Back to Field Notes
Zero Trust Architecture/Field Note

CISA Zero Trust Maturity Model 2.0 — A Useful Yardstick

The ZTMM is the rare maturity model that does not collapse into vendor marketing. Used honestly, it surfaces the real gaps.

Author

Sofia Reyes

Distinguished Architect, Zero Trust Practice

Published

January 22, 2026

Read

9 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01ZTMM 2.0 scores five pillars (Identity, Devices, Networks, Applications & Workloads, Data) and three cross-cutting capabilities (Visibility & Analytics, Automation & Orchestration, Governance) across four stages: Traditional, Initial, Advanced, Optimal.
  • 02Treat 'Advanced' as the realistic enterprise target — 'Optimal' rarely justifies the marginal cost outside national-security contexts.
  • 03Median enterprise scoring lands at 'Initial' on Devices and Data, 'Advanced' on Identity and Networks. The asymmetry is real: identity and SASE got funded; data classification and device-trust enforcement at scale did not.
  • 04Re-score quarterly with a delta report. Score honestly against the criteria text, not against the vendor pitch — that is the only way the model surfaces the actual gaps.

CISA published the Zero Trust Maturity Model (ZTMM) 2.0 in April 2023. It scores five pillars (Identity, Devices, Networks, Applications & Workloads, Data) and three cross-cutting capabilities (Visibility & Analytics, Automation & Orchestration, Governance) across four maturity stages: Traditional, Initial, Advanced, and Optimal.

How to use the model honestly

  • 01Score each pillar against the explicit criteria — not against the vendor's pitch
  • 02Treat 'Advanced' as the realistic enterprise target, not 'Optimal'
  • 03Use the cross-cutting capabilities as a forcing function for shared platform investment
  • 04Re-score quarterly, with a delta report for executive consumption

Where most programs land

After scoring 30+ enterprise programs against ZTMM 2.0, the median is 'Initial' on Devices and Data, 'Advanced' on Identity and Networks. The asymmetry is meaningful: organizations have spent on identity and SASE, but have not closed the loop on data classification or device-trust enforcement at scale.

#Zero Trust#CISA#Maturity

/WRITTEN_BY

Sofia Reyes

Distinguished Architect, Zero Trust Practice · Alexa Cybersecurity