Zero Trust
How to understand, apply and evolve Zero Trust to protect your organisation’s systems, data and users.
Pages
Page 12 of 18
Zero Trust Network Access (ZTNA)

sarayut Thaneerat via Getty Images
This guidance provides an overview of Zero Trust Network Access (ZTNA). It is primarily aimed at architects, security practitioners, and technical decision makers responsible for designing or evolving access networks, and will help them to prepare for and design a ZTNA architecture.
It is intended to support informed decision-making rather than prescribe a single ZTNA solution or implementation approach. Organisations should make decisions based on their existing architecture, risk appetite, and objectives.
How to use this guidance
The sections within this guidance are organised to guide the reader from understanding to implementation of ZTNA.
Sections 1 (Introduction to ZTNA) and 2 (Signals and policy engines) explain the underlying concepts and terminology, to build a solid understanding. Sections 3 (What to do before you start) and 4 (How to implement ZTNA) translate these ideas into practical guidance and recommend implementation approaches, describing the preparations and architectural properties needed before adopting ZTNA. Sections 5 (ZTNA reference architecture) and 6 (ZTNA anti-patterns) provide reference materials for additional detail and clarification.
Organisations should ensure they have a clear understanding of the core ZTNA concepts before making design or deployment decisions. After that, readers may find it useful to move between the implementation-focused sections as needed, returning to conceptual material to inform and refine design choices.
Contents
-
Introduction to ZTNA - introduces Zero Trust Network Access (ZTNA) and establishes a clear understanding of what it is intended to achieve. It defines the core concepts of ZTNA and addresses some common misconceptions.
-
Signals and policy engines - explains how policy decisions are made within a ZTNA architecture. It introduces the concept of signals, how they can be categorised, and what constitutes a baseline set of signals. It also describes the role of policy engines and how they are used within a ZTNA architecture to make and enforce access decisions.
-
What to do before building a ZTNA architecture - outlines the key prerequisites and preparatory steps organisations should consider before beginning the implementation of ZTNA.
-
How to implement ZTNA - introduces 8 high-level design requirements essential to a modern ZTNA implementation. These are intended to help organisations assess whether their ZTNA architecture includes the necessary features and capabilities.
-
ZTNA reference architecture - provides illustrative examples of using the design requirements to develop a ZTNA architecture, avoiding the identified anti‑patterns. It applies the concepts introduced throughout the guidance to show how they could be implemented in practice. These examples are illustrative only and should be adapted to meet an organisation’s specific use case and risk context.
-
ZTNA anti-patterns - describes 4 anti‑patterns identified by the NCSC, and aims to help organisations recognise them early to design them out of their ZTNA architectures.



