Zero Trust Is Mature on Paper, Not Yet in Practice
Two of the most cited references for building a Zero Trust Architecture come from very different places. One is CISA's Zero Trust Maturity Model, version 2.0, published April 2023 to help U.S. federal agencies comply with Executive Order 14028. The other is Microsoft's own Zero Trust Maturity Model, a vendor vision paper meant to help any enterprise self assess its readiness. Reading both side by side, then checking what actually happened once the U.S. government's own deadline arrived, gives a clean answer to the question this piece is built to test. Has Zero Trust matured as a concept faster than it has matured as a practice? Based on both documents and what followed, the answer is yes, and the gap is wide.
Two Models, Two Different Maps of the Same Idea
Both documents trace back to the same root, NIST Special Publication 800-207, and its seven tenets of Zero Trust. But once each organization turns those tenets into a maturity model, the structures diverge.
CISA's ZTMM organizes maturity around five pillars: Identity, Devices, Networks, Applications and Workloads, and Data. Underneath all five sit three cross cutting capabilities: Visibility and Analytics, Automation and Orchestration, and Governance. Progress runs across four stages: Traditional, Initial, Advanced, and Optimal.
Microsoft's model groups the same ground into six foundational elements: identities, devices, applications, data, infrastructure, and networks, built on three guiding principles stated directly in the paper: verify explicitly, use least privileged access, and assume breach. Its maturity ladder has only three rungs, Traditional, Advanced, Optimal. There is no separate Initial stage. What CISA treats as two distinct steps of progress, Microsoft folds into one.
That mismatch matters more than it looks. If the two most referenced maturity models in the field, one written by the government agency responsible for federal compliance and the other by the largest enterprise security vendor, cannot agree on how many stages maturity even has, that alone signals the field has not settled on a single definition of "mature." The pillars are similar in spirit. The staging is not.
What "Optimal" Actually Asks For
Reading the Optimal column in both documents shows how high the bar really sits.
CISA describes Optimal identity management as continuous validation and risk analysis, enterprise wide identity integration, and tailored access assigned automatically as needed. Optimal automation and orchestration means an agency's response activities adjust dynamically to enterprise wide change with no manual intervention. Optimal data management means data is inventoried continuously, encrypted even while in use, and access is granted dynamically on a just-in-time, just-enough basis.
Microsoft's Optimal stage reads almost the same way in different words. Cloud identity with real-time analytics dynamically gates access to applications, workloads, networks, and data. Trust is removed from the network entirely. Automatic threat detection and response replaces manual triage.
Then Microsoft says something worth sitting with. Describing where organizations typically sit if they have not yet started their Zero Trust journey, the paper places them squarely in Traditional: on-premises identity with static rules and some single sign-on, limited visibility into device compliance and cloud logins, and a flat network that leaves broad risk exposure. That is not a hypothetical laggard. According to the vendor writing the maturity model, that description fits most organizations today.
CISA's Own List of What the Model Does Not Cover
The CISA document is unusually candid about its own limits. It states plainly that the model does not address activities related to incident response specifics, logging, monitoring, alerting, forensic analysis, or recovery in any detail. It does not cover challenges specific to operational technology, certain classes of IoT devices, or the broader incorporation of emerging technology such as deception platforms and authenticated web application firewalls. Recommendations for incorporating machine learning and artificial intelligence into Zero Trust solutions are also left out of the model entirely.
The same document lists the practical friction agencies actually face. Legacy systems built on implicit trust, where access is checked rarely and only against fixed attributes, directly conflict with the model's core idea of adaptive, continuous trust evaluation, and changing them takes real investment. Zero Trust adoption also needs buy-in from senior leadership, IT staff, data owners, system owners, and end users all at once, which means agencies moving from siloed IT services to one coordinated architecture and governance policy. Agencies also start this journey from very different points, so no two paths look alike.
None of this is hidden in the document. CISA wrote the gaps into its own maturity model. That is a government agency admitting, inside its own reference architecture, that the paper model is ahead of what most organizations can currently execute.
The Deadline That Came and Went
This is where the gap stops being theoretical. OMB Memorandum M-22-09, issued in January 2022 under Executive Order 14028, set a hard deadline: every federal civilian executive branch agency was required to meet specific Zero Trust objectives by the end of fiscal year 2024, September 30, 2024. CISA's ZTMM exists specifically to help agencies get there.
Gartner's own forecast for the sector projected that three out of every four U.S. federal agencies would still fall short of fully implementing zero trust security policies past 2026, largely because of funding gaps and a shortage of qualified staff, and pointed to congressional budget delays as part of the cause, since money for the initiative often was not available until partway through the fiscal year, leaving agencies only a partial year to reach their goals. On the Department of Defense side, the Pentagon's own roadmap toward zero trust lists 152 separate activities targeted for completion by fiscal year 2027, and only about one in seven of them had actually been finished by late 2024, with the weakest spots concentrated in identity and access management and in how data gets tagged, two of the same pillars both CISA and Microsoft treat as foundational.
The deadline itself did not disappear quietly. The underlying executive order and OMB memo were never withdrawn. Rather than close the file, OMB rolled the requirement forward twice more through new guidance issued in mid-2024 and again in January 2025, each time telling agencies to keep maturing their architecture rather than declaring the job finished, with FISMA reporting continuing to measure progress against the same pillars but no new date attached to any of it. A fixed deadline turned into an open-ended, annually measured metric. That is what happens when the practice does not catch up to the paper model in time.
Automation Is Where Both Models Agree the Real Bottleneck Sits
Set the two documents next to each other one more time and a pattern jumps out. Both agree the hardest thing to mature is not identity or devices, the two pillars agencies tend to tackle first, but automation and orchestration.
CISA's Traditional stage for this cross cutting capability describes agencies relying on static and manual processes with limited automation. Its Optimal stage requires orchestration and response activities that dynamically adjust to enterprise wide change on their own. Microsoft's list of six tools needed to drive implementation puts automation and intelligence and AI near the top, describing the goal as automated alerting and remediation that reduces mean time to respond, powered by cloud intelligence reading every available signal in real time.
The DoD gap data lines up with this exactly. The pillars furthest behind, identity and access management and data tagging, are also the ones that depend most heavily on automated, cross system enforcement rather than a single tool or policy update. Getting a maturity model onto paper does not automate anything by itself.
Mature on Paper, Not Yet in Practice
Put the two documents together and the taxonomy of Zero Trust looks settled. A government security agency and the world's largest enterprise software vendor, working independently, converge on nearly the same five or six pillars, the same idea of a staged journey from static, manual, perimeter based security to dynamic, automated, identity centric security, and the same debt to NIST SP 800-207's seven tenets. On paper, there is very little left to argue about.
What is not settled is everything CISA admits its own model leaves out, and everything the OMB deadline exposed once agencies actually tried to hit it. A projected three in four failure rate, a Defense Department roadmap barely one seventh complete against its own target, and a hard compliance date quietly turned into an indefinite metric all point at the same conclusion. Zero Trust is mature on paper. It is not yet mature in practice.
*This article is based on an analysis of CISA's Zero Trust Maturity Model, Version 2.0 (April 2023), Microsoft's Zero Trust Maturity Model vision paper, and current reporting on U.S. federal zero trust implementation progress against the OMB M-22-09 deadline.*
Try Yurlie Online Developer Tools
Run CIDR calculations, JSON formatting, Base64 encoding, and UUID generation instantly in your browser.
