Blog/developer

How Far Has Zero Trust Actually Evolved

By Yurlie TeamAugust 6, 20267 min read 41 views
How Far Has Zero Trust Actually Evolved

How Far Has Zero Trust Actually Evolved

Zero Trust Architecture (ZTA) has become nearly unavoidable in security vendor marketing. Behind the "never trust, always verify" slogan, though, a harder question rarely gets a data-backed answer: how far has this concept actually moved from a paper idea to something running in production? Two systematic literature reviews published in 2025, one by Gambo and Almulhem from KFUPM, the other by Mushtaq, Mohsin, and Mushtaq in the journal Sensors, give a fairly detailed answer, and both agree on the same point: ZTA has matured conceptually, but its implementation remains uneven.

From De-perimeterization to a NIST Standard

Zero Trust's roots go back further than the term itself. Gambo and Almulhem trace its origins to the early 2000s, when a group of CISOs calling themselves the Jericho Forum proposed de-perimeterization as a response to firewalls becoming unmanageable amid growing network traffic. The term "Zero Trust" itself only appeared formally in 2010, through John Kindervag's Forrester Research report "No More Chewy Centers," which laid out three founding principles: ensure all resources are accessed securely regardless of location, adopt a strict least-privilege access strategy, and inspect and log all traffic.

From there, the timeline is fairly traceable through a series of milestones. Google introduced BeyondCorp in 2014 as the first real proof of implementation at industry scale. Gartner followed with the Zero Trust eXtended framework in 2017 and the Continuous Adaptive Risk and Trust Assessment model two years later. The most decisive point came in August 2020, when NIST published Special Publication 800-207, which for the first time gave the architecture a definition treated as canonical: three core components, the Policy Engine, Policy Administrator, and Policy Enforcement Point, plus seven tenets that nearly every subsequent study now cites. A year later, Executive Order 14028 turned ZTA adoption into a policy mandate in the US, followed by CISA's Zero Trust Maturity Model the same year and its Strategic Plan in 2023.

This sequence matters because it explains why ZTA research only truly exploded after 2020, not when the term was coined a decade earlier. Regulation and standardization, not the concept itself, turned out to be the real trigger for the research wave.

A Research Boom That's Starting to Level Off

Publication trend data collected by Gambo and Almulhem from Scopus shows a sharp pattern: articles on ZTA sat near zero from 2007 through 2019, then spiked starting in 2020, nearly doubling year over year, peaking around 350 articles in 2024. Notably, the growth rate between 2023 and 2024 started to slow, a signal both authors read as an indication that research interest in the topic may be approaching a plateau.

Through their PRISMA screening process, Gambo and Almulhem narrowed 1,774 initial articles from three databases (Scopus, Web of Science, IEEE Xplore) down to 91 articles genuinely relevant to their research questions. Mushtaq and colleagues followed a similar path with a leaner scope: 100 initial records were narrowed to 74 studies spanning 2016 through 2025. Despite covering different scopes, the two reviews reinforce each other's findings since both followed the same PRISMA methodology.

Where Zero Trust Has Actually Spread

One of the most useful contributions from Gambo and Almulhem's review is a fairly complete taxonomy of ZTA application domains. Healthcare stands out as one of the more mature domains, driven by real incidents like the Conti ransomware attack on Ireland's health service in 2021, which crippled roughly 80 percent of the hospital system's data. Other covered domains include communication networks (5G/6G, satellite communication, corporate networks, O-RAN), the financial sector, IoT and industrial IoT, online communities and remote work, virtual environments including cloud, edge computing, and the metaverse, transport and logistics including UAV systems and FPGA supply chains, military and defense, manufacturing, and smart energy systems ranging from electric vehicles to metering infrastructure, power IoT, and power grids.

On the enabling technology side, blockchain emerges as the most frequently paired technology with ZTA, used both for implementing decentralized policy decision points and for device identity management. Behind it come machine learning and deep learning for dynamic trust evaluation, encryption, privacy-preserving techniques like differential privacy and zero-knowledge proofs, Software-Defined Networking, Secure Access Service Edge, and Zero Trust Network Access as a VPN replacement.

This spread proves one thing: ZTA has moved well beyond the enterprise network use case that was NIST's original focus. But the breadth of domain coverage becomes a problem in itself once compared against the depth of actual implementation, which is exactly what the second review exposes.

Implementation Depth Is Uneven

Mushtaq, Mohsin, and Mushtaq take a different approach that surfaces the most important part of the question this article opened with. They mapped 74 studies against nine core cybersecurity dimensions: authentication, authorization, access control, cryptography, security gateway, environmental perception, network segmentation, audit, and orchestration. The result, visualized as a heatmap, shows a consistent pattern across nearly every domain: authentication, authorization, and access control are the three dimensions most maturely implemented, especially in cloud, healthcare, and IoT.

By contrast, automated policy orchestration, environmental perception (the system's ability to read real-time context like device health or location), and lightweight cryptography for resource-constrained devices turn out to be the weakest dimensions across almost every domain, including in industrial and IoT settings that arguably need them the most. Blockchain excels at tamper-proof audit trails but is weak on real-time orchestration. AI excels at dynamic trust evaluation but still struggles with explainability, since many of its trust models remain black boxes.

This finding matters because it shows that most implementations claiming to be "Zero Trust" actually touch only three to five of the nine dimensions that would ideally be required to fully realize the "never trust, always verify" principle.

Barriers That Remain Unresolved

Both reviews also agree on a set of recurring barriers across domains. The scale and complexity of large networks is a persistent challenge, since the micro-segmentation that ZTA relies on is hard to apply to modern networks that sprawl geographically, from IoT devices to cloud resources. Legacy systems are another real obstacle, particularly in healthcare and finance, where infrastructure is often too costly to replace outright.

On cost, Gambo and Almulhem cite an estimate from Cunningham's research putting the budget needed to implement ZTA at a small, hundred-employee company at around $45,000, a figure they note has only risen with inflation and the growth of cloud distribution technology. Real-time authentication and authorization, core to the continuous verification principle, still clash with latency and user experience issues, especially in large, diverse networks.

Mushtaq and colleagues add one more specific weak point: alignment with regulatory frameworks like GDPR and HIPAA remains shallow across most implementations. Healthcare ZTA systems, for instance, are often strong on access control but rarely integrate audit mechanisms that genuinely satisfy HIPAA compliance, while IoT implementations frequently overlook the data minimization principle mandated by GDPR.

So, How Far Has It Come?

Pulling one conclusion from both reviews, the evolution reads at two different speeds. Conceptually and taxonomically, Zero Trust has matured: from the de-perimeterization idea two decades ago, to the NIST SP 800-207 standard now treated as universal reference, to spreading into nearly every sector from hospitals to electric vehicles. But in terms of implementation, the pace is far slower and far less even. Most systems claiming to be "zero trust" actually realize only a fraction of the original principle, strong on authentication and access control but weak on automated orchestration, lightweight cryptography, and regulatory compliance.

The direction of future research, as both reviews conclude, is no longer about convincing anyone that ZTA is relevant. It's about closing the gap between a taxonomy that's already complete on paper and an implementation depth that's still far from whole.

*This article is based on an analysis of two systematic literature reviews: Gambo, M. L., & Almulhem, A. (2025). "Zero Trust Architecture: A Systematic Literature Review." arXiv:2503.11659, and Mushtaq, S., Mohsin, M., & Mushtaq, M. M. (2025). "A Systematic Literature Review on the Implementation and Challenges of Zero Trust Architecture Across Domains." Sensors, 25(19), 6118.*

Total Views: 41Category: developer

Try Yurlie Online Developer Tools

Run CIDR calculations, JSON formatting, Base64 encoding, and UUID generation instantly in your browser.

Explore Tools →