Skip to main content

Zero Trust Maturity

Assess your organization's Zero Trust posture against the CISA Zero Trust Maturity Model (ZTMM).

Overview​

Zero Trust is a security framework that eliminates implicit trust and continuously validates every stage of digital interaction. Infracast automatically evaluates your infrastructure against CISA's Zero Trust Maturity Model, providing visibility into your progress across all five pillars.

The Five Pillars​

1. Identity​

Verify users and devices before granting access.

What we assess:

  • Multi-factor authentication coverage
  • Identity provider integration
  • Privileged access management
  • Session management and timeout policies
  • Identity lifecycle automation

2. Devices​

Ensure devices meet security requirements before access.

What we assess:

  • Device inventory completeness
  • Endpoint protection status
  • Configuration compliance
  • Patch management currency
  • Mobile device management

3. Networks​

Segment and monitor network traffic.

What we assess:

  • Network segmentation implementation
  • Micro-segmentation readiness
  • Encrypted communications
  • Network monitoring coverage
  • Firewall rule hygiene

4. Applications & Workloads​

Protect applications and secure workload communications.

What we assess:

  • Application inventory
  • Workload protection coverage
  • Container security posture
  • API security controls
  • Code signing and integrity

5. Data​

Protect data at rest and in transit.

What we assess:

  • Data classification coverage
  • Encryption at rest
  • Encryption in transit
  • Data loss prevention controls
  • Backup and recovery posture

Maturity Levels​

Each pillar is scored 0–100 and mapped to one of four CISA ZTMM maturity levels:

LevelScore bandDescription
Traditional0–37Perimeter-based security with static policies
Initial38–62Some Zero Trust principles adopted, manual processes
Advanced63–87Automated policies, centralized visibility, dynamic access
Optimal88–100Fully automated, adaptive policies, continuous verification

How scores are calculated​

Every control starts from a baseline of 50 (the bottom of "Initial"). Findings and positive indicators then move it:

  • Each mapped finding applies its impact ×10. A high-impact finding is -2, so it costs the control 20 points; a lower-impact finding is -1, costing 10.
  • Each positive indicator detected on your infrastructure adds +10.
  • The control score is clamped to 0–100, then mapped to a level using the bands above.

A pillar score is the average of its five control scores, and the overall score is the average across the five pillars.

Control scores and pillar scores are not the same thing

A single high-impact finding costs 20 points on that one control — not 20 points on the pillar. Because a pillar averages five controls, the same finding moves the pillar by about 4 points. This distinction matters when you are predicting how much remediation is needed to cross a level boundary. Scoring constants are implementation-defined and accurate as of 2026-09-14; re-check the implementation rather than quoting these values if you are building automation against exact scores.

Controls​

Infracast assesses 25 controls across the 5 pillars (5 per pillar):

Identity Controls​

  • ID-1: Identity Providers (centralized IdP, SSO)
  • ID-2: Multi-Factor Authentication (phishing-resistant MFA)
  • ID-3: Privileged Access Management (PAM, JIT access)
  • ID-4: Identity Governance (access reviews, RBAC)
  • ID-5: Risk-Based Access (conditional access policies)

Device Controls​

  • DV-1: Device Inventory (comprehensive asset tracking)
  • DV-2: Device Health Assessment (compliance scoring)
  • DV-3: Endpoint Detection & Response (EDR/XDR)
  • DV-4: Patch Management (automated patching SLAs)
  • DV-5: Mobile Device Management (MDM/MAM)

Network Controls​

  • NW-1: Network Segmentation (micro-segmentation, SDP)
  • NW-2: Traffic Encryption (TLS 1.3, mTLS)
  • NW-3: Network Visibility (flow logs, NDR)
  • NW-4: DNS Security (DoH/DoT, threat blocking)
  • NW-5: Zero Trust Network Access (ZTNA vs VPN)

Application Controls​

  • AP-1: Application Inventory (discovery, SBOM)
  • AP-2: Secure Development (SAST/DAST, DevSecOps)
  • AP-3: Container Security (image scanning, runtime)
  • AP-4: API Security (authentication, gateways)
  • AP-5: Workload Protection (CWPP, CSPM)

Data Controls​

  • DA-1: Data Classification (automated labeling)
  • DA-2: Data Encryption (at rest, in transit)
  • DA-3: Data Loss Prevention (DLP policies)
  • DA-4: Data Access Controls (ABAC, JIT access)
  • DA-5: Backup & Recovery (immutable backups, DR)

OMB M-22-09 Compliance​

For federal agencies, Infracast maps assessments directly to OMB Memorandum M-22-09 requirements for Zero Trust implementation by end of FY2024.

Tracked requirements include:

  • Enterprise-wide identity management
  • Phishing-resistant MFA
  • Device inventory and EDR
  • DNS encryption
  • Application security testing

Using Zero Trust Assessment​

  1. Go to Security → Zero Trust Maturity
  2. View your overall score and pillar breakdown

Understand Your Score​

  • Each pillar shows a maturity level (Traditional → Optimal)
  • Overall score aggregates all pillars
  • Color coding indicates areas needing attention

Improve Your Score​

  1. Click on any pillar to see specific findings
  2. Review recommended improvements
  3. Address findings in priority order
  4. Re-run assessment to track progress

Reports​

Generate Zero Trust maturity reports for:

  • Executive summaries
  • Technical assessments
  • OMB M-22-09 compliance status
  • Progress tracking over time, from your saved score history

Reports can be exported as PDF, Word, or Markdown.

Score history​

Infracast saves your Zero Trust assessments so you can see how your score changes over time.

  • When points are saved: whenever you run an assessment (POST .../zerotrust/assess), and automatically about once an hour when your tenant's data has changed, with at least one point per day. At most one point is saved per tenant per hour.
  • Score History card: the Zero Trust page charts your overall score and the five pillar scores over time. It shows "not enough history yet" until there are at least two saved points.
  • History endpoint: GET /api/v1/tenants/{tenantID}/zerotrust/history?days=N returns points from the last N days (default 90, maximum 3650), ordered oldest to newest. The response includes:
    • source — stored when the points come from saved history, or live when there are no saved points in the window yet. A live response is a single current assessment, not a trend.
    • days — the window that was applied.
    • truncated — true if more points matched than one response can hold (the newest are kept).

API Endpoints​

Tenant-scoped assessment endpoints:

GET  /api/v1/tenants/{tenantID}/zerotrust/assessment       # latest assessment
POST /api/v1/tenants/{tenantID}/zerotrust/assess # run a new assessment
GET /api/v1/tenants/{tenantID}/zerotrust/omb-compliance # OMB M-22-09 status
GET /api/v1/tenants/{tenantID}/zerotrust/history?days=N # saved score history (default 90 days)

The pillar and control catalog is reference data and is not tenant-scoped:

GET /api/v1/zerotrust/pillars
GET /api/v1/zerotrust/pillars/{pillarID}
GET /api/v1/zerotrust/controls
GET /api/v1/zerotrust/controls/{controlID}

Availability​

Zero Trust Maturity is an Enterprise feature. It is included in Enterprise, Enterprise Pro, and Government tiers, and in trials.

Best Practices​

  1. Start with Identity — MFA and identity management provide the highest impact
  2. Focus on Critical Systems — Prioritize your most sensitive applications first
  3. Track Progress — Run assessments monthly to measure improvement
  4. Align with Business — Map technical controls to business risk tolerance