By NHI Mgmt Group Editorial TeamBased on StrongDM: “CISA Zero Trust Maturity Model (TL;DR Version)” (October 17, 2025)

TL;DR: CISA’s Zero Trust Maturity Model translates Zero Trust Architecture into five operational pillars and three maturity stages, with identity, device, network, application workload, and data controls moving from manual to dynamic enforcement. StrongDM’s summary also cites a 15.1% rise in cyberattacks and data breaches in 2021, according to the article.


At a glance

What this is: This is a StrongDM analysis of CISA’s Zero Trust Maturity Model and the shift it creates in access governance from static controls to continuous verification.

Why it matters: It matters because IAM, PAM, and NHI teams have to align identity, workload, and data access decisions with session-level enforcement rather than periodic approval cycles.

By the numbers:

  • In 2021, the average number of cyberattacks and data breaches increased by 15.1%.

Context

Zero Trust Architecture assumes that trust must be continuously earned, not granted once at login or provisioning time. In access governance terms, that shifts the control point from perimeter checks and annual reviews to dynamic authentication, session scoping, and policy enforcement across identity, device, network, workload, and data layers.

CISA’s maturity model is not a replacement for identity governance or privileged access management. It is an operational model for deciding how those controls progress from manual and static enforcement toward dynamic, continuously evaluated access decisions, especially in environments where legacy systems still expect persistent privilege.

For IAM and NHI programmes, the important change is not the label Zero Trust but the operating assumption behind it: access should be narrowly issued, continuously validated, and observably tied to actual resource use rather than standing entitlement.


Key questions

Q: What breaks when access governance still relies on standing entitlements in a zero trust model?

A: Standing entitlements break the logic of zero trust because they assume access can remain valid across changing risk conditions. In a mature model, identity, workload, and data access should be re-evaluated as context changes. If access is never forced back through a policy decision point, the programme can look compliant while still leaving broad, persistent reach in place.

Q: Why does session-based access create risk in Zero Trust environments?

A: Session-based access creates risk because it assumes the first authentication decision remains valid for the entire session. In reality, device state, user context, and risk posture can change after login. If access is not re-evaluated per request, organisations can miss opportunities to revoke access, narrow permissions, or block actions when conditions deteriorate.

Q: How can security teams tell whether zero trust is actually working in AWS?

A: Look for evidence that access is issued for a narrow purpose, expires automatically, and is auditable across accounts and resource types. If teams still rely on long-lived credentials, broad roles, or manual revocation to control AWS access, zero trust is only partially implemented.

Q: Which matters more for zero trust maturity, authentication or authorisation?

A: Both matter, but authorisation becomes the decisive control once identity has been verified. Zero trust is not satisfied by strong login alone, because access must also be dynamically approved for the specific resource, session, and risk context. Mature programmes measure whether authentication outcomes are translated into tightly scoped, continuously enforced authorisation.


Technical breakdown

How the CISA maturity model turns policy into enforcement

The CISA Zero Trust Maturity Model separates intent from implementation by mapping five pillars, identity, device, network/environment, application workload, and data, to three stages: traditional, advanced, and optimal. Traditional environments rely on manual configurations and static policies. Advanced environments centralise visibility and some identity control. Optimal environments use dynamic policy assignment, continuous authentication, and observed triggers to decide access in real time. The model matters because it makes Zero Trust measurable across domains instead of treating it as a slogan. Practical implication: use the pillars to locate where access is still static and where policy remains decoupled from runtime signals.

Practical implication: Map each pillar to its current maturity stage and expose where manual policy still drives access decisions.

Identity and application workload controls are the governance pivot

Identity is not just a login event in this model. It is a set of attributes that must be continuously authenticated, and application workloads must continuously authorise access based on current conditions. That is a material shift for IAM and PAM because the control objective is no longer simply to prove who someone is, but to keep checking whether the session still deserves access. For service accounts and machine workloads, the same logic applies through workload context, not human approval. Practical implication: treat identity and workload as the two pillars that determine whether access governance is truly dynamic or only cosmetically zero trust.

Practical implication: Tie identity and workload authorisation to runtime context instead of assuming provisioning-time approval is sufficient.

Visibility, automation, and governance are the layers that make zero trust operable

CISA places the five pillars on top of visibility and analytics, automation and orchestration, and governance. That ordering is important because the model fails if organisations only add policy language without telemetry or enforcement plumbing. Visibility tells you what is happening. Automation applies the policy consistently. Governance defines who owns the exceptions and maturity decisions. Strong zero trust programmes therefore depend on auditability and policy feedback loops, not just authentication controls. Practical implication: instrument access changes and runtime decisions so governance can measure whether the zero trust model is actually being enforced.

Practical implication: Build telemetry and orchestration around access decisions so governance can verify enforcement rather than assume it.


Threat narrative

Attacker objective: The objective is to reach protected infrastructure and data through access paths that were never re-evaluated as conditions changed.

  1. Entry occurs when access is granted through static entitlement or trust assumptions that are wider than the current session requires.
  2. Privilege escalation happens when identity, workload, or data access remains valid after the original risk context has changed.
  3. Impact follows when overly persistent access lets an attacker or unauthorized user reach infrastructure, applications, or data without continuous revalidation.
  • Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Zero trust changes access governance because it replaces entitlement permanence with session-bound verification. That is not just a tighter control posture, it is a different operating assumption for identity and privilege. Programmes built around periodic review and standing access have to reorient around continuous decision points, or they will keep certifying controls that the model has already made obsolete.

Identity is the primary zero trust control plane, but it cannot stand alone. The maturity model is structured around identity, device, network/environment, application workload, and data because access decisions only become trustworthy when those layers reinforce one another. For NHI and human IAM teams alike, that means access governance must align policy, telemetry, and enforcement instead of treating identity as a separate administrative function.

Access review becomes a weaker control when runtime conditions change faster than review cycles. The model’s emphasis on dynamic policy exposes the limits of access certification for ephemeral or rapidly shifting access states. Practitioners should read that as a governance signal: the more dynamic the environment, the less value there is in controls that only look backward.

Session-level enforcement is the named concept that access governance has to absorb. Traditional governance assumes access can be assigned, observed, and recertified over time. In zero trust, access is expected to be validated in the moment of use, which means the programme must measure runtime authorisation quality, not just entitlement completeness.

CISA’s model validates the direction of modern identity security without simplifying the work. The model gives agencies a shared language for maturity, but it also exposes how many organisations still rely on legacy systems that conflict with dynamic policy. The practical conclusion is that zero trust is a governance redesign exercise, not a single control deployment.

From our research library:

What this signals

Session-bound access is the practical dividing line between zero trust theory and governance reality. When organisations still certify broad entitlements after the fact, they are measuring a state that zero trust has already discarded. The more dynamic the environment becomes, the more access governance has to move upstream into issuance and runtime enforcement.

Zero trust does not eliminate identity governance, it makes governance more operationally specific. Teams need to decide where continuous authentication, workload authorisation, and data-layer controls are already enforced and where policy still depends on manual intervention. That gap is where most maturity claims will prove weakest.

Continuous verification is now the control pattern that connects human IAM, NHI access, and workload identity. The same programme logic applies across all three: narrow access, validate context, and make revocation observable before privilege becomes an inherited assumption.


For practitioners

  • Map each pillar to a maturity stage Assess identity, device, network/environment, application workload, and data separately so you can see where static policy still dominates and where dynamic enforcement already exists.
  • Rebuild access reviews around runtime signals Stop treating recertification as the primary proof of control effectiveness when access is session-scoped and continuously revalidated.
  • Align PAM with zero standing privilege Remove standing access where possible and tie elevation to session context so privileged use remains auditable and narrow.
  • Instrument workload authorisation decisions Track when application workloads are allowed to request or use resources, then compare those decisions to observed runtime risk.

Key takeaways

  • Zero trust maturity redefines access governance by making runtime verification more important than static entitlement ownership.
  • The model’s five pillars show that identity alone is not enough to establish trustworthy access decisions.
  • Practitioners should use the maturity model to find where manual policy still drives access and replace it with continuous enforcement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on dynamic access governance and entitlement control across zero trust pillars.
Recommendation — Map zero trust maturity to PR.AA-05 and remove static entitlements that outlive current risk context.
NIST Zero Trust (SP 800-207)Zero Trust Architecture — Zero Trust ArchitectureThe article is explicitly about CISA's maturity model built on NIST zero trust principles.
Recommendation — Use NIST 800-207 to structure access decisions around continuous verification and context-aware policy.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeZero trust maturity depends on shrinking persistent access and reducing excess privilege scope.
Recommendation — Apply AC-6 to minimise standing privilege and narrow access to the minimum needed for each session.
CIS Controls v8CIS-5 — Account ManagementThe article focuses on managing account access as a moving control rather than a static entitlement.
Recommendation — Use CIS-5 to govern account lifecycle and remove stale access that undermines zero trust enforcement.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article's workload and access model applies directly to machine identities that retain more access than they need.
Recommendation — Review service and workload identities for overprivilege and reduce any access that exceeds current task scope.

Key terms

  • Zero Trust: A security model that assumes no identity, human or non-human, should be trusted by default, even inside a network perimeter. Every access request must be verified, authorised, and continuously validated.
  • Zero Trust Maturity Model: A maturity model is a staged way to measure how fully an organisation has adopted a security approach. In this case, the model describes how access governance moves from static controls to dynamic, continuously verified enforcement across identity, device, network, workload, and data domains.
  • Session-bound Access: Session-bound access is access that exists only for a specific activity window and then disappears. In OT governance, it is the right pattern for remote support because it reduces persistent exposure, improves accountability, and fits the operational reality of maintenance and incident response.
  • Dynamic policy enforcement: The practice of making access decisions using current signals such as identity posture, device health, workload context, or data sensitivity. It replaces fixed rules and coarse entitlements with controls that can change as the environment changes.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org