Skip to content

CISA Has Five Zero Trust Pillars. DoD Has Seven. Which Is Your Assessment Using?

By Donovan Brown
August 25, 2026
12 sections
US flag for federal compliance — CMMC, NIST, ITAR
Photo: Pang Yuhao on Unsplash

Seven pillars, eight, five. The counts differ because assessments quote different federal documents. Here is what CISA v2.0 actually says, and the order that works for a Texas business.

01

Introduction

A vendor sends you a zero trust readiness assessment. It scores you across seven pillars. A second vendor shows up with eight. The federal model everyone cites in the marketing copy has five. Nobody is lying. They are quoting different source documents, and one of them was written for an environment that looks nothing like a Texas engineering firm with a shared drive full of CAD files.

02

CISA's model has five pillars, and the wording is fixed

The Cybersecurity and Infrastructure Security Agency published Zero Trust Maturity Model version 2.0 in April 2023. It is still the current version. It has five pillars, named exactly this way:

IdentityWho is asking, and how strongly did you prove it
DevicesWhat hardware is asking, and do you know its state
NetworksHow traffic is segmented, encrypted, and controlled
Applications and WorkloadsHow apps are accessed, tested, and monitored
DataWhat you hold, where it lives, and who can reach it

That is the whole list. If an assessment uses different pillar names and still calls itself CISA-aligned, someone paraphrased. The document is public at cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf and it reads in an afternoon.

03

Where "eight pillars" comes from

CISA also defines three cross-cutting capabilities: Visibility and Analytics, Automation and Orchestration, and Governance. These are not extra pillars. They mature inside every pillar. Identity has a governance dimension. Data has a visibility dimension. The model is a grid, not a row.

Flattening those three out to sit beside the five is how people arrive at eight. Not a catastrophe, but it usually means the questionnaire was built from a summary article rather than the PDF.

04

Four stages, and an easy way to spot a stale assessment

Version 2.0 defines four maturity stages: Traditional, Initial, Advanced, Optimal. Version 1.0, from 2021, had three. CISA added Initial because the jump from Traditional straight to Advanced was too wide to budget against.

One genuine source of confusion: CISA's own prose refers to the three stages of the zero trust maturity journey. Four named stages, three transitions between them, both statements in the same document. The practical test is simpler. If the assessment in your hand scores every control as Traditional, Advanced, or Optimal, it is quoting the superseded 2021 version. Ask why.

05

The seven-pillar model is a real document, for a different reader

Seven pillars means the Department of Defense Zero Trust Reference Architecture. It is a legitimate framework, written for an environment with classification levels, mandated credential types, and adversaries funded by other governments.

Run against a 200-person distributor, a large share of the controls map to nothing you own. If no federal contract obligates you to the DoD architecture, the CISA model is the shorter path to a defensible plan. If one does, you already know it, and seven pillars is the right assessment.

06

Microsegmentation sits at Optimal, which is the last stage

This is the most useful thing in the CISA model and the most frequently ignored.

Microsegmentation lives at the Optimal maturity stage. Not the entry point. The reason is practical: you cannot safely enforce which workloads may talk to which until you already know what you have and what currently talks to what. Skip the inventory and the traffic baseline and a segmentation project produces one of two results. Either the rules are so permissive they prove nothing, or an undocumented line-of-business application breaks at 7am on a Monday and stays broken until someone finds the flow.

NIST SP 800-207, the publication that actually defines zero trust, names three deployment approaches: enhanced identity governance, micro-segmentation, and network infrastructure with software-defined perimeters. Identity governance is listed first for the same reason. It is the approach you can start on without knowing everything else first.

07

Zero trust is not a product, and no product is certified

SP 800-207 contains no vendor names. None. That is deliberate.

NIST does publish a companion, SP 1800-35, finalized 10 June 2025, documenting 19 working zero trust architectures built from commercially available products with 24 collaborating vendors. Useful reading. It is a practice guide, not a standard, and NIST does not endorse the products in it. When a salesperson says a platform is NIST-approved for zero trust, that is the document being stretched. No such approval exists.

08

What three years of a funded federal mandate actually delivered

CISA's FY2024 Report to Congress, dated 29 January 2025, is the closest thing to an honest scoreboard anyone has published. Federal agencies had a mandate, a deadline, and appropriated money. After three years, the headline wins were asset visibility and encrypted DNS:

  • Agencies with over 90% hardware asset coverage rose from 33% to 55%
  • Software asset coverage over 90% rose from 18% to 39%
  • Devices classed Unknown or Uncategorized fell from 55% to under 5%
  • 92% of agencies onboarded to Protective DNS

CISA's own characterization is "considerable advancements". The report does not certify that agencies met the M-22-09 goals. The blockers it names are vendor support, legacy technology, and funding, familiar to anyone who has tried to retire an application one department cannot work without.

Read that as sequencing, not failure. Asset visibility is a precondition for zero trust, not zero trust itself. Organizations with more resources than yours spent three years mostly finding out what they owned. Budget accordingly, and be skeptical of a roadmap that has you enforcing policy in quarter two.

09

A defensible first year for a Texas business

Nothing below is from CISA. It is the order that survives contact with a real environment.

  • Identity first. Phishing-resistant MFA on administrative accounts, then everyone. Kill shared logins. Inventory who holds privileged access and why. Highest ratio of risk removed to dollars spent, every time.
  • Devices second. A hardware and software inventory that updates itself. You cannot enforce device posture on machines you cannot list.
  • Data third. Find where the regulated or contract-sensitive material actually lives. It is rarely only where the policy says.
  • Networks and workloads last. Segmentation designed from observed traffic, not from a diagram someone drew in 2019.

Visibility, automation, and governance improve across all four, which is how CISA intends the cross-cutting capabilities to work.

10

The honest limitation

Neither model tells you what to fund first. Both are scoring rubrics. They tell you where you sit on a scale. They do not tell you which gap costs the most if exploited, which is cheapest to close, or which one your insurance carrier asks about at renewal. That judgment is contextual, and it is the part a questionnaire cannot do.

Treat the score as an input. An assessment that hands you a color-coded grid and no sequenced, costed remediation plan has finished about half the job. Ask which pillar the assessor would fund first with your money, and why. The answer tells you more than the grid does.

11

Frequently Asked Questions

How many pillars does the CISA Zero Trust Maturity Model have?

Five: Identity, Devices, Networks, Applications and Workloads, and Data. It also defines three cross-cutting capabilities, Visibility and Analytics, Automation and Orchestration, and Governance, which mature inside each pillar rather than sitting beside them. Counting those as pillars produces the eight-pillar version you sometimes see.

Is a seven-pillar zero trust assessment wrong?

No. Seven pillars is the Department of Defense Zero Trust Reference Architecture, a real framework written for environments with classification levels and mandated credentials. If you have no obligation to the DoD architecture, the CISA model maps more cleanly to a commercial business.

What are the four CISA maturity stages?

Traditional, Initial, Advanced, and Optimal. Version 1.0 of the model, from 2021, had only three; version 2.0 added Initial in April 2023. An assessment that scores you on three stages is working from the superseded version.

Should we start with microsegmentation?

Almost certainly not. CISA places microsegmentation at the Optimal stage, the last one. You cannot enforce which workloads may talk to which until you know what you have and what currently talks to what, so an asset inventory and a traffic baseline come first. Starting with segmentation usually yields either rules too permissive to matter or an outage in an undocumented application.

Do we need to buy a zero trust product?

There is no certified zero trust product. NIST SP 800-207, which defines the concept, names no vendors at all. NIST SP 1800-35, finalized in June 2025, documents 19 working architectures built with commercially available products from 24 collaborating vendors, but it is a practice guide and NIST does not endorse those products. Zero trust is an architecture and a set of operating habits, built partly from tools you already own.

Where does a 20 to 500 person company realistically start?

Identity and asset visibility. Federal agencies working under a funded mandate spent three years, and their clearest measured gains were in exactly those two areas. Phishing-resistant MFA, elimination of shared administrative accounts, and an inventory that updates itself will move your risk further in six months than any segmentation project.

12

Getting a second read on your assessment

If someone handed you a zero trust score and you are not sure which document it came from, that is worth checking before you commit budget. We read these against the actual CISA v2.0 text through our cybersecurity practice, and the sequencing question usually matters more than the score. When the remediation work needs an owner, it sits alongside managed IT services. If you want a baseline first, start with the free IT assessment.

Call 713-571-2390 to talk it through with someone in Texas. 20+ years of experience, 100% Texas-based support, offices in The Woodlands and Round Rock.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call