Zero Trust Maturity
Assess your organization's Zero Trust posture against the CISA Zero Trust Maturity Model (ZTMM).
Overview
Zero Trust is a security framework that eliminates implicit trust and continuously validates every stage of digital interaction. Infracast automatically evaluates your infrastructure against CISA's Zero Trust Maturity Model, providing visibility into your progress across all five pillars.
The Five Pillars
1. Identity
Verify users and devices before granting access.
What we assess:
- Multi-factor authentication coverage
- Identity provider integration
- Privileged access management
- Session management and timeout policies
- Identity lifecycle automation
2. Devices
Ensure devices meet security requirements before access.
What we assess:
- Device inventory completeness
- Endpoint protection status
- Configuration compliance
- Patch management currency
- Mobile device management
3. Networks
Segment and monitor network traffic.
What we assess:
- Network segmentation implementation
- Micro-segmentation readiness
- Encrypted communications
- Network monitoring coverage
- Firewall rule hygiene
4. Applications & Workloads
Protect applications and secure workload communications.
What we assess:
- Application inventory
- Workload protection coverage
- Container security posture
- API security controls
- Code signing and integrity
5. Data
Protect data at rest and in transit.
What we assess:
- Data classification coverage
- Encryption at rest
- Encryption in transit
- Data loss prevention controls
- Backup and recovery posture
Maturity Levels
Each pillar is scored 0–100 and mapped to one of four CISA ZTMM maturity levels:
| Level | Score band | Description |
|---|---|---|
| Traditional | 0–37 | Perimeter-based security with static policies |
| Initial | 38–62 | Some Zero Trust principles adopted, manual processes |
| Advanced | 63–87 | Automated policies, centralized visibility, dynamic access |
| Optimal | 88–100 | Fully automated, adaptive policies, continuous verification |
How scores are calculated
Every control starts from a baseline of 50 (the bottom of "Initial"). Findings and positive indicators then move it:
- Each mapped finding applies its impact ×10. A high-impact finding is
-2, so it costs the control 20 points; a lower-impact finding is-1, costing 10. - Each positive indicator detected on your infrastructure adds +10.
- The control score is clamped to 0–100, then mapped to a level using the bands above.
A pillar score is the average of its five control scores, and the overall score is the average across the five pillars.
A single high-impact finding costs 20 points on that one control — not 20 points on the pillar. Because a pillar averages five controls, the same finding moves the pillar by about 4 points. This distinction matters when you are predicting how much remediation is needed to cross a level boundary. Scoring constants are implementation-defined and accurate as of 2026-09-14; re-check the implementation rather than quoting these values if you are building automation against exact scores.
Controls
Infracast assesses 25 controls across the 5 pillars (5 per pillar):
Identity Controls
- ID-1: Identity Providers (centralized IdP, SSO)
- ID-2: Multi-Factor Authentication (phishing-resistant MFA)
- ID-3: Privileged Access Management (PAM, JIT access)
- ID-4: Identity Governance (access reviews, RBAC)
- ID-5: Risk-Based Access (conditional access policies)
Device Controls
- DV-1: Device Inventory (comprehensive asset tracking)
- DV-2: Device Health Assessment (compliance scoring)
- DV-3: Endpoint Detection & Response (EDR/XDR)
- DV-4: Patch Management (automated patching SLAs)
- DV-5: Mobile Device Management (MDM/MAM)
Network Controls
- NW-1: Network Segmentation (micro-segmentation, SDP)
- NW-2: Traffic Encryption (TLS 1.3, mTLS)
- NW-3: Network Visibility (flow logs, NDR)
- NW-4: DNS Security (DoH/DoT, threat blocking)
- NW-5: Zero Trust Network Access (ZTNA vs VPN)
Application Controls
- AP-1: Application Inventory (discovery, SBOM)
- AP-2: Secure Development (SAST/DAST, DevSecOps)
- AP-3: Container Security (image scanning, runtime)
- AP-4: API Security (authentication, gateways)
- AP-5: Workload Protection (CWPP, CSPM)
Data Controls
- DA-1: Data Classification (automated labeling)
- DA-2: Data Encryption (at rest, in transit)
- DA-3: Data Loss Prevention (DLP policies)
- DA-4: Data Access Controls (ABAC, JIT access)
- DA-5: Backup & Recovery (immutable backups, DR)
OMB M-22-09 Compliance
For federal agencies, Infracast maps assessments directly to OMB Memorandum M-22-09 requirements for Zero Trust implementation by end of FY2024.
Tracked requirements include:
- Enterprise-wide identity management
- Phishing-resistant MFA
- Device inventory and EDR
- DNS encryption
- Application security testing
Using Zero Trust Assessment
Navigate to Zero Trust
- Go to Security → Zero Trust Maturity
- View your overall score and pillar breakdown
Understand Your Score
- Each pillar shows a maturity level (Traditional → Optimal)
- Overall score aggregates all pillars
- Color coding indicates areas needing attention
Improve Your Score
- Click on any pillar to see specific findings
- Review recommended improvements
- Address findings in priority order
- Re-run assessment to track progress
Reports
Generate Zero Trust maturity reports for:
- Executive summaries
- Technical assessments
- OMB M-22-09 compliance status
- Progress tracking over time, from your saved score history
Reports can be exported as PDF, Word, or Markdown.
Score history
Infracast saves your Zero Trust assessments so you can see how your score changes over time.
- When points are saved: whenever you run an assessment (
POST .../zerotrust/assess), and automatically about once an hour when your tenant's data has changed, with at least one point per day. At most one point is saved per tenant per hour. - Score History card: the Zero Trust page charts your overall score and the five pillar scores over time. It shows "not enough history yet" until there are at least two saved points.
- History endpoint:
GET /api/v1/tenants/{tenantID}/zerotrust/history?days=Nreturns points from the lastNdays (default 90, maximum 3650), ordered oldest to newest. The response includes:source—storedwhen the points come from saved history, orlivewhen there are no saved points in the window yet. Aliveresponse is a single current assessment, not a trend.days— the window that was applied.truncated—trueif more points matched than one response can hold (the newest are kept).
API Endpoints
Tenant-scoped assessment endpoints:
GET /api/v1/tenants/{tenantID}/zerotrust/assessment # latest assessment
POST /api/v1/tenants/{tenantID}/zerotrust/assess # run a new assessment
GET /api/v1/tenants/{tenantID}/zerotrust/omb-compliance # OMB M-22-09 status
GET /api/v1/tenants/{tenantID}/zerotrust/history?days=N # saved score history (default 90 days)
The pillar and control catalog is reference data and is not tenant-scoped:
GET /api/v1/zerotrust/pillars
GET /api/v1/zerotrust/pillars/{pillarID}
GET /api/v1/zerotrust/controls
GET /api/v1/zerotrust/controls/{controlID}
Availability
Zero Trust Maturity is an Enterprise feature. It is included in Enterprise, Enterprise Pro, and Government tiers, and in trials.
Best Practices
- Start with Identity — MFA and identity management provide the highest impact
- Focus on Critical Systems — Prioritize your most sensitive applications first
- Track Progress — Run assessments monthly to measure improvement
- Align with Business — Map technical controls to business risk tolerance