Back to Frameworks

DoD Zero Trust Reference Architecture

United States
v3.0
7 domains
45 controls

The U.S. Department of Defense Zero Trust Reference Architecture and Zero Trust Capabilities/Activities. Defines the DoD zero-trust target state across 7 pillars (User; Device; Application & Workload; Data; Network & Environment; Automation & Orchestration; Visibility & Analytics), 45 capabilities and 152 Target-Level / Advanced-Level activities, supporting the DoD Zero Trust Strategy goal of a target-level zero-trust architecture. Aligned with NIST SP 800-207 zero-trust tenets and implemented over NIST SP 800-53 controls.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

DoD ZT Pillar 1: User

9 controls
Controls in the DoD ZT Pillar 1: User domain of DoD Zero Trust Reference Architecture9 controls
CodeTitle
DODZT-1.1User Inventory
DODZT-1.2Conditional User Access
DODZT-1.3Multi-Factor Authentication
DODZT-1.4Privileged Access Management
DODZT-1.5Identity Federation and User Credentialing
DODZT-1.6Behavioral, Contextual ID, and Biometrics
DODZT-1.7Least Privileged Access
DODZT-1.8Continuous Authentication
DODZT-1.9Integrated ICAM Platform

DoD ZT Pillar 2: Device

7 controls
Controls in the DoD ZT Pillar 2: Device domain of DoD Zero Trust Reference Architecture7 controls
CodeTitle
DODZT-2.1Device Inventory
DODZT-2.2Device Detection and Compliance
DODZT-2.3Device Authorization with Real-Time Inspection
DODZT-2.4Remote Access
DODZT-2.5Partially and Fully Automated Asset, Vulnerability and Patch Management
DODZT-2.6Unified Endpoint Management and Mobile Device Management
DODZT-2.7Endpoint and Extended Detection and Response

DoD ZT Pillar 3: Application and Workload

5 controls
Controls in the DoD ZT Pillar 3: Application and Workload domain of DoD Zero Trust Reference Architecture5 controls
CodeTitle
DODZT-3.1Application Inventory
DODZT-3.2Secure Software Development and Integration
DODZT-3.3Software Risk Management
DODZT-3.4Resource Authorization and Integration
DODZT-3.5Continuous Monitoring and Ongoing Authorizations

DoD ZT Pillar 4: Data

7 controls
Controls in the DoD ZT Pillar 4: Data domain of DoD Zero Trust Reference Architecture7 controls
CodeTitle
DODZT-4.1Data Catalog Risk Alignment
DODZT-4.2DoD Enterprise Data Governance
DODZT-4.3Data Labeling and Tagging
DODZT-4.4Data Monitoring and Sensing
DODZT-4.5Data Encryption and Rights Management
DODZT-4.6Data Loss Prevention
DODZT-4.7Data Access Control

DoD ZT Pillar 5: Network and Environment

4 controls
Controls in the DoD ZT Pillar 5: Network and Environment domain of DoD Zero Trust Reference Architecture4 controls
CodeTitle
DODZT-5.1Data Flow Mapping
DODZT-5.2Software Defined Networking
DODZT-5.3Macro Segmentation
DODZT-5.4Micro Segmentation

DoD ZT Pillar 6: Automation and Orchestration

7 controls
Controls in the DoD ZT Pillar 6: Automation and Orchestration domain of DoD Zero Trust Reference Architecture7 controls
CodeTitle
DODZT-6.1Policy Decision Point and Policy Orchestration
DODZT-6.2Critical Process Automation
DODZT-6.3Machine Learning
DODZT-6.4Artificial Intelligence
DODZT-6.5Security Orchestration, Automation and Response
DODZT-6.6API Standardization
DODZT-6.7Security Operations Center and Incident Response

DoD ZT Pillar 7: Visibility and Analytics

6 controls
Controls in the DoD ZT Pillar 7: Visibility and Analytics domain of DoD Zero Trust Reference Architecture6 controls
CodeTitle
DODZT-7.1Log All Traffic
DODZT-7.2Security Information and Event Management
DODZT-7.3Common Security and Risk Analytics
DODZT-7.4User and Entity Behavior Analytics
DODZT-7.5Threat Intelligence Integration
DODZT-7.6Automated Dynamic Policies

Your Compliance Coverage

If you comply with DoD Zero Trust Reference Architecture, you already cover:

Maps to 6 other frameworks

45 total controls
NIST SP 800-53 Rev 5
15 source controls mapped|11 target controls covered
33%
NIST Cybersecurity Framework 2.0
5 source controls mapped|5 target controls covered
11%
NIST SP 800-207
4 source controls mapped|5 target controls covered
9%
ISO 19011
1 source controls mapped|1 target controls covered
2%
ISO 31000:2018
1 source controls mapped|1 target controls covered
2%
ISO 27018:2019
1 source controls mapped|1 target controls covered
2%

Frequently Asked Questions

What is DoD Zero Trust Reference Architecture?

DoD Zero Trust Reference Architecture is a compliance framework from United States with 7 domains and 45 controls. The U.S. Department of Defense Zero Trust Reference Architecture and Zero Trust Capabilities/Activities. Defines the DoD zero-trust target state across 7 pillars (User; Device; Application & Workload; Data; Network & Environment; Automation & Orchestration; Visibility & Analytics), 45 capabilities and 152 Target-Level / Advanced-Level activities, supporting the DoD Zero Trust Strategy goal of a target-level zero-trust architecture. Aligned with NIST SP 800-207 zero-trust tenets and implemented over NIST SP 800-53 controls. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does DoD Zero Trust Reference Architecture have?

DoD Zero Trust Reference Architecture has 45 controls organised across 7 domains. The largest domains are DoD ZT Pillar 1: User (9 controls), DoD ZT Pillar 2: Device (7 controls), DoD ZT Pillar 4: Data (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does DoD Zero Trust Reference Architecture map to?

DoD Zero Trust Reference Architecture maps to 6 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (33% coverage), NIST Cybersecurity Framework 2.0 (11% coverage), NIST SP 800-207 (9% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with DoD Zero Trust Reference Architecture compliance?

Start your DoD Zero Trust Reference Architecture compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about DoD Zero Trust Reference Architecture requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required