# zero-trust

Source: https://startwithidentity.com/glossary/zero-trust/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

A security model where trust is never assumed based on network location and is continuously re-evaluated. Each access decision considers identity, device posture, and context. Codified in NIST SP 800-207. Distinct from ZTNA, which is the access control product category.

Zero trust is a set of design principles, not a product, and the identity parts are the ones that actually get implemented: strong authentication, device posture, per-application authorization, and continuous re-evaluation instead of a one-time gate at the perimeter. NIST SP 800-207 is the reference worth reading, mostly because it is vendor-neutral enough to argue with.

See also: [what is zero trust](https://startwithidentity.com/guides/fundamentals/what-is-zero-trust/), [conditional access](https://startwithidentity.com/glossary/conditional-access/), [ZTNA](https://startwithidentity.com/glossary/ztna/), [zero trust vendors](https://startwithidentity.com/vendors/zero-trust/)
