Framework overlap

Does NIST SP 800-171 cover CISA Zero Trust Maturity Model?

You hold NIST SP 800-171 and have been told to do CISA Zero Trust Maturity Model. Here is how much overlaps, control by control.

26% of CISA Zero Trust Maturity Model you already have

NIST SP 800-171 already covers about 26% of CISA Zero Trust Maturity Model, leaving 34 of 46 controls as genuinely new work.

Already covered 0 Likely covered 12 New work 34

No control in NIST SP 800-171 maps directly to one in CISA Zero Trust Maturity Model. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in NIST SP 800-171 reaches these. This is the list to scope.

ZTMM-APP-1
Application Access
ZTMM-APP-2
Application Threat Protection
ZTMM-APP-3
Secure Application Development and Deployment
ZTMM-APP-4
Application Visibility and Analytics
ZTMM-APP-AO
Applications Pillar: Automation and Orchestration
ZTMM-APP-GOV
Applications Pillar: Governance
ZTMM-APP-TEST
Applications Pillar: Application Security Testing
ZTMM-CROSS-1
Visibility and Analytics
ZTMM-CROSS-2
Automation and Orchestration
ZTMM-CROSS-3
Governance for Zero Trust
ZTMM-DAT-1
Data Inventory and Classification
ZTMM-DAT-2
Data Access Control
ZTMM-DAT-3
Data Encryption
ZTMM-DAT-4
Data Loss Prevention
ZTMM-DAT-AO
Data Pillar: Automation and Orchestration
ZTMM-DAT-AVAIL
Data Pillar: Data Availability
ZTMM-DAT-CAT
Data Pillar: Data Categorization
ZTMM-DAT-GOV
Data Pillar: Governance
ZTMM-DEV-1
Device Inventory
ZTMM-DEV-2
Device Compliance and Posture
ZTMM-DEV-3
Device Threat Protection
ZTMM-DEV-AO
Devices Pillar: Automation and Orchestration
ZTMM-DEV-GOV
Devices Pillar: Governance
ZTMM-DEV-SCRM
Devices Pillar: Asset and Supply Chain Risk Management
ZTMM-ID-1
Identity Authentication
ZTMM-ID-2
Identity Stores
ZTMM-ID-3
Risk Assessments for Identity
ZTMM-ID-4
Access Management
ZTMM-ID-AO
Identity Pillar: Automation and Orchestration
ZTMM-ID-GOV
Identity Pillar: Governance
ZTMM-MAT-1
Maturity Stage Self-Assessment
ZTMM-NET-1
Network Segmentation
ZTMM-NET-2
Network Traffic Management
ZTMM-NET-3
Resilience and Availability
Show the 12 you already have
ZTMM-APP-VA
Applications Pillar: Visibility and Analytics
ZTMM-DAT-VA
Data Pillar: Visibility and Analytics
ZTMM-DEV-VA
Devices Pillar: Visibility and Analytics
ZTMM-ID-VA
Identity Pillar: Visibility and Analytics
ZTMM-NET-AO
Networks Pillar: Automation and Orchestration
ZTMM-NET-ENC
Networks Pillar: Traffic Encryption
ZTMM-NET-GOV
Networks Pillar: Governance
ZTMM-NET-VA
Networks Pillar: Visibility and Analytics
ZTMM-STAGE-ADV
Maturity Stage: Advanced
ZTMM-STAGE-INIT
Maturity Stage: Initial
ZTMM-STAGE-OPT
Maturity Stage: Optimal
ZTMM-STAGE-TRAD
Maturity Stage: Traditional

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-171 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition