By Cyber Defense Technologies October 3, 2026 4 min read
For decades, network security followed a castle-and-moat model. Anything inside the perimeter was trusted; anything outside was not. That model breaks down when users work from anywhere, applications run in the cloud, and attackers who get past the perimeter can move freely once inside.
Zero trust starts from a different assumption: the network is already hostile. No user, device or connection is trusted simply because of where it is. Every request is verified explicitly, access is limited to what is needed, and the environment is monitored for signs that something is wrong.
Where the definitions come from
- NIST SP 800-207, Zero Trust Architecture (2020), defines the core concepts, including policy decision and enforcement points that evaluate each access request.
- OMB memorandum M-22-09 (January 2022) set the federal zero trust strategy, with goals across identity, devices, networks, applications and data, including phishing-resistant MFA.
- The DoD Zero Trust Strategy (November 2022) sets a target level of zero trust for DoD components to reach by fiscal year 2027, with a more advanced level to follow, and defines the capabilities and activities needed to get there.
- CISA's Zero Trust Maturity Model describes maturity stages for each pillar and is widely used outside the federal government.
The seven pillars of the DoD Zero Trust Strategy
-
User
Verify every person with strong authentication and least-privilege access.
-
Device
Know every device and check its health before and during access.
-
Application and workload
Secure applications and the workloads that run them, wherever they are hosted.
-
Data
Label, encrypt and control the use of the information itself.
-
Network and environment
Segment networks to contain movement and limit what each connection can reach.
-
Automation and orchestration
Apply policy and respond to threats automatically and consistently.
-
Visibility and analytics
Collect and analyze activity to inform access decisions and detect threats.
The seven DoD pillars
The DoD strategy organizes zero trust into seven pillars. Each one answers a question an access decision needs to ask.
- User. Who is asking? Strong, phishing-resistant authentication, continuous evaluation of user behavior and least-privilege access.
- Device. What are they using? Device inventory, health and compliance checks before and during access.
- Application and workload. What are they reaching? Secure software development, application-level access controls and protection of workloads in data centers and clouds.
- Data. What is being protected? Data labeling, classification, encryption and controls on how data is used and shared.
- Network and environment. How is traffic contained? Micro-segmentation and software-defined controls that limit lateral movement.
- Automation and orchestration. How fast can policy respond? Automated policy decisions and response actions across tools.
- Visibility and analytics. What is happening? Centralized logging, analytics and behavior baselines that inform access decisions and detect threats.
Common misconceptions
"Zero trust is a product." Vendors sell components of zero trust, such as identity platforms, device management and micro-segmentation. No single product delivers it. Zero trust is an architecture and an operating model.
"We need to replace everything." Most organizations build zero trust by improving and integrating what they already have, prioritizing the systems and data that matter most.
"Zero trust means trusting no one." It means trusting nothing implicitly. Users still get access, but based on verified identity, device health, context and need, evaluated continuously rather than once at the door.
"Once we reach the target, we're done." Maturity models describe continuing progress. Threats, technology and missions change, and so must the controls.
Where to start
- Know your assets and data. You cannot protect what you cannot see. Build an inventory of users, devices, applications and sensitive data, and map how they connect.
- Strengthen identity. Centralize identity, enforce phishing-resistant MFA, and remove standing privileged access where possible.
- Bring device health into access decisions. Require managed, compliant devices for sensitive applications.
- Segment the network. Start with the most sensitive systems and the paths an attacker would use to reach them.
- Centralize visibility. Collect logs from identity, endpoints, networks and cloud services in one place, and use them to detect anomalies.
- Measure progress against a model. Use the DoD activities or the CISA maturity model to assess where you are, set realistic targets and track improvement.
Zero trust in classified and mission environments
Mission networks bring constraints that commercial guidance often skips: disconnected or low-bandwidth sites, legacy and embedded systems, cross-domain requirements, and strict accreditation. Zero trust principles still apply. Segmentation, strong identity, device health and continuous monitoring all strengthen classified networks. But designs must work within RMF authorization, approved products and operational realities, and changes must be planned so that security improvements do not interrupt the mission.
Frequently asked questions
Is zero trust required for contractors? Federal and DoD requirements apply directly to agencies and components. Contractors are affected through the systems they operate on behalf of the government, through contract requirements, and through the expectations of their customers.
How long does a zero trust program take? It is measured in years and implemented in stages. Early identity and visibility improvements deliver value quickly.
Does zero trust replace the need for a perimeter? Network boundaries still have value, but they are no longer the main line of defense.
How CDT can help
CDT engineers design and implement zero trust in demanding environments. Our secure architecture team plans zero trust roadmaps aligned to the DoD pillars, our classified network engineering brings those principles to accredited systems, and our penetration testing and red teaming show whether segmentation and access controls stop real attack paths.