Back to Frameworks

CISA Zero Trust Maturity Model

United States
v2.0
13 domains
46 controls

CISA Zero Trust Maturity Model for federal agencies

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (13)

Applications and Workloads Pillar

4 controls
Controls in the Applications and Workloads Pillar domain of CISA Zero Trust Maturity Model4 controls
CodeTitle
ZTMM-APP-1Application Access
ZTMM-APP-2Application Threat Protection
ZTMM-APP-3Secure Application Development and Deployment
ZTMM-APP-4Application Visibility and Analytics

CISA Zero Trust Maturity Model: Access Control & Identity

6 controls

Managing access to information systems (CISA Zero Trust Maturity Model)

Controls in the CISA Zero Trust Maturity Model: Access Control & Identity domain of CISA Zero Trust Maturity Model6 controls
CodeTitle
ZTMM-ID-AOIdentity Pillar: Automation and Orchestration
ZTMM-ID-VAIdentity Pillar: Visibility and Analytics
ZTMM-STAGE-ADVMaturity Stage: Advanced
ZTMM-STAGE-INITMaturity Stage: Initial
ZTMM-STAGE-OPTMaturity Stage: Optimal
ZTMM-STAGE-TRADMaturity Stage: Traditional

CISA Zero Trust Maturity Model: Audit & Accountability

0 controls

Audit logging and accountability measures (CISA Zero Trust Maturity Model)

CISA Zero Trust Maturity Model: Configuration Management

2 controls

Managing system configurations securely (CISA Zero Trust Maturity Model)

Controls in the CISA Zero Trust Maturity Model: Configuration Management domain of CISA Zero Trust Maturity Model2 controls
CodeTitle
ZTMM-DAT-AVAILData Pillar: Data Availability
ZTMM-DAT-CATData Pillar: Data Categorization

CISA Zero Trust Maturity Model: Incident Response

5 controls

Detecting and responding to security incidents (CISA Zero Trust Maturity Model)

Controls in the CISA Zero Trust Maturity Model: Incident Response domain of CISA Zero Trust Maturity Model5 controls
CodeTitle
ZTMM-APP-GOVApplications Pillar: Governance
ZTMM-APP-TESTApplications Pillar: Application Security Testing
ZTMM-DAT-AOData Pillar: Automation and Orchestration
ZTMM-DAT-GOVData Pillar: Governance
ZTMM-DAT-VAData Pillar: Visibility and Analytics

CISA Zero Trust Maturity Model: Risk Assessment & Management

5 controls

Identifying and managing cybersecurity risks (CISA Zero Trust Maturity Model)

Controls in the CISA Zero Trust Maturity Model: Risk Assessment & Management domain of CISA Zero Trust Maturity Model5 controls
CodeTitle
ZTMM-APP-AOApplications Pillar: Automation and Orchestration
ZTMM-APP-VAApplications Pillar: Visibility and Analytics
ZTMM-NET-AONetworks Pillar: Automation and Orchestration
ZTMM-NET-ENCNetworks Pillar: Traffic Encryption
ZTMM-NET-GOVNetworks Pillar: Governance

CISA Zero Trust Maturity Model: System & Communications Protection

6 controls

Protecting systems and communications (CISA Zero Trust Maturity Model)

Controls in the CISA Zero Trust Maturity Model: System & Communications Protection domain of CISA Zero Trust Maturity Model6 controls
CodeTitle
ZTMM-DEV-AODevices Pillar: Automation and Orchestration
ZTMM-DEV-GOVDevices Pillar: Governance
ZTMM-DEV-SCRMDevices Pillar: Asset and Supply Chain Risk Management
ZTMM-DEV-VADevices Pillar: Visibility and Analytics
ZTMM-ID-GOVIdentity Pillar: Governance
ZTMM-NET-VANetworks Pillar: Visibility and Analytics

Cross-Cutting Capability

3 controls
Controls in the Cross-Cutting Capability domain of CISA Zero Trust Maturity Model3 controls
CodeTitle
ZTMM-CROSS-1Visibility and Analytics
ZTMM-CROSS-2Automation and Orchestration
ZTMM-CROSS-3Governance for Zero Trust

Data Pillar

4 controls
Controls in the Data Pillar domain of CISA Zero Trust Maturity Model4 controls
CodeTitle
ZTMM-DAT-1Data Inventory and Classification
ZTMM-DAT-2Data Access Control
ZTMM-DAT-3Data Encryption
ZTMM-DAT-4Data Loss Prevention

Devices Pillar

3 controls
Controls in the Devices Pillar domain of CISA Zero Trust Maturity Model3 controls
CodeTitle
ZTMM-DEV-1Device Inventory
ZTMM-DEV-2Device Compliance and Posture
ZTMM-DEV-3Device Threat Protection

Identity Pillar

4 controls
Controls in the Identity Pillar domain of CISA Zero Trust Maturity Model4 controls
CodeTitle
ZTMM-ID-1Identity Authentication
ZTMM-ID-2Identity Stores
ZTMM-ID-3Risk Assessments for Identity
ZTMM-ID-4Access Management

Maturity

1 controls
Controls in the Maturity domain of CISA Zero Trust Maturity Model1 controls
CodeTitle
ZTMM-MAT-1Maturity Stage Self-Assessment

Networks Pillar

3 controls
Controls in the Networks Pillar domain of CISA Zero Trust Maturity Model3 controls
CodeTitle
ZTMM-NET-1Network Segmentation
ZTMM-NET-2Network Traffic Management
ZTMM-NET-3Resilience and Availability

Maps to 1 other framework

46 total controls
NIST SP 800-53 Rev 5
24 source controls mapped|18 target controls covered
52%

Frequently Asked Questions

What is CISA Zero Trust Maturity Model?

CISA Zero Trust Maturity Model is a compliance framework from United States with 13 domains and 46 controls. CISA Zero Trust Maturity Model for federal agencies It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does CISA Zero Trust Maturity Model have?

CISA Zero Trust Maturity Model has 46 controls organised across 13 domains. The largest domains are CISA Zero Trust Maturity Model: Access Control & Identity (6 controls), CISA Zero Trust Maturity Model: System & Communications Protection (6 controls), CISA Zero Trust Maturity Model: Incident Response (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does CISA Zero Trust Maturity Model map to?

CISA Zero Trust Maturity Model maps to 1 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (52% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with CISA Zero Trust Maturity Model compliance?

Start your CISA Zero Trust Maturity Model compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CISA Zero Trust Maturity Model requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 46 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required