What Is ZTX (Zero Trust eXtended)?

Also called: ZTX ecosystem

Related problems: Zero trust feels like a slogan and we don't know what it covers; Vendors each claim to deliver zero trust with one product; Need a structured way to assess our zero trust gaps; Board asking for a zero trust roadmap

Zero Trust eXtended (ZTX) gives organizations a way to answer a practical question: if we are serious about zero trust security, what exactly do we have to change? Created by the analyst firm Forrester, it splits a zero trust program into separate areas, covering who your users are, which devices they use, where your data and applications live and how your networks are segmented, plus the monitoring and automation that hold them together. Each area can then be assessed, prioritized and funded on its own. Forrester also originated the earlier, network-centered zero trust model, and ZTX broadened it for a world of cloud services, mobile devices and remote work.

At a glance

  • ZTX is Forrester’s framework for structuring a zero trust program, not a product or a formal standard.
  • It extends zero trust beyond network segmentation to data, people, devices and workloads.
  • Visibility and analytics, plus automation and orchestration, tie the areas together.
  • Vendors sometimes map their products to ZTX areas; no single product covers them all.
  • It is one of several references, alongside government guidance such as NIST’s zero trust architecture.

What problem it solves

The early zero trust idea focused on the network: stop trusting traffic because it comes from inside the firewall, and segment the network so attackers can’t move freely. That was useful but incomplete. Users now work from anywhere, applications live in several clouds, devices include personal phones, and the most valuable target is often the data itself.

ZTX gives organizations a map of everything a zero trust program needs to touch. Instead of buying one product labeled “zero trust” and declaring victory, teams can assess each area, see where controls are weak, and build a phased roadmap. It also gives a common structure for discussing progress with leadership and for comparing how vendors’ products fit.

How it works

ZTX describes a set of areas, each with its own controls:

Data. Know what data you have, classify it with data classification, and protect it with encryption, access controls and loss prevention wherever it goes.

People (workforce). Strong identity and least-privilege access through identity and access management (IAM), multifactor authentication and access reviews.

Devices. Know which devices connect, check their health and configuration, and limit what unhealthy or unmanaged devices can reach.

Workloads. Protect applications and servers in data centers and clouds, including how they talk to each other.

Networks. Segment networks and use microsegmentation so a compromised system can’t reach everything, and replace broad network access with per-application access such as zero trust network access (ZTNA).

Visibility and analytics. Collect and analyze activity across all areas to spot misuse and measure whether policies work.

Automation and orchestration. Apply and adjust policies consistently and respond to threats at machine speed.

An organization typically assesses its maturity in each area, picks priorities based on risk, and works through them in phases.

When it matters for buyers

  • When building a zero trust roadmap. ZTX is a ready-made checklist of areas to assess.
  • When vendors claim to “deliver zero trust.” Mapping a product to ZTX areas shows what it covers and what it leaves out.
  • When reporting to leadership. A structured view of progress by area is easier to explain than a list of tools.
  • When comparing frameworks. Organizations working with US federal agencies may be expected to follow government models instead, so check customer and contract requirements.
  • When consolidating tools. Seeing all areas together helps avoid gaps and overlapping purchases.

Questions to ask vendors

  • Which ZTX areas does your product address, and which does it not?
  • How does your product share identity, device and risk signals with other tools we use?
  • Can your policies be applied consistently across users in the office, at home and in the cloud?
  • What visibility and reporting do you provide to show policies are working?
  • What can be automated, and what still needs manual work?
  • What does a phased rollout look like for an organization of our size?

Our secure access service edge advisors help buyers turn a zero trust framework into a sourcing plan.

How it differs from zero trust security

Zero trust security is the underlying principle: never grant access just because of network location, verify each request using identity, device and context, and give only the access needed. ZTX is one analyst firm’s framework for applying that principle across an organization. You can practice zero trust without using ZTX, for example by following NIST’s zero trust architecture guidance or CISA’s maturity model, and many organizations combine elements of several. Forrester also uses the related term Zero Trust Edge (ZTE) for the networking and access slice of zero trust. ZTX is also different from cybersecurity mesh architecture (CSMA), a Gartner concept about making security tools work together through shared services, though the two share goals.

Frequently Asked Questions

Who created Zero Trust eXtended?
The analyst firm Forrester, which also originated the zero trust security model itself. ZTX expanded that original network-focused model into a broader set of areas. Forrester has continued to develop its zero trust research since, so check its current materials for the latest structure and naming.
Is ZTX different from zero trust?
ZTX is one framework for putting zero trust into practice. Zero trust is the underlying principle: verify every access request and grant only the access needed. ZTX organizes the work into areas such as data, people, devices, workloads and networks.
Do we have to use ZTX to do zero trust?
No. Other widely used references include NIST's zero trust architecture guidance and the US Cybersecurity and Infrastructure Security Agency (CISA) zero trust maturity model. Many organizations borrow from several. What matters is a clear scope, an honest assessment and a phased plan.
Can a vendor sell us ZTX?
No single product covers all of it. Some vendors cover several areas and may map their products to ZTX, but a full program usually combines identity, endpoint, network, data and monitoring tools, plus policy and process changes.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.