Designing secure access with ZTNA
ZTNA is widely deployed, but often still built on old trust assumptions. New NCSC guidance explains how to design ZTNA architectures aligned with zero trust principles.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
ZTNA is widely deployed, but often still built on old trust assumptions. New NCSC guidance explains how to design ZTNA architectures aligned with zero trust principles.

sasha85ru via Getty Images
Zero Trust Network Access (ZTNA) is often introduced to modernise access to applications. However, without changes to the underlying design, these deployments can continue to reflect older models of trust.
In many cases, ZTNA tools are deployed in environments that still treat network location as a primary signal of trust. This means the tools may be new, but the underlying approach continues to rely on broad, network-based access rather than more granular, context-driven decisions.
Our new guidance explains how organisations can design and implement ZTNA in a way that better aligns with zero trust principles, and supports modern network environments.
The guidance focuses specifically on network access within a broader zero trust architecture. It:
This guidance does not redefine zero trust, or prescribe a single technical solution, and is not intended to be used as a checklist or compliance framework. ZTNA decisions should always be shaped by an organisation’s users, systems, threats, and operational constraints.
This guidance is primarily aimed at architects, security practitioners, and technical decision-makers responsible for designing or evolving access architectures.
It will be useful whether you are:
We recommend starting with the introductory sections to build an understanding of the core concepts of ZTNA before moving on to the sections on prerequisites and design requirements to help plan and implement your architecture. The final section on anti-patterns is particularly important because we see many ZTNA deployments fail, not because of missing technology features, but because legacy trust assumptions are carried forward into new designs.
As with all the NCSC’s zero trust guidance, ZTNA should be considered as part of a wider architectural approach, rather than a standalone solution.
If you have feedback on the guidance, please contact us at [email protected]


