
- 01ZTMM 2.0 scores five pillars (Identity, Devices, Networks, Applications & Workloads, Data) and three cross-cutting capabilities (Visibility & Analytics, Automation & Orchestration, Governance) across four stages: Traditional, Initial, Advanced, Optimal.
- 02Treat 'Advanced' as the realistic enterprise target — 'Optimal' rarely justifies the marginal cost outside national-security contexts.
- 03Median enterprise scoring lands at 'Initial' on Devices and Data, 'Advanced' on Identity and Networks. The asymmetry is real: identity and SASE got funded; data classification and device-trust enforcement at scale did not.
- 04Re-score quarterly with a delta report. Score honestly against the criteria text, not against the vendor pitch — that is the only way the model surfaces the actual gaps.
CISA published the Zero Trust Maturity Model (ZTMM) 2.0 in April 2023. It scores five pillars (Identity, Devices, Networks, Applications & Workloads, Data) and three cross-cutting capabilities (Visibility & Analytics, Automation & Orchestration, Governance) across four maturity stages: Traditional, Initial, Advanced, and Optimal.
How to use the model honestly
- 01Score each pillar against the explicit criteria — not against the vendor's pitch
- 02Treat 'Advanced' as the realistic enterprise target, not 'Optimal'
- 03Use the cross-cutting capabilities as a forcing function for shared platform investment
- 04Re-score quarterly, with a delta report for executive consumption
Where most programs land
After scoring 30+ enterprise programs against ZTMM 2.0, the median is 'Initial' on Devices and Data, 'Advanced' on Identity and Networks. The asymmetry is meaningful: organizations have spent on identity and SASE, but have not closed the loop on data classification or device-trust enforcement at scale.


