Framework overlap

Does DoD Zero Trust Reference Architecture cover CISA Zero Trust Maturity Model?

You hold DoD Zero Trust Reference Architecture and have been told to do CISA Zero Trust Maturity Model. Here is how much overlaps, control by control.

28% of CISA Zero Trust Maturity Model you already have

DoD Zero Trust Reference Architecture already covers about 28% of CISA Zero Trust Maturity Model, leaving 33 of 46 controls as genuinely new work.

Already covered 0 Likely covered 13 New work 33

No control in DoD Zero Trust Reference Architecture maps directly to one in CISA Zero Trust Maturity Model. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in DoD Zero Trust Reference Architecture reaches these. This is the list to scope.

ZTMM-APP-1
Application Access
ZTMM-APP-2
Application Threat Protection
ZTMM-APP-3
Secure Application Development and Deployment
ZTMM-APP-4
Application Visibility and Analytics
ZTMM-APP-AO
Applications Pillar: Automation and Orchestration
ZTMM-APP-GOV
Applications Pillar: Governance
ZTMM-APP-TEST
Applications Pillar: Application Security Testing
ZTMM-CROSS-1
Visibility and Analytics
ZTMM-CROSS-2
Automation and Orchestration
ZTMM-CROSS-3
Governance for Zero Trust
ZTMM-DAT-1
Data Inventory and Classification
ZTMM-DAT-2
Data Access Control
ZTMM-DAT-3
Data Encryption
ZTMM-DAT-4
Data Loss Prevention
ZTMM-DAT-AO
Data Pillar: Automation and Orchestration
ZTMM-DAT-AVAIL
Data Pillar: Data Availability
ZTMM-DAT-CAT
Data Pillar: Data Categorization
ZTMM-DAT-GOV
Data Pillar: Governance
ZTMM-DEV-1
Device Inventory
ZTMM-DEV-2
Device Compliance and Posture
ZTMM-DEV-3
Device Threat Protection
ZTMM-DEV-AO
Devices Pillar: Automation and Orchestration
ZTMM-DEV-GOV
Devices Pillar: Governance
ZTMM-ID-1
Identity Authentication
ZTMM-ID-2
Identity Stores
ZTMM-ID-3
Risk Assessments for Identity
ZTMM-ID-4
Access Management
ZTMM-ID-GOV
Identity Pillar: Governance
ZTMM-MAT-1
Maturity Stage Self-Assessment
ZTMM-NET-1
Network Segmentation
ZTMM-NET-2
Network Traffic Management
ZTMM-NET-3
Resilience and Availability
ZTMM-NET-ENC
Networks Pillar: Traffic Encryption
Show the 13 you already have
ZTMM-APP-VA
Applications Pillar: Visibility and Analytics
ZTMM-DAT-VA
Data Pillar: Visibility and Analytics
ZTMM-DEV-SCRM
Devices Pillar: Asset and Supply Chain Risk Management
ZTMM-DEV-VA
Devices Pillar: Visibility and Analytics
ZTMM-ID-AO
Identity Pillar: Automation and Orchestration
ZTMM-ID-VA
Identity Pillar: Visibility and Analytics
ZTMM-NET-AO
Networks Pillar: Automation and Orchestration
ZTMM-NET-GOV
Networks Pillar: Governance
ZTMM-NET-VA
Networks Pillar: Visibility and Analytics
ZTMM-STAGE-ADV
Maturity Stage: Advanced
ZTMM-STAGE-INIT
Maturity Stage: Initial
ZTMM-STAGE-OPT
Maturity Stage: Optimal
ZTMM-STAGE-TRAD
Maturity Stage: Traditional

How this is calculated

Already covered means a mapping runs from a control in DoD Zero Trust Reference Architecture to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition