The phrase “zero trust” has been in security strategy documents for a decade. For most of that time it was treated as a security philosophy, an aspiration, or a product marketing category, rather than a specific regulatory requirement with measurable criteria and enforcement consequences. That changed in 2026. The federal mandates issued in 2022 had deadlines that are now past, CISA has published a maturity model with specific capability levels, and multiple regulatory frameworks across the US, EU, and UK are converging on zero trust principles as baseline expectations for critical sectors.
This briefing lays out the regulatory landscape, what each framework actually requires, and what the board should understand about the organisation’s current position.
OMB M-22-09: Federal ZTA Mandate Now Enforceable
The Biden administration’s OMB Memorandum M-22-09, “Moving the US Government Toward Zero Trust Cybersecurity Principles,” set a September 2024 deadline for federal agencies to achieve specific zero trust goals. The goals cover five pillars: Identity, Devices, Networks, Applications/Workloads, and Data. Within each pillar, agencies were expected to reach defined maturity targets.
Those deadlines have passed. OMB and CISA are now in active assessment and enforcement posture with agencies that missed targets. The practical consequence for organisations that contract with federal agencies is that zero trust implementation is increasingly appearing in procurement requirements. Federal contractors handling sensitive data or providing IT services to agencies face ZTA requirements by inheritance from their agency clients.
CISA’s Zero Trust Maturity Model Version 2 (published 2023, updated 2025) provides the specific capability descriptions and maturity levels (Traditional, Initial, Advanced, Optimal) against which agencies and their contractors are assessed. It is the most useful document for understanding what “implementing zero trust” actually means in measurable terms.
What CISA ZTMM Requires in Practice
The ZTMM defines specific capabilities for each pillar. Selected examples relevant to most enterprise environments:
Identity pillar: Multi-factor authentication for all users and services, phishing-resistant MFA (hardware keys or passkeys rather than SMS/TOTP) for privileged access, continuous validation of identity attributes during sessions rather than just at login, and centralised identity governance with automated provisioning and de-provisioning.
Device pillar: Asset inventory covering all managed and unmanaged devices accessing corporate resources, device health attestation integrated into access control decisions, endpoint detection and response (EDR) on all managed endpoints, and mobile device management (MDM) for mobile endpoints.
Network pillar: Micro-segmentation within internal networks, encrypted traffic for all east-west communications, software-defined perimeters replacing VPN-based access models, and network access control decisions tied to identity and device health rather than network location.
Application/Workload pillar: Application-layer access control (not just network-layer), authenticated API access between services, automated vulnerability management, and integration of application access decisions with identity and device signals.
Data pillar: Data classification and labeling, data access logging and monitoring, encryption at rest and in transit with key management, and data loss prevention controls aligned with classification.
The maturity levels matter. An organisation at “Initial” for all pillars is meaningfully different from one at “Advanced,” and the assessment process distinguishes them.
DORA and Financial Sector ZTA
The EU’s Digital Operational Resilience Act (DORA), now in enforcement for financial sector entities, does not use the phrase “zero trust” in its text. But its requirements for ICT risk management, access control, and third-party risk management map directly to zero trust principles.
DORA Article 9 requires financial entities to implement policies and procedures ensuring appropriate protection of ICT systems, including strong authentication, least-privilege access, and continuous monitoring of access patterns. DORA Article 28 extends access control requirements to ICT third-party service providers, requiring contractual obligations that align with the entity’s own controls.
The European Banking Authority (EBA) guidelines interpreting DORA’s ICT risk management requirements reference zero trust architecture as an appropriate implementation approach for meeting Article 9 requirements. Supervised financial entities being assessed for DORA compliance will encounter questions about identity-based access control, network micro-segmentation, and continuous monitoring that are the operational substance of zero trust.
CIRCIA and Critical Infrastructure
The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) focuses on incident reporting requirements, but its cybersecurity performance goals framework aligns with zero trust controls. CISA’s Cross-Sector Cybersecurity Performance Goals, which CIRCIA references, include specific controls around MFA, network segmentation, and privileged access management that constitute the core of zero trust implementation.
For critical infrastructure operators in the 16 designated sectors, these are not soft recommendations. CISA’s enforcement posture for CIRCIA compliance is more assertive than previous voluntary frameworks, and the CPGs are the baseline against which incident response assessments will evaluate whether reasonable security practices were in place.
UK Cyber Security and Resilience Bill
The UK’s Cyber Security and Resilience Bill, progressing through Parliament with expected passage in late 2026, will extend regulatory oversight of cybersecurity to a broader set of operators than the current NIS framework. The draft legislation references security requirements that NCSC has articulated in its Zero Trust architecture guidance (available at ncsc.gov.uk/collection/zero-trust-architecture).
NCSC’s UK zero trust guidance is less prescriptive than CISA ZTMM but covers the same pillar model. Organisations subject to the new UK legislation should expect zero trust maturity questions in assessments similar to what NIS2-regulated operators face in the EU.
What the Board Should Understand
Zero trust is not a single purchase or a project with an end date. It is a security architecture model that requires sustained programme investment across identity, endpoint, network, and data capabilities. Programmes that “implement zero trust” by deploying a specific product without addressing the underlying capability pillars will not satisfy regulatory assessment requirements.
Maturity assessment results will become regulatory evidence. As CISA, EBA, and FCA build assessment frameworks, the organisation’s documented ZTA maturity level will be part of regulatory submissions and post-incident investigations. Demonstrable progress across pillars is better regulatory positioning than high-level policy statements.
MFA and privileged access are the immediate priorities. Across all frameworks, phishing-resistant MFA and privileged access management are the highest-weight requirements and the most commonly cited gaps in regulatory assessments. Boards should understand whether the organisation has deployed phishing-resistant MFA for privileged users and whether privileged access is controlled through a PAM system with session recording.
Third-party access is in scope. DORA Article 28, CISA’s CPGs, and similar requirements all extend zero trust expectations to suppliers, partners, and managed service providers with access to the organisation’s systems. Network-level VPN access for third parties, without identity-based access controls and session monitoring, does not meet current expectations in regulated sectors.
The transition from zero trust as strategy to zero trust as regulatory requirement happened quietly over the past 18 months. The organisations with mature programmes are now seeing it pay off in regulatory assessments. Those still treating it as a future initiative need to accelerate.