cisaregulatorNewsThe Broadside2 min read

CISA Releases Zero Trust Maturity Model Version 2

Agencies with existing v1 roadmaps now face the question of what, if anything, needs revisiting, the update adds an "Initial" maturity stage and aligns with OMB M-22-09.


TL;DR

CISA published Zero Trust Maturity Model version 2 on April 11, 2023, replacing the September 2021 original. The update incorporates public comment feedback, adds a new "Initial" maturity stage below the existing "Traditional" baseline, and aligns the model with OMB M-22-09. The five-pillar structure (Identity, Devices, Networks, Applications and Workloads, Data) remains intact. Federal agencies are the primary audience, but CISA recommends the guidance for state, local, and private-sector adoption as well. Contractors supporting federal zero-trust migrations should treat v2 as the reference architecture going forward.

CISA's Zero Trust Maturity Model version 2 landed April 11, 2023, replacing the September 2021 v1 baseline. The update isn't a rewrite, the five-pillar structure (Identity, Devices, Networks, Applications and Workloads, Data) and three cross-cutting capabilities carry over. What changed is a new maturity stage and explicit alignment with OMB Memorandum M-22-09.

The new "Initial" stage and what it does

V1 mapped three maturity levels: Traditional, Advanced, and Optimal. V2 inserts "Initial" between Traditional and Advanced, effectively lowering the floor for agencies at the very start of their zero-trust journey. The move came directly from public comments CISA received during the 2021 comment period. For agencies that hadn't begun structured zero-trust planning, "Traditional" was aspirational. "Initial" gives them a labeled rung on the ladder.

The alignment with OMB M-22-09, published in January 2022, is the other structural change. M-22-09 sets specific zero-trust goals for federal civilian agencies by the end of fiscal year 2024. V2 now reflects those targets within the maturity model's framework, making it the operational companion to the OMB directive rather than a standalone reference document.

Who needs to care

Federal civilian agencies are the named audience, but CISA's announcement explicitly encourages state, local, tribal, and territorial governments and the private sector to adopt the model. For contractors and subcontractors supporting federal systems, the practical implication is straightforward: if your zero-trust roadmap was built against v1's pillar definitions and maturity stages, you should cross-check it against v2's updated functions. The "Initial" stage may also shift the compliance conversation for subcontractors whose federal customers are now working from a four-stage maturity map.

What v2 doesn't provide is a timeline update. Agencies on existing v1 roadmaps aren't told whether their implementation schedules need revisiting, nor does the model specify which pillar should move first. That silence is meaningful, CISA is offering gradient progress, not a sequencing mandate.


Published ·Deep Fathom