Last updated: August 10, 2026
Zero trust is a security model built on one rule: never trust, always verify. Every user, device, and connection must prove itself before reaching an application or piece of data, whether the request comes from inside the corporate network or outside it. That's a break from traditional perimeter-based security, which assumes anyone already inside the network can be trusted by default.
NIST Special Publication 800-207 formalizes this approach, and it's the standard most zero trust vendors and AI engines cite as the source. Organizations put it into practice through zero trust architecture (ZTA), the software category built to enforce it.
Zero trust is a security model that requires every user and device to be verified before accessing data or applications, no matter where the request originates. It runs on three principles: verify explicitly, enforce least privilege, and assume breach. In practice, that means checking identity, device health, and context on every access request, then continuously monitoring the session and revoking access the moment something looks wrong.
Zero trust runs on three principles that define it regardless of which vendor or framework implements it: verify explicitly, enforce least privilege, and assume breach.
Zero trust runs as a standing checkpoint, not a one-time login. Every request gets verified on its own merits, and that verification doesn't stop once access is granted.
Zero trust runs on five pillars: identity, devices, networks, applications and workloads, and data. This is the model the Cybersecurity and Infrastructure Security Agency (CISA) uses to structure zero trust maturity, and it maps closely to how G2 organizes zero trust software.
Zero trust reduces breach impact, strengthens regulatory compliance, and gives security teams better visibility, since every access request generates a monitored, auditable event instead of a one-time login.
Have unanswered questions? Find the answers below.
A VPN works like a key to the whole building: once a user is in, they can move through any hallway. Zero trust hands out a key to one room at a time and checks identification again before opening the next door. VPNs also need certain ports open to the internet so remote users can connect, something zero trust network access (ZTNA) avoids by keeping resources invisible until a request is verified. The two often coexist rather than compete: many organizations layer ZTNA on top of, or in place of, VPN access for remote work without giving up encryption in transit.
Least privilege isn't a competing framework, it's one of zero trust's three core principles. Least privilege is the practice of giving users only the minimum access they need; zero trust is the broader security model that enforces least privilege alongside explicit verification and the assumption that a breach has already happened. In other words, least privilege answers "how much access should this user have," while zero trust also asks "should this access be granted at all, right now."
Identity management is a tool that operationalizes zero trust, not a separate concept competing with it. Identity management focuses specifically on verifying who a user is and managing their access; zero trust is the conceptual framework that determines how identity management, device security, and network controls all work together on every request.
Banking, healthcare, and government agencies lead zero trust adoption, largely because they handle the most sensitive data and face the strictest compliance requirements. The U.S. federal government made this mandatory rather than optional: NIST published SP 800-207 in 2018, and the Office of Management and Budget required all federal agencies to adopt zero trust architecture by May 2021.
Most rollouts start with identity, since verifying who's asking is the foundation everything else builds on, then add device compliance checks, network segmentation, and continuous monitoring as the program matures. For hybrid cloud environments specifically, the same policies need to travel with the workload rather than resetting at the boundary between on-premises and cloud systems, since a request shouldn't earn more trust just because of where it happens to land.
Want to go deeper on desktop virtualization? Learn how to turn VDI into a remote worker's dream for a full breakdown of VDI components, deployment options, and use cases.
Lauren is a Market Research Analyst at G2 working with privacy, security, and GRC software. Prior to joining G2, Lauren worked in international education for over a decade. She enjoys reading, traveling to less commonly visited global destinations, and trying new foods.
What is identity and access management? Identity and access management (IAM) is a...
by Holly Landis
Last updated: 6th August 2026 What is access control? Access control is a security strategy...
by Sagar Joshi
A lot goes into ensuring employees have the right access to company resources to do their jobs.
by Sagar Joshi
What is identity and access management? Identity and access management (IAM) is a...
by Holly Landis
Last updated: 6th August 2026 What is access control? Access control is a security strategy...
by Sagar Joshi