
What the document says
NIST's Special Publication 800-207, finalised 11 August 2020, defines zero trust architecture around seven tenets rather than one technical control. It treats every data source and computing service as a resource; it requires that all communication be secured regardless of network location, so being inside a corporate network no longer implies trust; and it grants access to a resource per session, evaluated before it is given, without automatically extending to a different resource. Access decisions draw on dynamic policy covering the identity, device state and behaviour of the requester rather than a static rule tied to where the request comes from. The remaining tenets require an enterprise to continuously monitor the security posture of every asset, enforce authentication and authorisation dynamically before each access, and collect telemetry to keep improving that posture over time. NIST states plainly that zero trust is a set of guiding principles for workflow, system design and operations rather than a single architecture, and that moving toward it cannot be accomplished with a wholesale replacement of technology. The Cybersecurity and Infrastructure Security Agency's maturity model, built around five pillars and three cross-cutting capabilities, gives federal agencies a way to measure incremental progress toward those tenets rather than a pass-or-fail state.
Confidence and limits
This description rests on NIST's own published text, the authoritative statement of what the tenets are and how the document frames them. CISA's maturity model is a separate federal implementation aid, not a restatement of SP 800-207 itself, so the two are treated here as complementary rather than a single source. Because SP 800-207 is a living reference document rather than a report on an event, this description reflects the text as retrieved on 16 September 2026.
Why it mattered
Before 2020, zero trust was mostly a vendor marketing term with no common technical definition, which made it hard for a buyer to compare products or hold a vendor to a specific claim. By publishing seven concrete tenets and stating that the change is architectural rather than a purchase, NIST gave procurement teams and auditors a shared reference to check vendor claims against, and gave agencies a basis for later federal zero trust mandates.
Defensive takeaway
When evaluating a product marketed as zero trust, ask which of the seven tenets it actually enforces, for example per-session authorisation or continuous device posture checks, and treat any remaining tenets as work your own organisation still has to do.
- Does access to one resource in our environment still implicitly grant access to another?
- Do we treat a device or user on our internal network as more trusted than one connecting remotely?
- Could we show, with logs, that an access decision was evaluated per session rather than granted once and left standing?
SP 800-207 does not certify any product or organisation as zero trust; it describes a direction of travel. Most enterprises, as the document itself notes, will run in a hybrid state between perimeter defence and zero trust for years, which makes the tenets a checklist for gradual investment rather than a one-time deployment.
Before buying a product marketed as zero trust, check which of the seven NIST tenets it actually implements and which ones still depend on your own policy, identity and monitoring work.
NIST's own published text establishes the tenets and the document's framing of zero trust as an architecture rather than a product; CISA's maturity model corroborates how a federal agency is expected to apply it, but the two describe complementary, not identical, frameworks.
Sources & reading trail
Full text of the seven zero trust tenets and the statement that zero trust is an architecture, not a single technology purchase.
standards-body · Source published: 11 August 2020 · Retrieved: 16 September 2026
CISA's maturity model describing five pillars agencies use to measure progress toward the NIST tenets.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.