https://www.nccoe.nist.gov/projects/implementing-zero-trust-architecture Skip to main content U.S. flag An official website of the United States government Here's how you know Here's how you know [icon-dot-g] Official websites use .gov A .gov website belongs to an official government organization in the United States. [icon-https] Secure .gov websites use HTTPS A lock ( A locked padlock ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. * Security Guidance Toggle Sub-Menu + By Technology Toggle Sub-Menu o 5G Cybersecurity o Applied Cryptography o Artificial Intelligence o Critical Cybersecurity Hygiene o Data Classification o Data Security o DevSecOps o Internet of Things (IoT) o IPv6 o Mobile Device Security o Supply Chain Assurance o Trusted Cloud o Zero Trust Architecture + By Sector Toggle Sub-Menu o Consumer Data Protection o Energy o Financial Services o Healthcare o Manufacturing o Public Safety/First Responder + By Status Toggle Sub-Menu o Defining Scope o Seeking Collaborators o Preparing Draft o Soliciting Comments o Reviewing Comments o Finalized Practice Guide o Archived * Our Approach Toggle Sub-Menu + Mission & Vision + How We Work + About the Center * News & Insights * Get Involved Toggle Sub-Menu + Attend Events + Contact Us + Subscribe to Updates + Join a Community of Interest + Technical Contributions + Government Organizations + Academic Engagement [ ] Search * Home * Security Guidance * Implementing a Zero Trust Architecture Abstract image of a network with the concept of zero trust at its center. Implementing a Zero Trust Architecture Conventional network security has focused on perimeter defenses, but many organizations no longer have a clearly-defined perimeter. To protect a modern digital enterprise, organizations need a comprehensive strategy for secure "anytime, anywhere" access to their corporate resources (e.g., applications, legacy systems, data, and devices) regardless of where they are located. End-to-end zero trust architecture implementations to help industry and government reduce the risk of cyber attack The National Cybersecurity Center of Excellence (NCCoE) aims to remove the shroud of complexity around designing for zero trust with "how to" guides and example approaches to implementing a zero trust architecture for several common business cases. Status: Soliciting Comments The National Cybersecurity Center of Excellence has released preliminary draft NIST Cybersecurity Practice Guide SP 1800-35 Vol C- D, Implementing a Zero Trust Architecture, for public comment until September 9, 2022. NIST is adopting an agile process to publish this content. Each volume is being made available as soon as possible rather than delaying release until all volumes are completed. Work continues on implementing the example solutions and developing other parts of the content. As a preliminary draft, we will publish at least one additional draft for public comment before it is finalized. The preliminary draft guide is available for download by specific volumes: NIST SP 1800-35A: Executive Summary (Preliminary Draft)Document Version NIST SP 1800-35A: Executive Summary (Preliminary Draft) NIST SP 1800-35B: Approach, Architecture, and Security Characteristics (Preliminary Draft)Document Version NIST SP 1800-35B: Approach, Architecture, and Security Characteristics (Preliminary Draft) NIST SP 1800-35C: How-To Guides (Preliminary Draft)Document Version NIST SP 1800-35C: How-To Guides (Preliminary Draft) NIST SP 1800-35D: Functional Demonstrations (Preliminary Draft) Document Version NIST SP 1800-35D: Functional Demonstrations (Preliminary Draft) Submit Comments View the 2-page fact sheet Your Information First & Last Name First Name [ ] Last Name [ ] Email [ ] Comment(s) Comment Some header Line # [ ] Page # [ ] Comment [ ] Item weight Add new item after item 1 [ ] [0 ] Remove item 1 [ ] [ ] [ ] [Add another comment] Add another comment more items [20 ] more items [Submit Comments] Project Abstract The proliferation of cloud computing, mobile device use, and the Internet of Things has dissolved conventional network boundaries. The workforce is more distributed, with remote workers who need access to resources anytime, anywhere, and on any device, to support the mission. Organizations must evolve to provide secure access to company resources from any location and asset, protect interactions with business partners, and shield client-server as well as inter-server communications. The NCCoE initiated this project in collaboration with industry participants to demonstrate several approaches to a zero trust architecture applied to a conventional, general purpose enterprise information technology (IT) infrastructure on premises and in the cloud, which will be designed and deployed according to the concepts and tenets documented in NIST Special Publication (SP) 800-207, Zero Trust Architecture. The example implementations integrate commercial and open-source products that leverage cybersecurity standards and recommended practices to showcase the robust security features of zero trust architectures. This project will result in a NIST Cybersecurity Practice Guide, a publicly available description of the practical steps needed to implement the cybersecurity reference designs for zero trust. Read the Zero Trust Architecture Project Description The proliferation of cloud computing, mobile device use, and the Internet of Things has dissolved conventional network boundaries. Collaborating Vendors Organizations participating in this project submitted their capabilities in response to an open call in the Federal Register for all sources of relevant security capabilities from academia and industry (vendors and integrators). The following respondents with relevant capabilities or product components (identified as "Technology Partners/Collaborators" herein) signed a Cooperative Research and Development Agreement to collaborate with NIST in a consortium to build this example solution. * Appgate * AWS * Broadcom Software * Cisco * DigiCert * F5 * Forescout * Google Cloud * IBM * Ivanti * Lookout * Mandiant * Microsoft * Okta * Palo Alto Networks * PC Matic * Ping Identity * Radiant Logic * SailPoint * Tenable * Trellix * VMware * Zimperium * Zscaler Federal CIO Council Efforts Since late 2018, National Institute of Standards and Technology (NIST) and NCCoE cybersecurity researchers have had the opportunity to work closely with the Federal Chief Information Officer (CIO) Council, federal agencies, and industry to address the challenges and opportunities for implementing zero trust architectures across U.S. government networks. This work resulted in publication of NIST Special Publication (SP) 800-207, Zero Trust Architecture. In November 2019, the NCCoE and the Federal CIO Council cohosted a Zero Trust Architecture Technical Exchange Meeting that brought together zero trust vendors and practitioners from government and industry to share successes, best practices, and lessons learned in implementing zero trust in the federal government and the commercial sector. The NCCoE project builds on this body of knowledge. We continue to share lessons learned with the Federal CIO Council and look forward to their continued feedback to inform NCCoE cybersecurity guidance and identify future challenges in this space. Join the Community of Interest A Community of Interest (COI) is a group of professionals and advisors that share business insights, technical expertise, challenges, and perspectives to guide NCCoE projects. COIs often include experts, innovators, and everyday users of cybersecurity and privacy technologies. Share your expertise and consider becoming a member of this project's COI. Request to Join Employee speaking on video call with colleagues on online briefing with laptop at home The Zero Trust Architecture (ZTA) Team Releases Preliminary Draft Practice Guide (Vol C-D) August 09, 2022 NIST NCCoE Abstract cybersecurity banner News * Announcements The Zero Trust Architecture (ZTA) Team Releases Preliminary Draft Practice Guide (Vol B) July 07, 2022 NIST NCCoE * Announcements The Zero Trust Architecture (ZTA) Team Releases Preliminary Draft Practice Guide (Vol A) June 03, 2022 NIST NCCoE * Announcements NCCoE Announces Technology Collaborators to Demonstrate Zero Trust Architectures July 21, 2021 NIST NCCoE Have a question about this project? Contact Us NCCoE 9700 Great Seneca Highway, Rockville, MD 20850 NIST is an agency of the U.S. Department of Commerce. * Facebook * Twitter * LinkedIn * YouTube * Site Privacy * Accessibility * Privacy Program * Copyrights * Vulnerability Disclosure * No Fear Act Policy * FOIA * Environmental Policy * Scientific Integrity * Information Quality Standards * Commerce.gov * Science.gov * USA.gov * Vote.gov