The gap that matters most in zero trust is the difference between deploying individual controls and operating a measurable architecture across the enterprise. MFA, SSO, endpoint management, segmentation, application policy, and data controls may all contribute, but adoption of one control does not prove maturity across the full model. CISA's Zero Trust Maturity Model provides a practical way to assess that unevenness pillar by pillar.
The honest answer to "are we doing zero trust" is rarely yes or no. The better question is: on which pillar, at what maturity stage, with what evidence? This guide uses CISA's framework to help organizations locate their current position and prioritize the next control gap.
Why "We've Adopted Zero Trust" Is the Wrong Question
Many organizations that say they have adopted zero trust have deployed MFA and single sign-on. That is real progress, but under CISA's model it advances only part of the Identity pillar and does not establish maturity across Devices, Networks, Applications and Workloads, Data, or the cross-cutting capabilities. Identity is usually where programs start—and where many stall.
Two numbers explain why identity alone isn't sufficient. Microsoft's Digital Defense Report 2025 found password-based attacks now account for more than 99% of the roughly 600 million daily identity attacks against Microsoft Entra, and identity-based attacks rose 32% in the first half of 2025 alone. Attackers have adapted faster than most identity-only zero trust programs have matured — which is exactly why the model requires four more pillars beyond identity to call a program complete.
The Framework: CISA's Zero Trust Maturity Model
The CISA Zero Trust Maturity Model (ZTMM v2.0) is the closest thing to an industry-standard yardstick for this conversation, and it's increasingly what's showing up in board reporting because it forces programs to substantiate claims with actual telemetry rather than a slide saying "zero trust: in progress."
Five pillars, each assessed independently:
- Identity — how users, devices, and non-human identities are verified and continuously evaluated, not just authenticated once
- Devices — visibility, health, and compliance posture of every device touching enterprise resources
- Networks — segmentation and encrypted traffic, moving away from flat, trust-the-perimeter architectures
- Applications & Workloads — access control and monitoring applied to applications themselves, not just the network around them
- Data — classification, encryption, and access governance applied at the data layer, independent of where that data sits
Three cross-cutting capabilities that tie the pillars together:
● Visibility and Analytics
● Automation and Orchestration
● Governance
Four maturity stages, applied per pillar (not as one score for the whole organization):
● Traditional — where most programs start, and where many get stuck
● Initial — early automation and policy enforcement beginning
● Advanced — centralized visibility and dynamic policy enforcement across most of the pillar
● Optimal — fully automated, continuously verified, and dynamically adjusted in near real time
A common mistake is treating zero trust as one maturity score for the entire company instead of assessing each pillar separately. An organization can be Optimal on Identity and still be Traditional on Data. That unevenness is precisely what a pillar-level assessment is designed to expose.
What Maturity Is Actually Worth
This isn't just a compliance exercise — it shows up directly in breach economics. IBM's 2025 Cost of a Data Breach Report (Ponemon Institute methodology, 604 organizations across 17 industries and 16 countries) found organizations with zero trust architecture in place saved an average of $1.76 million per breach compared to organizations without it — a reduction of roughly 40% against the 2025 global average breach cost of $4.44 million. Zero trust ranked as the third most cost-effective control measured in the report, behind only having a tested incident response plan ($2.66 million saved) and extensive AI/automation use in security operations ($1.9 million saved).
For U.S. organizations specifically, where the average breach cost hit $10.22 million in 2025, the proportional case is even stronger — the same relative maturity improvements translate into larger absolute dollar savings.
The mechanism behind the savings tracks directly to the maturity model: breaches at organizations with more mature identity, device, and network segmentation controls are contained faster and spread less, because there's no longer a single flat network for an attacker to move laterally across once they're past the perimeter.
Where Programs Actually Get Stuck (And Why)
Identity gets the investment; Data and Applications & Workloads lag behind. Identity is the pillar with the clearest vendor category (IAM, MFA, SSO) and the most mature tooling, so it's usually where budget goes first. Data classification and per-application access governance require more organizational work — cataloging what data exists, who should touch it, and how — and that work doesn't have a single tool you can buy your way out of. This is the most common reason a program looks mature on paper (identity) but isn't close to CISA's "Optimal" stage across the full model.
Governance lags the technical pillars. Visibility and Analytics tooling gets deployed; the Governance cross-cutting capability — the policies, ownership, and accountability structures that make the technical controls durable — often doesn't keep pace. A SIEM or identity platform without a governance structure behind it tends to degrade back toward Traditional practices within a couple of budget cycles, as tuning gets deprioritized and exceptions accumulate.
Non-human identity is the frontier most programs haven't reached yet. Non-human identities—service accounts, API keys, workload identities, automation identities, and AI agents—can greatly exceed the number of human users in modern environments. Most zero trust programs began with workforce identity and have not yet applied equivalent lifecycle, privilege, credential, and behavioral controls to machine-to-machine access.
Illustrative Scenarios: Two Different Maturity Profiles
The following scenarios are hypothetical and are not customer case studies.
Scenario 1: A 200-Person Fintech
The company has:
- Universal MFA
- Centralized SSO
- Endpoint management
- Limited application controls
Its likely profile could be:
| Pillar | Maturity |
|---|---|
| Identity | Advanced |
| Devices | Initial |
| Networks | Traditional |
| Applications and Workloads | Initial |
| Data | Traditional |
The organization has made meaningful progress in Identity, but a compromised account may still access broad network resources and unclassified data.
Its next investment should likely target Networks and Data rather than another identity feature.
Scenario 2: A 5,000-Person Healthcare System
The organization has:
- Risk-based authentication
- Strong endpoint telemetry
- Microsegmentation for critical systems
- Application monitoring
- Board-level oversight
Its profile could be:
| Pillar | Maturity |
|---|---|
| Identity | Optimal |
| Devices | Advanced |
| Networks | Advanced |
| Applications and Workloads | Advanced |
| Data | Initial |
This organization has stronger cross-pillar maturity but remains exposed where classification and legacy clinical data controls are incomplete.
IBM reported that healthcare had the highest average breach cost in 2025 at $7.42 million, reinforcing the financial importance of disciplined security controls in the sector.
Most organizations map closer to Organization A than B. That's not a criticism — it reflects where budget and organizational effort naturally go first. The point of the maturity model is to make that unevenness visible and prioritize the next investment deliberately, rather than continuing to add identity tooling because that's the pillar with the clearest next purchase.
How to Actually Assess Where You Stand
1. Score each pillar independently — resist the urge to average. A single "zero trust maturity" number hides more than it reveals. Score Identity, Devices, Networks, Applications & Workloads, and Data separately against CISA's four stages, and be honest about which ones are still Traditional.
2. Check whether Governance exists as a real function, not just a policy document. A technical control without an owner, a review cadence, and an escalation path tends to decay. If nobody can say who owns exceptions to your access policies, that's a Governance gap regardless of how advanced your identity tooling looks.
3. Inventory non-human identities before assuming your identity pillar is done. If service accounts, API keys, and workload identities aren't inside the same continuous-verification model as human users, your Identity pillar likely isn't as mature as the human-facing tooling suggests.
4. Model the breach-cost case for your specific pillars, not zero trust in the abstract. The $1.76 million average saving is a real, citable number for a board conversation — but the more persuasive version ties it to your specific gaps: if Networks is your weakest pillar, tie the business case to lateral-movement scenarios specifically, not zero trust generally.
5. Build a 12-24 month roadmap that closes your worst pillar first, not your easiest one. It's tempting to keep investing in the pillar with the most mature vendor tooling (usually Identity) because it's the easiest next purchase. The maturity model's real value is forcing investment toward the pillar that's actually weakest — which for most organizations is Data or Applications & Workloads, not Identity.
The Maturity Trend Worth Watching
Non-human identity is becoming a major maturity test as AI agents, service accounts, APIs, and automated workloads multiply. Programs that treat zero trust only as workforce identity and device management risk leaving machine credentials, workload privileges, secrets, and agent actions outside continuous verification. Organizations should add non-human identity inventory, ownership, credential rotation, privilege controls, behavioral monitoring, and decommissioning evidence to their maturity roadmap.
CyberTech Intelligence Perspective: Zero trust maturity should be reported as evidence across distinct pillars, not as a single claim that the organization has "implemented zero trust." The weakest high-consequence pillar should determine the next investment priority.
Where This Fits Your Roadmap
If you're heading into a board conversation about zero trust investment, the pillar-by-pillar framing above is the difference between a credible roadmap and a vague "we're working on it." The IBM breach-cost data gives you the financial case; the CISA model gives you the structure to show exactly where that investment needs to go next.
That's the kind of executive-level, research-grounded framing CyberTech Intelligence's CISO Engagement Programs and Strategic Consulting services are built to support — helping security leaders benchmark their actual maturity against peers and bring a defensible, prioritized roadmap into the boardroom rather than a status update.
Request a Zero Trust Maturity Assessment
Limitations and Practical Considerations
● A maturity model is a decision aid, not an audit conclusion or universal score. CISA's stages describe characteristics that organizations should interpret against their mission, threat model, regulatory obligations, legacy environment, and risk appetite. Self-assessments may overstate maturity when evidence is incomplete, controls are unevenly deployed, or exceptions are not measured. IBM breach-cost findings are portfolio-level associations and should not be used to predict savings for a specific organization.
● Zero trust implementation can increase operational complexity, integration effort, user friction, and dependency on accurate identity, device, application, and data inventories. Programs should test controls, provide accessible alternatives, govern emergency access, monitor false positives, protect privacy, and preserve business continuity. The scenarios in this guide are hypothetical examples, not customer case studies.
References and Source Links
● CISA, Zero Trust Maturity Model Version 2.0: https://www.cisa.gov/resources-tools/resources/zero-trust-maturity-model
● NIST SP 800-207, Zero Trust Architecture: https://csrc.nist.gov/pubs/sp/800/207/final
● Microsoft Digital Defense Report 2025: https://www.microsoft.com/en-us/security/security-insider/intelligence-reports/microsoft-digital-defense-report-2025
● IBM, Cost of a Data Breach Report 2025: https://www.ibm.com/reports/data-breach
Author
CyberTech Intelligence Editorial Desk
Author