Skip to main content

Designing secure access with ZTNA

ZTNA is widely deployed, but often still built on old trust assumptions. New NCSC guidance explains how to design ZTNA architectures aligned with zero trust principles.

,
Network connection concept. Zero trust security model. Secure network. 3d render

sasha85ru via Getty Images

Zero Trust Network Access (ZTNA) is often introduced to modernise access to applications. However, without changes to the underlying design, these deployments can continue to reflect older models of trust.

In many cases, ZTNA tools are deployed in environments that still treat network location as a primary signal of trust. This means the tools may be new, but the underlying approach continues to rely on broad, network-based access rather than more granular, context-driven decisions.

Our new guidance explains how organisations can design and implement ZTNA in a way that better aligns with zero trust principles, and supports modern network environments.


What this guidance covers

The guidance focuses specifically on network access within a broader zero trust architecture. It:

  • Explains what ZTNA is, and how it differs from traditional ‘walled garden’ approaches to access.
  • Outlines the organisational and technical foundations needed before starting a ZTNA deployment.  
  • Describes key design requirements that ZTNA architectures should meet.  
  • Provides a simple reference architecture showing how ZTNA can be used to access private applications and Software as a Service (SaaS). 
  • Highlights common anti-patterns that can undermine ZTNA.  

This guidance does not redefine zero trust, or prescribe a single technical solution, and is not intended to be used as a checklist or compliance framework. ZTNA decisions should always be shaped by an organisation’s users, systems, threats, and operational constraints. 


Who the guidance is for

This guidance is primarily aimed at architects, security practitioners, and technical decision-makers responsible for designing or evolving access architectures. 

It will be useful whether you are: 

  • exploring ZTNA as part of a broader zero trust strategy
  • replacing or reducing reliance on legacy ‘walled garden’ architecture
  • reviewing an existing ZTNA deployment to check whether it delivers the expected security outcomes

How to use the guidance

We recommend starting with the introductory sections to build an understanding of the core concepts of ZTNA before moving on to the sections on prerequisites and design requirements to help plan and implement your architecture. The final section on anti-patterns is particularly important because we see many ZTNA deployments fail, not because of missing technology features, but because legacy trust assumptions are carried forward into new designs.  

As with all the NCSC’s zero trust guidance, ZTNA should be considered as part of a wider architectural approach, rather than a standalone solution. 

If you have feedback on the guidance, please contact us at [email protected]

Lili C and Peter R
Security Architects, NCSC

Written by

Peter R NCSC Senior Security Architect
Lili C NCSC Senior Security Architect