✳ US · NIST ZTA

NIST SP 800-207 Zero Trust Architecture: protect resources, not network location

An educational overview of NIST SP 800-207, Zero Trust Architecture, final August 2020 (document history 11 August 2020, DOI 10.6028/NIST.SP.800-207), as an architecture paradigm for protecting resources. Network location is not the prime trust signal.

US · NIST ZTAArchitecture paradigm explainerLast reviewed

What category of architecture paradigm this is

NIST SP 800-207 Zero Trust Architecture is an architecture paradigm for protecting resources (assets, services, workflows, and accounts). Network location is not the prime trust signal. There is no implicit trust from network location or from asset ownership. Authentication and authorization (subject and device) are discrete decisions before a session to a resource. It is not a product you install.

Who it commonly frames: readers who only had a Reference field guide, buyers who treat a zero-trust product or a ZTNA purchase as the architecture, and teams who treat a VLAN or an internal IP as trust. This is an architecture paradigm. It is not a U.S. statute that forces a certificate, and it is not a certification scheme.

What security people most often confuse: they fold a product purchase, a ZTNA path, a contractor VLAN, SSDF, NIST AI RMF 1.0, and an Atlas lesson into one seal. This page keeps those objects apart. The field guide at /reference/frameworks/nist-sp-800-207/ stays the edition-pin home. F5 at /learn/topics/least-privilege-and-layers/ stays least privilege and layers. Cloud shared responsibility stays at /learn/topics/shared-responsibility-cloud/. M3 at /learn/misconceptions/zero-trust-not-a-product/ stays the product and VLAN correction. The cloud-misconfig lab at /labs/cloud-misconfig/ stays the shared-responsibility call. The SSDF explainer at /learn/explainers/ssdf/ stays the software practice vocabulary. The AI RMF explainer at /learn/explainers/nist-ai-rmf/ stays the voluntary AI framework. The secure-access landscape at /landscape/segments/secure-access/ talks zero trust network access. It does not replace this card. This explainer complements those pages. It does not replace any of them. It does not reproduce the logical-component catalog. It does not reproduce the deployment-model catalog.

Edition pin

The edition string to teach is NIST SP 800-207, Zero Trust Architecture, final, August 2020 (document history 11 August 2020), DOI 10.6028/NIST.SP.800-207. Official hubs are https://csrc.nist.gov/pubs/sp/800/207/final and https://doi.org/10.6028/NIST.SP.800-207. Re-opened on 2026-09-26: the publication page still says Date Published August 2020, Document History 08/11/20 Final, and the same DOI.

SP 800-207A stays a name-only companion. This card does not invent an adoption percentage, and it does not open a second ZTA card.

Three slogans are literacy labels

Protect resources: assets, services, workflows, and accounts, not network segments as the prime trust signal. Authenticate and authorize before a session: subject and device decisions are discrete before access to a resource. Name the policy decision and owner: who decides for this session, and what remains outside a product purchase.

These are slogan labels. They are not a finished architecture, and they are not permission to paste a component list or a deployment list into Atlas. On the synthetic YardOS floor, a scanner vendor on the warehouse VLAN still needs a decision before a session to the resource. That conversation lives on F5 at /learn/topics/least-privilege-and-layers/ and on M3 at /learn/misconceptions/zero-trust-not-a-product/. This page points there. It does not become a checklist.

Name the resource, the session decision, and the owner

Ask which resource is being protected, what decision is required before a session, who owns that decision, and what remains outside a product purchase. A named owner on a YardOS vendor window is a start. A slide that says zero trust certified is not that evidence.

Practice stays on the existing pages. F5 is /learn/topics/least-privilege-and-layers/. Cloud shared responsibility is /learn/topics/shared-responsibility-cloud/. M3 is /learn/misconceptions/zero-trust-not-a-product/. The cloud-misconfig lab is /labs/cloud-misconfig/. The secure-access landscape, when you are comparing an access path, is /landscape/segments/secure-access/. The field guide remains /reference/frameworks/nist-sp-800-207/.

When the need is software security practice vocabulary, use the SSDF explainer at /learn/explainers/ssdf/. When the need is AI risk placement, use the AI RMF explainer at /learn/explainers/nist-ai-rmf/. Do not collapse those lanes.

SP 800-207A is a companion, not this edition

SP 800-207A is a name-only companion (final September 2023, document history 13 September 2023, Date Published September 2023). Do not swap it into the SP 800-207 edition string. This page does not open a full SP 800-207A Atlas page.

What this card is not

Not a zero-trust course. Not a logical-component catalog. Not a deployment-model catalog. Not an NCCoE project dump. Not an Agentic Top 10 card. Not a federal companion page. Not a full SP 800-207A page. Not a CISA Zero Trust Maturity Model Atlas page. Not exploit or red-team PoC homework. Not an SSDF rewrite. Not an AI RMF rewrite. Not a replacement for the field guide at /reference/frameworks/nist-sp-800-207/, for F5 at /learn/topics/least-privilege-and-layers/, for cloud shared responsibility at /learn/topics/shared-responsibility-cloud/, for M3 at /learn/misconceptions/zero-trust-not-a-product/, or for the cloud-misconfig lab at /labs/cloud-misconfig/. Not permission to invent an adoption statistic. Not a claim that naming zero trust means the architecture is finished. Not an Atlas attestation of ZTA completion.

Not a CSF 2.0 profile. Outcomes live on /learn/topics/outcomes-then-controls/. This page is the labeled literacy home beside the field guide.

Rewrite the one-line claim

Replace "we bought zero trust" and "the VLAN is done" with a reading sentence. We use NIST SP 800-207 as a shared architecture vocabulary for protecting named resources, then name the policy decision and owner for the specific session.

When a slide says "zero trust certified" or "ZTA complete," privately ask which edition (SP 800-207, final, August 2020), which resource is protected, who owns the policy decision for that session, and whether the live need is this architecture vocabulary, a ZTNA access path, SSDF practice vocabulary, or AI RMF placement. Do not paste proprietary prompts, customer data, or exploit kits into Atlas.

A product, a ZTNA path, and a VLAN are not the architecture

Teaching table only. It does not assign a certificate, a finished architecture, a ZTNA result, or an Atlas seal.

Six phrases people fold into one zero-trust badge. Not a seal, and not an architecture catalog.
Phrase people sayLiteracy correction
We bought a zero-trust product, so ZTA is done.SP 800-207 is an architecture paradigm. A purchase is one possible control context, not the architecture. M3: /learn/misconceptions/zero-trust-not-a-product/.
ZTNA means Zero Trust Architecture is complete.Zero trust network access can be one access path. It does not finish the principles in SP 800-207. Secure-access landscape: /landscape/segments/secure-access/.
The contractor is on the VLAN / has an internal IP, so they are trusted.SP 800-207 does not treat network location, including an internal address, as enough trust for a resource. F5: /learn/topics/least-privilege-and-layers/. M3: /learn/misconceptions/zero-trust-not-a-product/.
ZTA is SSDF.SSDF (SP 800-218) is a software security practice vocabulary. ZTA is an architecture paradigm for protecting resources. Explainer: /learn/explainers/ssdf/.
ZTA is AI RMF.NIST AI RMF 1.0 is a separate voluntary AI risk framework. Explainer: /learn/explainers/nist-ai-rmf/.
We named zero trust, so we are certified / covered.Naming a framework is not evidence of implementation, assessment, certification, or absence of risk. Atlas does not issue a zero-trust seal. Field guide: /reference/frameworks/nist-sp-800-207/. Cloud shared responsibility: /learn/topics/shared-responsibility-cloud/. Cloud-misconfig lab: /labs/cloud-misconfig/.

Claims to retire

We bought a zero-trust product, so ZTA is done.

SP 800-207 is an architecture paradigm. A purchase is one possible control context, not the architecture.

ZTNA means Zero Trust Architecture is complete.

Zero trust network access can be one access path. It does not finish the principles in SP 800-207.

The contractor is on the VLAN / has an internal IP, so they are trusted.

SP 800-207 does not treat network location, including an internal address, as enough trust for a resource.

ZTA is SSDF.

SSDF (SP 800-218) is a software security practice vocabulary. ZTA is an architecture paradigm for protecting resources.

ZTA is AI RMF.

NIST AI RMF 1.0 is a separate voluntary AI risk framework.

We named zero trust, so we are certified / covered.

Naming a framework is not evidence of implementation, assessment, certification, or absence of risk. Atlas does not issue a zero-trust seal.

SP 800-207A is the SP 800-207 edition pin.

SP 800-207A is a name-only companion (final September 2023). Do not swap it into the SP 800-207 edition string.

Resources, session decisions, and a named owner

Slogan depth only. This table does not reproduce the logical-component catalog. It does not reproduce the deployment-model catalog.

Three slogan labels. Not a finished architecture, and not a certification.
SloganOne-line literacyBoundary
Protect resourcesAssets, services, workflows, and accounts, not network segments as the prime trust signalSlogan label. Not a finished architecture, and not a component catalog.
Authenticate and authorize before a sessionSubject and device decisions are discrete before access to a resourceSlogan label. Not a finished architecture, and not a component catalog.
Name the policy decision and ownerWho decides for this session, and what remains outside a product purchaseSlogan label. Not a finished architecture, and not a component catalog.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.