CISA Zero Trust Maturity Model
The federal zero-trust maturity model: five pillars, three cross-cutting capabilities, and four maturity stages from traditional to optimal.
What This Framework Contributes.
The deepest inheritance in the framework and the one that most needs a boundary drawn round it. Five pillars are carried verbatim as terrain; four further layers are added, and an average taken across all nine is not a ZTMM score.
- The five pillars as terrain layers T1–T5, unrenamed, so an agency already reporting ZTMM maturity reads this framework without translating its own reporting.
- The four stages as the rung ladder every sub-tower is scored against, made concrete: what Advanced means on privileged access is not what it means on passive OT monitoring, and both are written down.
- Movement across the pillars. A maturity model scores ground; this framework asks what an adversary can reach from where, which is a question the model does not pose.
What it does not do for CISA ZTMM.
Read this before the crosswalk, not after it. A reader who takes the mappings below as coverage of CISA ZTMM will be wrong in a way that is expensive to discover later.
- A ZTMM assessment or submission.Nothing here produces a maturity self-assessment in the model’s own form. The sub-tower ladders are this framework’s, scored for its own rollup.
- The model’s per-pillar functions.ZTMM decomposes each pillar into its own named functions. The sub-towers below are not those functions and are not offered as a substitute for them.
- The pillar set as a complete map of a federal estate.Four layers are added here precisely because a measurable part of a federal estate had nowhere to stand. That is a stated disagreement with the model’s scope, not an oversight — and the justification for each is published rather than assumed.
- Comparability of the rollup.Coverage computed across nine layers is not comparable with a maturity stage computed across five. An agency reporting both must report them separately, and this framework’s number is the one that has to give way.
The Five Pillars, Carried Verbatim.
Unrenamed on purpose. An agency already reporting maturity against these pillars should not have to translate its own reporting to read this framework — so the pillar names are the layer names, and the layer ids run in the model’s own order.
17 controls apply to every layer by construction and are stated once rather than repeated in nine lists: TM-1 Terrain Inventory and Overlay, TM-2 Defensive Layer Classification, TM-3 Asset Weighting, TM-6 Terrain Currency, TM-7 Terrain Ownership, KT-1 Decisive Point Identification, KT-2 Decisive Point Protection Floor, FO-7 Obligation Profile Declaration, EN-1 Event Declaration and Triage, EN-2 Engagement Reconstruction, EN-3 Evidence Preservation, EN-4 Escalation and Engagement Authority, EN-5 Eradication and Transition to Recovery, EN-6 Engagement Communication, SM-7 Deception Emplacement, CE-4 Coverage and Residual Risk Computation, CE-5 Remediation Backlog Prioritization. The controls named under each pillar below are the ones that do something particular to that ground.
Identity
T1 · 4 sub-towers · 11 controlsThe high ground. In zero trust, whoever controls identity controls movement. Every other layer is downstream of this one, which is why it is almost always the main effort.
- Authentication (phishing-resistant MFA)
- Authorization / PDP
- Privileged Access (JIT/PAM)
- Identity Governance (ICAM)
Devices
T2 · 4 sub-towers · 10 controlsThe entry fords. Where an adversary crosses from outside to inside. Managed and unmanaged endpoints are not the same ground, and a framework that scores them together hides the crossing.
- Endpoint Protection (EDR)
- Device Compliance / Posture
- Mobile & BYOD
- Server / Workload Hardening
Networks
T3 · 4 sub-towers · 7 controlsThe corridors. Movement corridors and the obstacles that canalize them. This is the layer where you decide which ground the adversary is allowed to walk on.
- Perimeter / TIC 3.0
- Microsegmentation
- Egress & DNS Control
- WAF & DDoS
Applications and Workloads
T4 · 4 sub-towers · 6 controlsThe urban terrain. Dense, complex, and hard to clear — the layer where defenders lose track of what they own. It also holds the single most leveraged decisive point in a modern estate.
- AppSec (SAST / DAST)
- API Security
- Pipeline Security (CI/CD)
- Runtime & Container
Data
T5 · 4 sub-towers · 6 controlsThe objective. The reason the campaign exists. Every other layer is defended in order to hold this one, and a scheme that cannot say which records it is protecting is not a scheme.
- Classification
- Encryption & Key Management
- DLP
- Data Access Governance
4 layers that are not pillars.
This is a stated disagreement with the model’s scope, not an oversight, so each addition carries the objection at its strongest and answers it. A reviewer who rejects the answer should reject the layer — and the framework will still work with five.
Operational Technology
T6 · added in v2.0 · 4 sub-towersGround you cannot maneuver freely on. Scored separately because the moves available here are narrower and the consequence of loss is physical. Treating an OT estate as ordinary network terrain overstates the defender’s options.
“CISA’s Zero Trust Maturity Model already covers devices and networks. Operational technology is devices on networks. Adding a sixth pillar duplicates two existing ones and breaks comparability with the maturity assessment the agency already reports under OMB M-22-09.”
- Comparability is preserved by construction: T1–T5 keep the ZTMM names, boundaries and maturity rungs exactly, and an agency’s reported ZTMM figures drop into this model unchanged. T6–T9 are scored alongside them, not blended into them. Removing the four added layers reproduces the ZTMM result exactly, which is the test the separation is designed to pass.
- The substantive objection is the interesting one, and it fails on the moves available rather than on the assets present. A maturity model is a statement about what good looks like. Scored as T2 devices, an OT estate is assessed against endpoint protection, posture-based access and rebuild-from-image — three practices that are respectively unavailable, unavailable and dangerous on a process controller. The estate scores Traditional forever, and the score carries no information because it was never achievable.
- Scoring OT separately changes what the number means. The four sub-towers here are the moves that are actually available on this ground — inventory, boundary, engineering access, passive monitoring — so a Traditional score is a finding somebody can act on and an Advanced score is a claim that can be tested.
- There is a second-order reason that matters in a federal estate specifically. OT is procured by program and facilities offices under different authorities, so it is systematically absent from an IT-derived asset register. A layer with its own inventory sub-tower forces the discovery; a sub-heading under Devices inherits the register that already does not contain it.
What it does not fix. This layer does not make an agency competent at OT security, and its four sub-towers are a floor rather than a program — an agency running genuine industrial control should be working to a sector-specific standard, with this layer serving only to place OT on the same map as everything else. It also overlaps deliberately with T8 Facilities on building systems; the overlap is resolved by ownership, not by cloning the asset into both layers.
Workforce
T7 · added in v3.0 · 4 sub-towersTerrain that is also the force. The only layer that is simultaneously the ground being defended and the force doing the defending. Insider risk and analyst saturation are the same measurement problem seen from two directions.
“People are not terrain. Personnel security, training and insider threat are established disciplines with their own programs and their own statutory basis; recasting them as a maturity layer in a cyber framework is a category error, and one that invites a security organization to surveil its own staff under the cover of a maturity score.”
- The category objection is answered by what the layer actually scores. It does not score people; it scores four registers and processes — who holds privilege, whether roles can demonstrate readiness, what the agency’s stated monitoring position is, and how fast access is revoked. Every one of those is an organizational property with an owner and a measurable state, and none of them is a judgment about an individual.
- The reason they belong on the terrain map rather than beside it is that they are already load-bearing for the rest of the model and are invisible to it. T1 identity governance can revoke an entitlement in seconds and cannot tell you that the human behind it left the agency three weeks ago, because the trigger lives in a personnel process. Scoring identity without workforce produces an identity layer that reports Advanced while carrying accounts for people who no longer work there.
- The saturation half has no home anywhere else at all. The framework’s central claim is temporal — that the defender must decide and act faster than the adversary — and the binding constraint on that claim in every real SOC is human capacity. A model that measures tooling maturity and not the state of the force will report a strengthening defense right up to the point where the defense culminates.
- On the surveillance risk, which is the strongest form of the objection: the layer is deliberately constructed to make an over-reaching program score badly. The insider-risk sub-tower cannot reach Advanced without a documented statement of what is deliberately not monitored, reviewed with counsel and privacy, and cannot reach Optimal without measuring the cost of false positives to the workforce. Those requirements exist because the risk is real, and a layer that ignored it would deserve the objection.
What it does not fix. This layer does not replace personnel security, background investigation or an insider-threat program constituted under its own authority, and it does not attempt to model human behavior. It measures whether the registers exist, whether readiness is demonstrated, whether the monitoring position is stated and bounded, and whether revocation is fast. Where an agency has a formal insider-threat function, this layer’s role is to keep it connected to the terrain rather than to duplicate it.
Facilities
T8 · added in v3.0 · 4 sub-towersThe physical boundary. A federal estate with data centers, laboratories and public counters has physical ground that a purely logical model scores as though it were not there.
“Physical security is covered by the PE family in NIST 800-53 and is already assessed under FISMA. In a cloud-forward agency the data center belongs to the provider and is inherited. A physical layer in a zero-trust maturity model measures the provider’s controls and the agency’s empty offices.”
- The inheritance argument is correct for the provider’s data centers and is exactly why this layer scores what is not inherited. A cloud-forward agency still operates equipment rooms, wiring closets, laboratory space, public counters with agency devices, and offsite backup — none of which appears in a provider’s attestation, and all of which sits inside the agency’s own boundary.
- The 800-53 argument confuses a control family with a terrain layer. The PE family states what shall be done; it does not produce a weighted coverage figure that rolls up to a mission consumer, and it is assessed on a three-year authorization cycle rather than on the defensive cycle. This layer’s job is to place physical space in the same rollup as everything else so that a mission’s residual risk includes the closet.
- The operational reason is that physical access defeats controls scored on other layers, invisibly to those layers. If physical is not a layer, the estate’s coverage figure silently assumes physical integrity — an assumption it has made no measurement of and cannot see when it fails.
- The specific finding this layer exists to produce is the vendor reconciliation: the maintenance supplier with standing physical access to a space holding production systems, who is also a registered supplier with logical access, tracked by two organizations that have never compared lists. That finding is not reachable from any other layer in the model.
What it does not fix. This layer is not a physical-security program and does not attempt to be one. It scores four properties of the spaces that hold production systems, and it defers to the agency’s physical-security function on everything else. In an estate that is genuinely fully cloud-hosted with no agency-operated space, this layer will be small and should be — the model is not improved by inventing weight for it.
Supply Chain
T9 · added in v3.0 · 4 sub-towersThe lines of communication. Doctrinally, an army’s lines of communication are terrain an enemy attacks precisely because they are not defended like the front. Software supply chain is the same idea with a different noun.
“Supply chain risk management already has a federal home: SR controls in 800-53, C-SCRM under NIST 800-161, FedRAMP for cloud services, and a procurement organization that owns supplier relationships. A terrain layer duplicates all of it and gives the security program a scoring surface it has no authority to act on.”
- The duplication objection has force against a layer that re-assessed suppliers, which this one does not. It scores four agency-side properties: whether the suppliers with reach are registered, whether the components in production are known, whether supplier access is constrained, and whether external changes cross a gate. Every one of those is inside the agency’s authority, and none of them is what a supplier questionnaire measures.
- Terrain treatment changes what happens to the answer. C-SCRM produces a supplier risk rating held by a procurement or risk function. This layer produces a weighted coverage figure that rolls into the residual risk of a named mission consumer, so a supplier weakness appears in the same ranked backlog as an unsegmented network and competes with it honestly. That comparison is not available when the two are assessed by different programs on different scales.
- The doctrinal argument is the one that decides it. An adversary who compromises an update channel is not attacking a supplier — they are attacking the mission that the update channel supplies, along a route the agency has not defended because it is not on the agency’s map. Lines of communication are terrain precisely because their defenders keep treating them as logistics.
- The practical test the layer has to pass is an advisory. When a component is named nationally, the agency either can or cannot say within hours whether it is running it and where. That is a terrain question — it requires an overlay, not a supplier rating — and an agency that cannot answer it has an unmapped route into its own estate regardless of how mature its vendor management is.
What it does not fix. This layer does not assess suppliers, does not replace C-SCRM or FedRAMP inheritance, and cannot see beyond the first tier of a supply chain with any confidence. Its residual risk is the least reducible in the model, and an agency that drives this figure down without changing access constraint or the staging gate has improved its paperwork. The layer’s honest claim is narrower than the discipline’s: it puts the route on the map and measures the gate at the end of it.
The Cross-Cutting Layer.
The maturity model has cross-cutting capabilities of its own, and this layer mirrors them. Counting it as an addition would overstate the disagreement; counting it as a pillar would understate it. It is reported as its own third category for that reason.
Cross-Cutting
TX · 3 sub-towersThe enablers of movement. Not ground, but what makes maneuver on the other nine possible: reconnaissance, mobility, and command authority. Scored as enablers rather than as terrain with a coverage gap.
- Visibility & Analytics (ISR)
- Automation & Orchestration (mobility)
- Governance (command authority)
Four Stages, Used as a Scoring Rung.
The stages are carried verbatim and pinned to the coverage percentage the tower model allocates with. Those percentages are a convention for turning a qualitative judgment into something that can be weighted — not a measurement, and not a maturity submission.
| Stage | Coverage allocated | What the stage means on any sub-tower |
|---|---|---|
| Traditional | 25% | Manual, static, and evaluated once rather than continuously. |
| Initial | 50% | Automated in places, with the estate’s hard cases handled by exception. |
| Advanced | 75% | Centrally enforced across the whole layer, with the exceptions named and owned. |
| Optimal | 100% | Continuous, dynamic, and measured against adversary tempo rather than against a policy. |
Traditional
- Coverage allocated
- 25%
- What the stage means on any sub-tower
- Manual, static, and evaluated once rather than continuously.
Initial
- Coverage allocated
- 50%
- What the stage means on any sub-tower
- Automated in places, with the estate’s hard cases handled by exception.
Advanced
- Coverage allocated
- 75%
- What the stage means on any sub-tower
- Centrally enforced across the whole layer, with the exceptions named and owned.
Optimal
- Coverage allocated
- 100%
- What the stage means on any sub-tower
- Continuous, dynamic, and measured against adversary tempo rather than against a policy.
Derived. Pillars, additions and the cross-cutting layer come from the terrain model’s own `origin` field; the justification for each addition is the layer’s own, read from the terrain reference. What the framework takes from this source and what it declines to take is set out in sources and provenance; the controls named on this page each carry their full lineage on their own sheet.