The Cybersecurity and Infrastructure Security Agency (CISA) Zero Trust Maturity Model (ZTMM) lays out a framework for practically achieving Zero Trust.

While originally intended for government agencies, the ZTMM has wide applicability, including as a potential roadmap for large enterprises to achieve Zero Trust.

The ZTMM breaks the requirements of Zero Trust into five categories across three foundational needs (see image below; source: Zero Trust Maturity Model, April 2023; CISA Cybersecurity Division).