Zero trust is one idea with a lot of competing rulebooks. The frameworks broadly agree on principles and disagree on structure, scoring, and who is obligated to comply. Here is what each of the major documents actually is, and where they diverge.
The landscape
| Framework | Published | What it is | Structure |
|---|---|---|---|
| NIST SP 800-207 | Aug 2020 | The canonical definition of zero trust architecture. Everything else builds on it. | 7 tenets; policy engine, policy administrator, policy enforcement point |
| NIST SP 800-207A | Sep 2023 | Access control for cloud-native and multi-cloud workloads. Identity-based segmentation for microservices. | Policy tiers for service-to-service and user-to-service access |
| NIST SP 1800-35 | Jun 2025 (final) | NCCoE practice guide. The only document that shows working builds rather than principles. | 19 example implementations with 24 vendors, mapped to CSF and SP 800-53r5 |
| CISA Zero Trust Maturity Model 2.0 | Apr 2023 | A self-assessment roadmap for federal civilian agencies. Descriptive, not binding. | 5 pillars plus 3 cross-cutting capabilities; 4 maturity stages |
| OMB M-22-09 | Jan 2022 | Policy mandate, not a framework. Sets dated obligations for civilian agencies. | Specific targets: phishing-resistant MFA, device inventory, encrypted DNS and HTTP, app pen testing |
| DoD Zero Trust Reference Architecture 2.0 | 2022 | Engineering-level architecture for defense systems. | 7 pillars, 45 capabilities |
| DoD Zero Trust Strategy and Capability Execution Roadmap | Oct 2022 / Jan 2023 | The compliance clock. Assigns countable work to fixed dates. | 152 activities; 91 at Target Level due end of FY2027, the rest Advanced Level by FY2032 |
| DoD Zero Trust Overlays | Jun 2024 | Translates zero trust activities into audited security controls. | Maps all 152 activities to NIST SP 800-53r5 controls for RMF |
| NSA Zero Trust Implementation Guidelines | Jan 2026 | Sequencing guidance. Tells you what order to do the work in. | Primer, Discovery, Phase One (36 activities supporting 30 capabilities), Phase Two |
Where they actually differ
- Definition vs. measurement vs. mandate. NIST defines zero trust. CISA measures how far along you are. DoD tells you what to finish and by when. OMB compels civilian agencies to act. Comparing them as peers is the most common mistake.
- Pillar count is cosmetic. CISA uses five pillars (Identity, Devices, Networks, Applications and Workloads, Data) with Visibility and Analytics, Automation and Orchestration, and Governance as cross-cutting capabilities. DoD promotes visibility and automation to full pillars and calls Identity “User,” giving seven. The content is nearly identical. The shape is not, so cross-mapping requires care.
- Scoring is the real split. CISA grades on four qualitative stages: Traditional, Initial, Advanced, Optimal. DoD grades on binary activity completion against a deadline. DoD is far easier to audit and far harder to tailor. CISA gives you room to justify your architecture and correspondingly weak evidence of progress.
- Only some connect to controls. If your auditor speaks NIST SP 800-53, the DoD Overlays and SP 1800-35 give you traceability. The CISA maturity model does not map to controls at all, which is why agencies often score themselves “Advanced” with no artifact to back it.
- Scope and enforcement. CISA is advisory for federal civilian agencies. DoD guidance binds components and reaches into the defense industrial base and its subcontractors. Commercial firms borrow from both and are obligated by neither.
- All of them predate agentic AI. Every framework here assumes non-person entities are servers and services with stable identities. None of them addresses autonomous agents that acquire credentials, chain tool calls, and act on a user’s behalf at machine speed. That gap is now the interesting part of the problem.
Which one to use
Designing an architecture: SP 800-207 for the model, SP 800-207A if you are cloud-native, SP 1800-35 for reference builds that already work.
Reporting progress to a board or agency leadership: CISA ZTMM 2.0. The four stages communicate well to non-engineers.
Defense contractor or DIB supplier: the DoD roadmap for scope, the Overlays for RMF evidence, the NSA guidelines for sequencing. Note that recent NSA releases are published under Department of War branding following the 2025 renaming, so search both names.
Commercial enterprise: use CISA’s pillars to structure the conversation and DoD’s activity list to make it concrete. The activities are public, specific, and vendor-neutral, which makes them the best free checklist available regardless of whether you have a federal contract.
Primary sources
- NIST SP 800-207, Zero Trust Architecture
- NIST SP 800-207A, Zero Trust Architecture Model for Access Control in Cloud-Native Applications
- NIST SP 1800-35, Implementing a Zero Trust Architecture
- CISA Zero Trust Maturity Model Version 2.0
- DoD Zero Trust Reference Architecture v2.0
- DoD Zero Trust Strategy
- NSA Zero Trust Implementation Guideline, Phase One



Leave a Reply