Zero Trust eXtended (ZTX) gives organizations a way to answer a practical question: if we are serious about zero trust security, what exactly do we have to change? Created by the analyst firm Forrester, it splits a zero trust program into separate areas, covering who your users are, which devices they use, where your data and applications live and how your networks are segmented, plus the monitoring and automation that hold them together. Each area can then be assessed, prioritized and funded on its own. Forrester also originated the earlier, network-centered zero trust model, and ZTX broadened it for a world of cloud services, mobile devices and remote work.
At a glance
- ZTX is Forrester’s framework for structuring a zero trust program, not a product or a formal standard.
- It extends zero trust beyond network segmentation to data, people, devices and workloads.
- Visibility and analytics, plus automation and orchestration, tie the areas together.
- Vendors sometimes map their products to ZTX areas; no single product covers them all.
- It is one of several references, alongside government guidance such as NIST’s zero trust architecture.
What problem it solves
The early zero trust idea focused on the network: stop trusting traffic because it comes from inside the firewall, and segment the network so attackers can’t move freely. That was useful but incomplete. Users now work from anywhere, applications live in several clouds, devices include personal phones, and the most valuable target is often the data itself.
ZTX gives organizations a map of everything a zero trust program needs to touch. Instead of buying one product labeled “zero trust” and declaring victory, teams can assess each area, see where controls are weak, and build a phased roadmap. It also gives a common structure for discussing progress with leadership and for comparing how vendors’ products fit.
How it works
ZTX describes a set of areas, each with its own controls:
Data. Know what data you have, classify it with data classification, and protect it with encryption, access controls and loss prevention wherever it goes.
People (workforce). Strong identity and least-privilege access through identity and access management (IAM), multifactor authentication and access reviews.
Devices. Know which devices connect, check their health and configuration, and limit what unhealthy or unmanaged devices can reach.
Workloads. Protect applications and servers in data centers and clouds, including how they talk to each other.
Networks. Segment networks and use microsegmentation so a compromised system can’t reach everything, and replace broad network access with per-application access such as zero trust network access (ZTNA).
Visibility and analytics. Collect and analyze activity across all areas to spot misuse and measure whether policies work.
Automation and orchestration. Apply and adjust policies consistently and respond to threats at machine speed.
An organization typically assesses its maturity in each area, picks priorities based on risk, and works through them in phases.
When it matters for buyers
- When building a zero trust roadmap. ZTX is a ready-made checklist of areas to assess.
- When vendors claim to “deliver zero trust.” Mapping a product to ZTX areas shows what it covers and what it leaves out.
- When reporting to leadership. A structured view of progress by area is easier to explain than a list of tools.
- When comparing frameworks. Organizations working with US federal agencies may be expected to follow government models instead, so check customer and contract requirements.
- When consolidating tools. Seeing all areas together helps avoid gaps and overlapping purchases.
Questions to ask vendors
- Which ZTX areas does your product address, and which does it not?
- How does your product share identity, device and risk signals with other tools we use?
- Can your policies be applied consistently across users in the office, at home and in the cloud?
- What visibility and reporting do you provide to show policies are working?
- What can be automated, and what still needs manual work?
- What does a phased rollout look like for an organization of our size?
Our secure access service edge advisors help buyers turn a zero trust framework into a sourcing plan.
How it differs from zero trust security
Zero trust security is the underlying principle: never grant access just because of network location, verify each request using identity, device and context, and give only the access needed. ZTX is one analyst firm’s framework for applying that principle across an organization. You can practice zero trust without using ZTX, for example by following NIST’s zero trust architecture guidance or CISA’s maturity model, and many organizations combine elements of several. Forrester also uses the related term Zero Trust Edge (ZTE) for the networking and access slice of zero trust. ZTX is also different from cybersecurity mesh architecture (CSMA), a Gartner concept about making security tools work together through shared services, though the two share goals.
