually means

Zero trust as an architectural principle was formalized by NIST in Special Publication 800-207, and the core principle is stated with deceptive simplicity: no user, device, or network connection should be implicitly trusted. Every access request — regardless of whether it originates inside or outside the traditional network perimeter — should be authenticated, authorized, and continuously validated before access is granted.

This represents a fundamental departure from the perimeter security model that most enterprise networks were built on. The perimeter model assumes that anything inside the network can be trusted and anything outside cannot. Zero trust assumes that the network perimeter is meaningless — which, in a world of remote work, cloud infrastructure, SaaS applications, and mobile endpoints, it effectively is.

NIST SP 800-207 grounds the model in seven tenets, and they are worth stating plainly because they are the NIST-side counterpart to CISA's pillars: all data sources and computing services are treated as resources; all communication is secured regardless of network location; access is granted per-session; access is governed by dynamic policy that weighs identity, device state, and other observable attributes; the enterprise continuously monitors and measures the integrity and security posture of its assets; all resource authentication and authorization are dynamic and strictly enforced before access is allowed; and the enterprise collects telemetry on assets, traffic, and access to continuously improve its security posture. Every CISA pillar and cross-cutting capability is, in effect, one of these tenets made operational.

Zero trust is not about distrust — it is about eliminating implicit trust. The difference matters: you are not treating your employees as threats. You are building a security architecture that does not assume they are immune to being compromised.

The practical implication is that zero trust requires a fundamentally different approach to identity, network segmentation, device security, application access, and data governance — simultaneously, at enterprise scale. This is why it is a multi-year journey, not a product deployment.

The five pillars and three cross-cutting capabilities

The CISA Zero Trust Maturity Model v2.0 organizes zero trust around five pillars — Identity, Devices, Networks, Applications and Workloads, and Data — supported by three cross-cutting capabilities that integrate advancements across all five: Visibility and Analytics, Automation and Orchestration, and Governance. The distinction is architectural, not cosmetic: the pillars are the technology domains you build, while the cross-cutting capabilities are the disciplines that make those domains coherent and enforceable as a single architecture rather than five disconnected projects. NIST SP 800-207 defines the logical components of a zero trust architecture — the Policy Decision Point (itself split into a Policy Engine and a Policy Administrator), the Policy Enforcement Point, and the principles that govern them — while CISA's model extends those principles into the pillar-and-capability structure executives use to plan, fund, and govern implementation. Understanding all five pillars and all three cross-cutting capabilities is essential for any executive making investment decisions in this space:

  • Identity Every user and service must have a verified, managed identity. Multi-factor authentication is the entry point, but mature identity security extends to continuous authentication, behavioral analytics, and privileged access management for administrative accounts. Identity is the foundation that everything else builds on.
  • Devices Every device accessing organizational resources must be known, managed, and assessed for security posture before access is granted. Device health — patch level, configuration compliance, detection of compromise indicators — becomes an input to access decisions, not just a compliance checkbox.
  • Networks Network segmentation is replaced by micro-segmentation and software-defined perimeters. Access to network resources is granted based on identity and context, not network location. The corporate VPN as a broad access mechanism gives way to application-specific access with continuous verification.
  • Applications and workloads Applications enforce their own access controls rather than relying on network perimeter protection. API security, service-to-service authentication, and application-layer inspection become standard architecture patterns rather than exceptional controls.
  • Data Data is classified, tagged, and protected based on its sensitivity — not just based on where it is stored. Data access is controlled and audited at the data layer, not just at the network or application layer. This is particularly important for cloud-stored data that moves across network boundaries.
  • Visibility and analytics — Cross-cutting capability Zero trust depends on continuous monitoring across all five pillars simultaneously. Logging, telemetry, behavioral analytics, and SIEM/SOAR integration provide the real-time visibility required to detect anomalies, trigger automated responses, and generate the audit trail that satisfies both internal governance and external regulatory requirements. You cannot enforce what you cannot see — in a zero trust architecture, visibility is the cross-cutting capability that makes every pillar verifiable.
  • Automation and orchestration — Cross-cutting capability Manual policy enforcement does not scale in a zero trust architecture. Automated policy engines, orchestration platforms, and SOAR integration allow access decisions to be made and enforced at machine speed — without human variability in the enforcement chain. SOAR platforms orchestrate the response to policy violations, isolating devices and revoking credentials before a human analyst has opened the alert. Automation is the cross-cutting capability that separates a zero trust architecture from a zero trust aspiration.
  • Governance — Cross-cutting capability The enterprise-wide definition and enforcement of cybersecurity policies, procedures, and processes — within and across every pillar — to manage risk. Governance is CISA's third cross-cutting capability, and it is the one executives most often overlook and most directly own. It is what turns five technology domains and two operational disciplines into an accountable program: who sets policy, who enforces it, how exceptions are adjudicated, and how the whole architecture is measured against risk. In practice, governance is the difference between a zero trust architecture that is documented and one that is actually governed.

Why most zero trust initiatives stall

Zero trust initiatives fail for predictable reasons, and almost none of them are technical. The technology to implement zero trust is mature and widely available. The challenges are organizational:

Lack of executive sponsorship with staying power. Zero trust implementation takes three to five years for a large enterprise. Initiatives that start with strong executive sponsorship frequently lose that sponsorship when the sponsor changes roles, when the organization shifts strategic priorities, or when early implementation friction generates organizational resistance. Without sustained executive commitment, zero trust implementations stall after the first pillar and never become the coherent architecture they were intended to be.

Identity programs that stop at MFA. Multi-factor authentication is the most commonly cited zero trust "implementation" — and it is genuinely important. But MFA alone is not zero trust. Organizations that check the MFA box and declare zero trust progress have addressed one control in one of the five pillars — with four more pillars and three cross-cutting capabilities untouched. The remaining work is an order of magnitude larger.

Network segmentation that is never completed. Micro-segmentation projects are technically complex, operationally disruptive, and frequently encounter resistance from application teams who fear that tighter network controls will break their applications. Projects start, encounter friction, and stop. The result is partial segmentation that provides false comfort — the architecture looks more secure on paper than it is in practice.

Shadow IT and legacy systems that cannot be governed. Zero trust requires that every identity, device, and application be known and managed. In most enterprises, significant portions of the environment are neither. Legacy applications that cannot support modern authentication protocols. Operational technology that was never designed to be network-managed. SaaS applications procured outside IT governance. Each exception is a gap in the architecture.

The executive governance model for zero trust

CISOs who successfully implement zero trust architecture treat it as a program with an executive governance structure — not a project with a delivery date. This is not a soft-skills addendum to the technical work; it is CISA's formal Governance capability operationalized. In practice, executive governance means:

  • A zero trust program charter approved by the executive team that defines scope, investment commitment, organizational accountability, and success metrics. Without a charter, zero trust is a technology initiative. With a charter, it is a business risk management program.
  • Maturity measurement against a published framework. The CISA Zero Trust Maturity Model v2.0 provides a four-stage maturity scale — Traditional, Initial, Advanced, and Optimal — applied across each of the five pillars and three cross-cutting capabilities. Organizations that measure their current maturity and set explicit maturity targets have a governance artifact that enables executive oversight, budget justification, and progress accountability. The scale is concrete, not abstract: for the Identity pillar, Traditional is password-only authentication; Initial adds multi-factor authentication; Advanced introduces continuous, risk-based authentication that weighs context on every request; and Optimal reaches continuous validation with automated Policy Decision Point and Policy Enforcement Point decisions made at machine speed. That single ladder — password to continuous, automated validation — is what a maturity target actually looks like, and every pillar has its own version of it.
  • Cross-functional governance ownership. The five pillars each span multiple teams — identity (often HR and IT), devices (IT and endpoint management), networks (infrastructure), applications (development and operations), and data (legal, compliance, and data governance). The three cross-cutting capabilities span all of them: visibility and analytics (security operations), automation and orchestration (SecOps and platform engineering), and governance (the CISO and executive team, who own policy definition and enforcement across the whole architecture). No single team owns the full model. Executive governance must create the cross-functional accountability structure that makes coordinated progress across every pillar and capability possible.
  • Compliance alignment from the start. For regulated organizations, zero trust implementation should be designed to satisfy multiple compliance frameworks simultaneously — NIST CSF 2.0, ISO 27001:2022, CMMC, FedRAMP, HIPAA, and others all have controls that zero trust architecture addresses. Building this alignment in from the start avoids the rework of retrofitting compliance evidence onto an already-implemented architecture.

What the board needs to understand

Zero trust is increasingly a board-level governance topic, particularly for organizations in regulated industries or with significant cyber risk exposure. CISOs presenting zero trust to boards should frame it not as a security technology project but as a risk management program with measurable outcomes.

The board-level conversation should address three questions: What is the organization's current security posture relative to the threats it faces? What is the cost and timeline of implementing zero trust architecture? What risk reduction does that investment deliver, expressed in terms the board can evaluate — reduction in breach probability, reduction in breach impact, improvement in compliance posture, and reduction in cyber insurance cost?

Executive Summary

Zero trust is a security architecture that eliminates implicit trust from your environment. It requires sustained executive commitment across the five CISA pillars — identity, devices, networks, applications, and data — held together by three cross-cutting capabilities: visibility and analytics, automation and orchestration, and governance. Governance is the one you own directly.

Organizations that succeed treat it as a governance program. Organizations that fail treat it as a product purchase. The difference is entirely in how executive leadership frames and sustains it.

Start with an honest maturity assessment against the CISA Zero Trust Maturity Model. Set realistic maturity targets for a 24-month horizon. Build the cross-functional governance structure. Then select the technology.

A practical starting point for 2026

For organizations that are early in their zero trust journey, the most pragmatic starting point is identity — specifically, ensuring that every human identity has MFA enforced, that privileged accounts are managed under a Privileged Access Management program, and that identity governance processes ensure that access is removed when roles change or personnel leave.

These are not glamorous controls. They do not make for impressive vendor case studies. But the overwhelming majority of major breaches involve compromised credentials — and the identity pillar, implemented with depth rather than just MFA, addresses that attack vector more effectively than any other single investment.

From that foundation, the sequencing of the remaining pillars should be driven by your organization's specific risk profile, threat landscape, and compliance obligations — not by vendor roadmaps or analyst framework aesthetics. Zero trust is not a universal sequence. It is a set of principles applied to your specific environment, in the order that best addresses your actual risk.

The executive SecOps framework

Volume IV of the ITOps Intelligence™ series covers AI-integrated security operations — zero trust, AI-driven threat detection, SIEM/SOAR governance, and CISO board reporting frameworks. Aligned with NIST CSF 2.0, ISO 27001:2022, CMMC, and FedRAMP.

View Volume IV Join the Waitlist