simpl.
Cybersecurity GRC 17 items

Zero Trust Architecture Assessment (NIST 800-207)

Assesses maturity against the zero trust tenets and pillars defined in NIST SP 800-207 and the CISA Zero Trust Maturity Model.

NIST 800-207CISA ZTMMNIST 800-53

Free PDF · enter your email to download.

Zero Trust Tenets & Governance

  • Has the organization defined protect surfaces and mapped transaction flows for critical resources? *
  • Is access to resources granted per-session on a least-privilege basis? *
  • Are access decisions made by a policy decision point evaluating dynamic signals? *
  • Is a documented zero trust strategy and roadmap approved by leadership?

Identity Pillar

  • Is every access request authenticated regardless of network location? *
  • Is phishing-resistant MFA enforced for all users? *
  • Are risk-based and continuous authentication signals evaluated at access time? *

Device Pillar

  • Is device posture (patch level, EDR status, compliance) verified before granting access? *
  • Is a real-time inventory of all assets accessing resources maintained? *
  • Are non-compliant or unmanaged devices denied or quarantined? *

Network & Environment

  • Is the network micro-segmented so lateral movement is restricted? *
  • Is all traffic, including internal east-west, encrypted? *
  • Are software-defined perimeters or identity-aware proxies used in place of implicit trust zones?

Application, Data & Visibility

  • Are applications accessed through brokered, authenticated sessions rather than direct network exposure? *
  • Is data classified and access governed by data-centric policies? *
  • Are all access decisions and resource activity logged for analytics? *
  • Is telemetry aggregated to continuously improve policy?

Download the full Zero Trust Architecture Assessment (NIST 800-207) checklist

Get it as a clean, printable PDF — free.