Zero trust means no user, device or network location gets trusted by default. Every request to reach an application or piece of data is checked against who is asking, what device they're on and whether they need that access, and the answer is limited to that one resource. For a mid-sized company the first steps are practical ones: strong MFA everywhere, checking device health before granting access, replacing broad VPN access with per-application access, segmenting the network and logging every access decision. You don't buy zero trust. You move toward it, one pillar at a time.

What is zero trust?

The reference definition comes from NIST SP 800-207, Zero Trust Architecture, published in August 2020. Its core idea is that trust should never be granted implicitly because of network location or because the organization owns the asset. Being on the office network or connected to the VPN proves very little on its own.

SP 800-207 sets out a small number of tenets. In plain terms:

  • Every data source and service counts as a resource that needs protecting.
  • All communication is secured, whether it's on the internal network or not.
  • Access is granted per session and per resource, with the least privilege needed.
  • Access decisions use dynamic policy: identity, device state, behavior and other context.
  • The organization monitors the security posture of every device it owns or allows.
  • Authentication and authorization happen before access and are strictly enforced.
  • The organization collects telemetry and uses it to improve its security over time.

Architecturally, a policy engine decides, and a policy enforcement point sits in front of the resource and carries out that decision. Everything else in a zero trust program is about feeding better signals into that decision and putting enforcement closer to the resource.

Why does zero trust matter for mid-sized companies?

Most mid-sized networks were built on the castle-and-moat model. Once you're inside, through the office LAN or a VPN, you can reach a large share of servers and file shares. That means one stolen credential or one compromised laptop can become broad access, and lateral movement after that is often easy.

The perimeter has also thinned out. Staff work from home, core applications run in SaaS and the cloud, and contractors need access to specific systems. Zero trust fits that reality better, and it limits how far a single compromised account or device can reach.

What is the CISA Zero Trust Maturity Model?

CISA released version 2.0 of its Zero Trust Maturity Model (ZTMM) in April 2023. It was written to help US federal agencies with their zero trust plans, but it's one of the clearest yardsticks available to any organization.

The model is built on five pillars:

Pillar What it covers A sensible first step
Identity Users and service identities, authentication, access policy Single identity provider, MFA for everyone
Devices Laptops, phones, servers, IoT; inventory and health Full inventory and a minimum health standard
Networks Segmentation, traffic encryption, network access Separate users from servers, remove flat VPN access
Applications and Workloads Access to apps, secure development, app exposure Put every app behind single sign-on
Data Inventory, classification, encryption, access Identify where your sensitive data lives

Three cross-cutting capabilities run across all five pillars: Visibility and Analytics, Automation and Orchestration, and Governance.

Version 2.0 uses four maturity stages: Traditional, Initial, Advanced and Optimal. The Initial stage is new in this version, and it's useful for mid-sized organizations because it describes the early, partial progress most of us are actually making.

Where should a mid-sized company start?

Start where the risk is highest and the effort is manageable. These five steps cover the pillars that matter most early on, in roughly the order we'd tackle them.

1. Enforce strong MFA everywhere

Identity is the foundation, because every access decision starts with knowing who is asking.

  • Consolidate on one identity provider and connect as many applications as possible to it with single sign-on.
  • Require MFA for every user on every application, including "internal" ones. Access from the office network shouldn't be an exception.
  • Use the strongest methods for administrators and remote access: FIDO2/WebAuthn security keys, platform authenticators or certificate-based smart cards. In CISA's model, the Advanced and Optimal stages of the Identity pillar call for this stronger class of MFA.
  • Turn off legacy authentication protocols that can't enforce MFA. They often provide a quiet path around your policies.

Measure coverage honestly. The exceptions list, such as shared mailboxes, service accounts or an executive who asked to be excluded, is where the gaps usually sit.

2. Check device posture before granting access

A valid password and MFA from an unmanaged, unpatched laptop is still a risky request. Zero trust looks at the device as well as the user.

Start with a complete inventory of devices that access company resources. Then define a minimum posture standard, for example:

  • A supported, patched operating system
  • Disk encryption turned on
  • Endpoint protection installed and running
  • Screen lock and a local firewall enabled
  • Enrolled in your device management platform

Evaluate that posture at sign-in and use the result in your access policy. Run in report-only mode for a few weeks first so you can see who would be blocked. For personal devices, a common compromise is browser-only access to lower-risk apps with downloads restricted.

3. Replace flat VPN access with per-application access

A traditional VPN places the device on the internal network, often with reach far beyond what the user needs. Per-application access, often called zero trust network access (ZTNA), publishes each application individually through an access proxy or broker. Identity and device posture are checked on every request, and the user never gets network-level access.

A practical migration path:

  1. Move internal web applications behind an identity-aware access proxy first. These are the easiest wins.
  2. Broker administrative protocols such as SSH and RDP through a gateway that enforces MFA and logs sessions.
  3. Keep the VPN for a shrinking list of legacy applications, with tight per-group access rules.
  4. Retire VPN access for each group once its applications have moved.

A useful side effect is that published applications no longer need to accept inbound connections directly from the internet.

4. Segment the network

Per-application access reduces how much users can reach, but servers still talk to each other. Segmentation limits east-west movement if a server or account is compromised.

  • Separate user networks from server networks, and allow only the ports each application needs.
  • Put management interfaces, domain controllers and backup systems in their own restricted segments.
  • In the cloud, use security groups and network rules that deny by default.
  • Move toward workload-level microsegmentation for your most sensitive systems once the broad zones are in place.

Map your traffic flows before you write rules. Blocking something you didn't know was needed is the fastest way to lose support for the project.

5. Log every access decision

Zero trust generates a lot of useful evidence. Collect sign-in events from your identity provider, access proxy decisions, device posture results, administrative actions and cloud control plane logs in one place. Keep them long enough to investigate an incident properly.

Alert on a short list of meaningful events: a new administrator, MFA changes on privileged accounts, access granted from a non-compliant device and sign-ins at odd times or places. This is the start of the Visibility and Analytics capability, and it's also how you prove your policies work.

What about applications and data?

Don't leave these pillars for last. Build an inventory of applications, including SaaS, and connect each one to your identity provider. Remove anonymous or shared-account access wherever you find it.

For data, identify where your most sensitive information lives and who can reach it. Cloud storage and file shares with broad or public access are common findings, and fixing them early reduces exposure regardless of how far along the rest of the program is.

How do you measure zero trust progress?

Score each pillar against the four ZTMM stages. Be conservative, since partial deployment usually means Initial, not Advanced. Then set a realistic target for each pillar over the next 12 to 18 months.

Most mid-sized companies get the most value from moving Identity and Devices forward first, then Networks. Governance matters from day one. Every policy needs an owner, and exceptions need an expiry date.

Frequently asked questions

Is zero trust a product we can buy?

No. It's an architecture and a set of principles. Products can help with specific parts, such as identity, device management or access proxies, but no single tool delivers zero trust. Be wary of anything marketed as a complete solution.

Do we have to get rid of our VPN?

Not immediately. Most organizations run both for a while and shift applications to per-application access in stages. The goal is to shrink VPN use until only a few legacy systems depend on it, with tight rules around those.

How long does it take?

It's an ongoing program, not a project with an end date. Meaningful progress on MFA, device posture and your first per-application access is achievable within a year for many mid-sized companies. Broader segmentation and data controls usually take longer.

Does zero trust make sense for a small IT team?

Yes, and arguably more so. Consolidating identity, requiring MFA and replacing broad network access often reduces day-to-day complexity. Start with the identity pillar and build out from there.

Key takeaways

  • Zero trust removes implicit trust based on network location and checks every access request.
  • NIST SP 800-207 defines the architecture. CISA's ZTMM v2.0 gives you five pillars and four stages to measure against.
  • Start with MFA everywhere and device posture checks, then move applications off the flat VPN.
  • Segment the network so one compromised account or server can't reach everything.
  • Log access decisions centrally, and review your pillar scores at least twice a year.