Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 1403

Zero Trust Network

Reviewed byCybersecurity entrepreneur & security researcher

What is Zero Trust Network?

Zero Trust NetworkA network architecture that never trusts users, devices, or services by default and enforces continuous, identity-aware verification of every connection.


A zero trust network discards the legacy assumption that the internal network is inherently trusted. Every connection — north-south or east-west — must be authenticated, authorized, and continuously evaluated based on identity, device posture, context, and risk before access to an application or service is granted.

The term was coined by John Kindervag at Forrester in his 2010 report No More Chewy Centers: Introducing the Zero Trust Model of Information Security, which attacked the "hard shell, soft centre" perimeter model. Google's BeyondCorp program (2014 onward) then proved the pattern at enterprise scale by moving access decisions off the VPN and onto per-request checks. In 2020 NIST codified it in SP 800-207, whose core abstraction is a Policy Decision Point (PDP) and Policy Enforcement Point (PEP): the PEP sits in the data path, and for every request it asks the PDP — fed by identity, device, and threat-intel signals — for an allow/deny verdict scoped to a single session.

In the U.S. federal sphere, Executive Order 14028 (May 2021) and OMB memo M-22-09 (January 2022) mandated agencies move toward zero trust, with milestones due by the end of FY2024. Architecturally it combines strong identity (MFA, FIDO2), device attestation, encrypted transport (mTLS), microsegmentation, and least-privilege, just-in-time access — shrinking the blast radius of compromised credentials and treating "assume breach" as a design principle.

flowchart LR
  U[User + Device] -->|request| PEP[Policy Enforcement Point]
  PEP -->|query| PDP[Policy Decision Point]
  ID[Identity / MFA] --> PDP
  DEV[Device posture] --> PDP
  CTX[Context + risk signals] --> PDP
  PDP -->|allow / deny| PEP
  PEP -->|least-privilege session| APP[Application / Resource]

● Examples

  1. 01

    An employee accessing an internal app via a zero-trust gateway that checks identity, MFA, and device posture for every request.

  2. 02

    Service-to-service calls in a microservice mesh authenticated with short-lived mTLS certificates.

● Frequently asked questions

What is Zero Trust Network?

A network architecture that never trusts users, devices, or services by default and enforces continuous, identity-aware verification of every connection. It belongs to the Network Security category of cybersecurity.

What does Zero Trust Network mean?

A network architecture that never trusts users, devices, or services by default and enforces continuous, identity-aware verification of every connection.

How do you defend against Zero Trust Network?

Defences for Zero Trust Network typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for Zero Trust Network?

Common alternative names include: Zero Trust, Zero Trust Architecture (ZTA).

● Related terms

● See also