Zero trust is an approach to cybersecurity that does not automatically trust a user, device, or resource because it is inside a company network or owned by the company. Instead, access is evaluated for the specific request, including the user and device, before a session to a resource is established. Businesses are rethinking perimeter-based security as employees, partners, devices, and data increasingly operate across remote, personal-device, and cloud environments.
What does zero trust mean?
Zero trust shifts security away from treating a company network as a trusted inside and everything beyond it as untrusted outside. NIST describes it as an evolving cybersecurity approach that moves defenses from static, network-based perimeters toward users, assets, and resources. A zero-trust architecture applies those principles when planning enterprise systems and workflows.
In practice, simply connecting from an office, VPN, or company-owned device does not establish trust. Authentication and authorization are separate checks that take place before access to an enterprise resource is granted. The resource might be data, an application, a service, a workflow, or an account.
Perimeter-based thinking versus zero-trust thinking
| Question | Perimeter-based assumption | Zero-trust approach |
|---|---|---|
| Does network location establish trust? | Being inside a protected network may be treated as evidence of trust. | Location alone does not establish trust; the access request is evaluated. |
| What is being protected? | The network boundary or segment is a primary focus. | Users, devices, and specific resources—including data and services—are central. |
| When is access evaluated? | Access may rely heavily on the fact that a user or device has entered the network. | Authentication and authorization are evaluated before a session to a resource is established. |
This is a change in how access decisions are made, not a claim that older security controls have no value or that zero trust makes every request safe. NIST presents an architecture and deployment models, not a single product recipe that works identically for every organization.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
Why are businesses rethinking how they stay secure?
People and devices are no longer all inside one company boundary
Remote work, bring-your-own-device use, and partners accessing business systems make it harder to rely on the office network as the dividing line between trusted and untrusted activity. A user may connect from different locations or devices, while the information they need may be hosted outside a company-owned network.
Business resources are spread across environments
Cloud services and hybrid systems distribute applications and data across on-premises infrastructure and multiple cloud environments. NIST’s 2025 implementation guide addresses authorized access in these settings, including access by a hybrid workforce and partners using different locations and devices. In that context, knowing where a request originates is less useful on its own than assessing whether that user and device should reach the particular resource.
Zero trust responds to this architectural shift; it does not guarantee that breaches will be prevented, nor does the guidance establish a typical business’s breach reduction or financial return. It also does not mean every business must replace its VPN.
What does a zero-trust program involve?
Start with business needs and important data
NIST’s SP 800-207 advises organizations to implement zero-trust principles, process changes, and technology incrementally, by use case, to protect data assets and business functions. A practical starting point is to identify important resources, who needs access to them, and which devices are involved. Then prioritize a concrete use case rather than attempting to redesign every system at once.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteRank #3
- Zero Trust Security: An Enterprise Guide
- Apress
- ABIS BOOK
Choose controls to support a specific use case
For the selected use case, assess which identity, device, and access controls can support the required decisions, and how they fit with existing systems and operations. The exact controls and rollout depend on the organization’s environment; NIST’s guidance does not prescribe one universal implementation sequence.
Use guidance appropriate to the organization
NIST SP 800-207 provides the foundational architecture, deployment models, use cases, and a high-level roadmap. NIST’s SP 1800-35, published in June 2025, documents example implementations consistent with that standard and maps principles and technologies to other security guidance. CISA’s Zero Trust Maturity Model, Version 2, is a planning aid designed to help U.S. federal agencies develop strategies and implementation plans; it is not a mandatory template for every private business.
For its 2025 practice guide, the National Cybersecurity Center of Excellence at NIST worked with 24 collaborators to integrate commercially available technology into 19 example implementations. Those figures describe the guide’s contributors and demonstrations, not measured security results or proof that a particular combination is right for every organization. NIST does not endorse a specific vendor through these examples.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Where do MFA and security keys fit?
Multi-factor authentication (MFA) requires two or more different authenticators. CISA says MFA makes unauthorized access more difficult if a password or PIN is compromised, while warning that MFA methods do not all offer the same level of security. Its October 2022 fact sheet urges organizations to use phishing-resistant MFA as part of zero-trust principles.
A FIDO2 security key is one physical-key option an organization may consider for MFA. It is one possible identity control, not a complete zero-trust architecture. Before selecting a key, check whether the organization’s accounts, devices, and identity platform support it; how users will enroll; how access can be recovered if a key is lost; and how administrators will manage deployment. CISA’s small- and medium-business guidance recommends working with the IT team to select an MFA method suited to the business.
What zero trust does—and does not—promise
- It does: shift access decisions toward the specific user, device, and resource, instead of granting implicit trust based only on network location or asset ownership.
- It does not: amount to one purchase, one authentication method, or a guarantee that attacks or breaches will stop.
- It is: an architectural approach that organizations implement incrementally around their business functions and data.
NIST SP 800-207 was published in 2020; NIST’s SP 1800-35 implementation guide followed in June 2025. CISA’s maturity-model page describes Version 2, and its phishing-resistant MFA fact sheet is dated October 2022. Organizations should check current guidance and verify compatibility and requirements in their own environment before making implementation decisions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

