Governance Briefing — CISA releases Zero Trust Maturity Model v2.0
CISA published Zero Trust Maturity Model version 2.0 on 11 April 2023, expanding guidance across five pillars and adding an AI/automation theme to help U.S. federal agencies plan implementations aligned with EO 14028.
On 11 April 2023 the Cybersecurity and Infrastructure Security Agency released Zero Trust Maturity Model v2.0, refining maturity stages (traditional, advanced, optimal) across identity, devices, networks, applications/workloads, and data. The update adds an automation and orchestration theme and maps capabilities to Executive Order 14028 and OMB Memorandum M-22-09 requirements.
Federal agencies and vendors supporting them should realign zero trust roadmaps, assess gaps against the revised capability sets (e.g., continuous authorization, dynamic segmentation), and incorporate automation objectives into FY2024 budget and acquisition plans.
- CISA Zero Trust Maturity Model v2.0 outlines updated capabilities, maturity levels, and automation guidance.
- CISA release notice summarizes the April 2023 updates and alignment with federal zero trust mandates.
Continue in the Governance pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Public-Sector Governance Alignment Playbook — Zeph Tech
Align OMB Circular A-123, GAO Green Book, OMB M-24-10 AI guidance, EU public sector directives, and UK Orange Book with digital accountability, risk management, and service…
-
Third-Party Governance Control Blueprint — Zeph Tech
Deliver OCC, Federal Reserve, PRA, EBA, DORA, MAS, and OSFI third-party governance requirements through board reporting, lifecycle controls, and resilience evidence.
-
Governance, Risk, and Oversight Playbook — Zeph Tech
Operationalise board-level governance, risk oversight, and resilience reporting aligned with Basel Committee principles, ECB supervisory expectations, U.S. SR 21-3, and OCC…




