Your agency's Zero Trust Network Access (ZTNA) procurement is about to close. Before you sign, ask yourself: does this solution actually meet CISA's Optimal stage, or did you just buy a rebranded VPN?
CISA's Zero Trust Maturity Model defines Optimal protection as continuous validation with inline data protection. Traditional ZTNA architectures provide encrypted tunnels at the application level but lack the intelligence required for real-time risk analysis. If your solution can't answer "yes" to the questions below, you're not building toward Optimal. You're maintaining the perimeter in a new wrapper.
Prerequisites
Before you work through this checklist, confirm you have:
- Documented current-state architecture showing identity directories, device management platforms, and data repositories across on-premises and cloud environments.
- Authority to query vendors about specific technical capabilities during procurement or contract modification.
- Access to CISA's Zero Trust Maturity Model (reference document for cross-checking Optimal stage requirements).
- Stakeholder alignment between your identity management, endpoint security, and data governance teams.
Identity Pillar Checklist
☐ 1. Centralized identity validation across hybrid environments
Your ZTNA solution validates user credentials against a single identity directory that spans on-premises Active Directory and cloud identity providers. You're not managing separate identity silos per environment.
Good looks like: A user authenticates once, and that identity is recognized consistently whether they're accessing an on-premises application or a SaaS tool.
☐ 2. Machine learning-driven risk analysis at authentication
The architecture collects behavioral signals (sign-on frequency, typical access times, geolocation patterns) and uses machine learning to calculate risk scores in real time. It doesn't just check static credentials.
Good looks like: When a user attempts access from an unusual location at 3 a.m., the system automatically escalates authentication requirements or blocks access before querying you for policy decisions.
☐ 3. Continuous identity validation throughout session lifecycle
Access decisions aren't made once at login. The system re-evaluates identity posture continuously while the session is active, detecting privilege creep or behavioral anomalies.
Good looks like: If a user's role changes mid-session or their device posture degrades, access rights adjust automatically without waiting for the next login cycle.
☐ 4. Lifecycle management with automated permission auditing
You can demonstrate continuous monitoring that flags over-provisioned accounts, dormant identities, or permission drift without manual quarterly reviews.
Good looks like: Your ZTNA dashboard surfaces identities with excessive privileges weekly, and you can trace when those permissions were granted and by whom.
Device Pillar Checklist
☐ 5. Device posture assessment at initial connection
Before granting access, the system checks hardware details, OS version, patch level, running applications, hardened configuration status, and geographic location.
Good looks like: An outdated device attempting to connect triggers an automatic block with a remediation path before it touches your network.
☐ 6. Multi-identity detection per device
The architecture identifies all user accounts active on a single endpoint, flagging shared devices or unauthorized secondary identities.
Good looks like: When a contractor's laptop shows two active identities (one authorized, one not), the system alerts your security team before data access occurs.
☐ 7. Post-connection posture monitoring
Device security status isn't static. The solution continuously monitors for configuration changes, new software installations, or degraded security posture after the initial connection is established.
Good looks like: If a user disables endpoint protection mid-session, the ZTNA immediately terminates their access to sensitive applications without waiting for the next authentication event.
Data Pillar Checklist
☐ 8. Automated data discovery and inventory
The system continuously scans on-premises and cloud environments, maintaining a current inventory of where data resides without manual cataloging.
Good looks like: When a team spins up a new cloud storage bucket, it appears in your data inventory within hours, not after your next quarterly audit.
☐ 9. Automated data classification
Data is categorized and tagged based on content characteristics (e.g., presence of Social Security numbers, CUI markings, export-controlled technical data) without requiring users to manually label files.
Good looks like: A document containing technical specifications is automatically classified as export-controlled, and access policies adjust accordingly.
☐ 10. Context-aware access control matching identity to data sensitivity
The architecture evaluates both who is requesting access and what type of data they're accessing, then applies policy based on that pairing.
Good looks like: A user with valid credentials attempting to download a dataset classified as CUI from an untrusted device is blocked, even though that same user can access less-sensitive resources from the same device.
☐ 11. Data-centric encryption inside and outside your boundary
Data is encrypted within your environment and remains encrypted when it leaves your control. This isn't just transport-layer encryption; it's encryption applied to the data object itself.
Good looks like: If an authorized user downloads a file to a personal device, that file remains encrypted and unreadable if the device is lost or if the user's access is later revoked.
Common Mistakes
Confusing encrypted tunnels with continuous validation. Traditional ZTNA creates application-specific encrypted connections but doesn't re-evaluate risk after the tunnel is established. Optimal requires ongoing posture assessment.
Treating device compliance as a one-time check. Checking device posture at login and then ignoring it for the session duration leaves you exposed. Devices degrade, users disable protections, and configurations drift.
Assuming data classification is someone else's problem. If your ZTNA can't see data classifications, it can't enforce context-aware policies. Data governance and access control must integrate.
Procuring identity, device, and data solutions separately. Optimal zero trust requires these pillars to communicate. If your identity platform doesn't share risk signals with your data protection layer, you're building silos with better encryption.
Next Steps
If you answered "no" to any item above, document the gap and determine whether it's a capability your current vendor can add or a fundamental architectural limitation. For procurement teams evaluating new solutions, convert this checklist into RFP requirements with specific technical demonstrations required during vendor evaluations.
For agencies already operating a ZTNA, map your current capabilities against CISA's Maturity Model stages. If you're at Traditional or Advanced, identify which Optimal capabilities deliver the highest risk reduction for your mission and build a roadmap that sequences upgrades based on threat exposure, not vendor marketing cycles.
Zero trust isn't a product category. It's a security model that requires continuous validation across identity, device, and data. If your architecture can't answer these questions with "yes," you're not advancing toward Optimal. You're just encrypting the status quo.



