Abstract illustration: Zero Trust Frameworks Compared, NIST, CISA, DoD and NSA

Zero Trust Frameworks Compared: NIST, CISA, DoD and NSA

Zero trust is one idea with a lot of competing rulebooks. The frameworks broadly agree on principles and disagree on structure, scoring, and who is obligated to comply. Here is what each of the major documents actually is, and where they diverge.

The landscape

FrameworkPublishedWhat it isStructure
NIST SP 800-207Aug 2020The canonical definition of zero trust architecture. Everything else builds on it.7 tenets; policy engine, policy administrator, policy enforcement point
NIST SP 800-207ASep 2023Access control for cloud-native and multi-cloud workloads. Identity-based segmentation for microservices.Policy tiers for service-to-service and user-to-service access
NIST SP 1800-35Jun 2025 (final)NCCoE practice guide. The only document that shows working builds rather than principles.19 example implementations with 24 vendors, mapped to CSF and SP 800-53r5
CISA Zero Trust Maturity Model 2.0Apr 2023A self-assessment roadmap for federal civilian agencies. Descriptive, not binding.5 pillars plus 3 cross-cutting capabilities; 4 maturity stages
OMB M-22-09Jan 2022Policy mandate, not a framework. Sets dated obligations for civilian agencies.Specific targets: phishing-resistant MFA, device inventory, encrypted DNS and HTTP, app pen testing
DoD Zero Trust Reference Architecture 2.02022Engineering-level architecture for defense systems.7 pillars, 45 capabilities
DoD Zero Trust Strategy and Capability Execution RoadmapOct 2022 / Jan 2023The compliance clock. Assigns countable work to fixed dates.152 activities; 91 at Target Level due end of FY2027, the rest Advanced Level by FY2032
DoD Zero Trust OverlaysJun 2024Translates zero trust activities into audited security controls.Maps all 152 activities to NIST SP 800-53r5 controls for RMF
NSA Zero Trust Implementation GuidelinesJan 2026Sequencing guidance. Tells you what order to do the work in.Primer, Discovery, Phase One (36 activities supporting 30 capabilities), Phase Two

Where they actually differ

  • Definition vs. measurement vs. mandate. NIST defines zero trust. CISA measures how far along you are. DoD tells you what to finish and by when. OMB compels civilian agencies to act. Comparing them as peers is the most common mistake.
  • Pillar count is cosmetic. CISA uses five pillars (Identity, Devices, Networks, Applications and Workloads, Data) with Visibility and Analytics, Automation and Orchestration, and Governance as cross-cutting capabilities. DoD promotes visibility and automation to full pillars and calls Identity “User,” giving seven. The content is nearly identical. The shape is not, so cross-mapping requires care.
  • Scoring is the real split. CISA grades on four qualitative stages: Traditional, Initial, Advanced, Optimal. DoD grades on binary activity completion against a deadline. DoD is far easier to audit and far harder to tailor. CISA gives you room to justify your architecture and correspondingly weak evidence of progress.
  • Only some connect to controls. If your auditor speaks NIST SP 800-53, the DoD Overlays and SP 1800-35 give you traceability. The CISA maturity model does not map to controls at all, which is why agencies often score themselves “Advanced” with no artifact to back it.
  • Scope and enforcement. CISA is advisory for federal civilian agencies. DoD guidance binds components and reaches into the defense industrial base and its subcontractors. Commercial firms borrow from both and are obligated by neither.
  • All of them predate agentic AI. Every framework here assumes non-person entities are servers and services with stable identities. None of them addresses autonomous agents that acquire credentials, chain tool calls, and act on a user’s behalf at machine speed. That gap is now the interesting part of the problem.

Which one to use

Designing an architecture: SP 800-207 for the model, SP 800-207A if you are cloud-native, SP 1800-35 for reference builds that already work.

Reporting progress to a board or agency leadership: CISA ZTMM 2.0. The four stages communicate well to non-engineers.

Defense contractor or DIB supplier: the DoD roadmap for scope, the Overlays for RMF evidence, the NSA guidelines for sequencing. Note that recent NSA releases are published under Department of War branding following the 2025 renaming, so search both names.

Commercial enterprise: use CISA’s pillars to structure the conversation and DoD’s activity list to make it concrete. The activities are public, specific, and vendor-neutral, which makes them the best free checklist available regardless of whether you have a federal contract.

Primary sources


Leave a Reply

Discover more from Digerati One (Di1) | AI Integration & Multi-Cloud Architecture

Subscribe now to keep reading and get access to the full archive.

Continue reading