Skip to main content
Lightbridge Cloud A Lightbridge.ai company
SK Written by Sarika Krishnan with Robert LabardeeSenior Program Manager and Founder and CEO

DoD Zero Trust Architecture for CMMC Contractors

Lightbridge Cloud provides independent readiness guidance on DoD Zero Trust, the Department of Defense strategy and reference architecture that moves beyond reliance on perimeter defenses alone. It applies the zero trust concepts described in NIST SP 800-207, including per-request evaluation of access using identity, device, and other context. For a CMMC contractor using NIST SP 800-171 Revision 2, zero trust informs CUI architecture without replacing applicable requirements.

NIST SP 800-207 sets out seven basic tenets of zero trust.

NIST SP 800-207 is the National Institute of Standards and Technology publication that describes zero trust architecture for federal and nonfederal systems alike. Its seven basic tenets describe resources, communication, per-session access, dynamic policy, asset posture, dynamic authorization, and security information. The DoD reference architecture separately sets out five major tenets and seven pillars. These NIST tenets summarize the model.

Treat resources as resources

All data sources and computing services are considered resources, including services, devices, and other systems that can access enterprise resources.

Secure communication everywhere

All communication is secured regardless of network location. Being inside an enterprise network does not by itself imply trust or reduce the security requirements for a request.

Grant access per session

Access to individual enterprise resources is granted on a per-session basis, with only the least privileges needed to complete the task. Authorization to one resource does not automatically grant access to another.

Use dynamic policy

Access is determined by dynamic policy using observable identity, application or service, requesting asset, and relevant behavioral or environmental attributes.

Monitor asset posture

The enterprise monitors and measures the integrity and security posture of owned and associated assets. No asset is inherently trusted, and posture can inform how a resource request is handled.

Enforce dynamic authorization

Resource authentication and authorization are dynamic and strictly enforced before access is allowed, with continual reevaluation as the session and its context change.

Collect security information

The enterprise collects information about assets, network infrastructure, communications, and access, then uses it to improve security posture, policy creation, and enforcement.

The exact wording and emphasis shift between guidance documents. Confirm the current framing against the NIST publication itself before writing it into a policy or a contract deliverable.

The DoD Zero Trust Strategy organizes the model around seven pillars.

The Department of Defense published a Zero Trust Strategy and a companion reference architecture, issued by the DoD CIO, to move DoD component networks beyond reliance on perimeter-based defense alone and toward the NIST SP 800-207 model at scale. The reference architecture organizes zero trust capabilities across seven pillars, summarized below, while the DoD strategy defines target and advanced maturity levels that DoD networks work toward on a published timeline.

User

Identity verification, multifactor authentication, and privileged access management for every person who touches the environment, tied to continuous risk-based authentication rather than a single login event.

Device

Device inventory, health attestation, and compliance checks inform access decisions, so an unmanaged or noncompliant endpoint can be handled according to the environment's policy and risk.

Application and Workload

Securing applications and workloads themselves, including secure software development practices, application-layer access control, and runtime protection independent of network location.

Data

Data tagging, classification, and encryption so protection travels with the data itself, including controlled unclassified information, rather than depending on where the data happens to sit.

Network and Environment

Micro-segmentation and software-defined perimeters that isolate resources into small, tightly controlled zones instead of one large trusted network segment.

Automation and Orchestration

Automated policy enforcement and orchestrated response can coordinate access decisions and threat containment efficiently, while leaving room for manual review where policy or risk requires it.

Visibility and Analytics

Centralized logging and analytics across every pillar, giving the continuous telemetry that zero trust enforcement and a NIST SP 800-171 Revision 2 assessment can draw on.

The pillar definitions, the target and advanced level thresholds, and the DoD's own implementation timeline are revised periodically. Verify the current version against the DoD CIO before citing a specific date or maturity threshold in a proposal or a compliance artifact.

Zero trust principles can inform NIST SP 800-171 Revision 2 security-requirement families, but they do not replace them.

DoD's own reference architecture describes how the Department secures its own networks. A defense contractor is generally not required to reproduce that architecture wholesale on its own systems. What governs a contractor's controlled unclassified information environment is the applicable contract obligation and security requirements. For CMMC Level 2, the model incorporates the 110 security requirements in NIST SP 800-171 Revision 2. Zero trust matters here because several of its principles are effective, well-documented ways to implement or support those requirements.

Identity-centric access control and continuous verification support the Identification and Authentication and Access Control security-requirement families. Network segmentation that isolates the systems handling controlled unclassified information can reduce the assessment boundary an applicable assessor examines. Encryption of data in transit and at rest supports System and Communications Protection. Centralized, continuous logging supports Audit and Accountability. Framed this way, zero trust is an architectural strategy in service of a NIST SP 800-171 Revision 2 gap assessment, not a parallel checklist. See our guide on DFARS and NIST SP 800-171 for the full security-requirement picture, and how it relates to CMMC.

Lightbridge Cloud treats zero trust marketing built for generic enterprise security as a different problem from a CMMC-scoped CUI environment. A contractor sizing this work should start from the applicable security requirements and assessment objectives, not from a generic zero trust maturity model.

Use your CMMC level to scope zero trust-related work.

A CMMC level sets applicable security requirements and an assessment path; it does not prescribe a zero trust architecture. A practical program starts with the level a contract actually calls for, then uses risk and system scope to decide which zero trust capabilities may support that program.

CMMC Level 1: Foundational

Covers Federal Contract Information under the 15 security requirements in FAR 52.204-21. MFA and the CMMC Level 2 least-privilege requirement are not Level 1 requirements, although zero trust concepts may be used as optional design enhancements. A full zero trust architecture is beyond what Level 1 specifies.

CMMC Level 2: Advanced

Maps to the 110 security requirements in NIST SP 800-171 Revision 2 that protect controlled unclassified information. Zero trust principles can support implementation of requirements associated with the Access Control, Identification and Authentication, and Audit and Accountability CMMC domains.

CMMC Level 3: Expert

Adds 24 selected requirements from NIST SP 800-172 to the Level 2 requirements for the most sensitive programs. The CMMC model does not require a particular zero trust architecture or maturity across the DoD's seven pillars; additional segmentation, automation, or analytics should follow applicable requirements and risk.

Level thresholds and assessment objectives are set by the published CMMC model and are revised over time. Confirm the level a specific contract requires against its own clauses and the current DoD CIO guidance before committing to an architecture.

Lightbridge Cloud provides independent zero trust readiness advisory.

Lightbridge Cloud is an independent, vendor-neutral advisory firm. Its zero trust work is readiness and architecture advisory: mapping zero trust principles to the NIST SP 800-171 Revision 2 security requirements relevant to a CMMC Level 2 assessment, scoping the CUI enclave, and designing identity, segmentation, and logging architecture that supports evidence for the applicable assessment path. As of this guide's August 30, 2026 update, the DoD states that the CMMC program is paused in Phase I, where only Level 1 and Level 2 self-assessments may be required. Lightbridge does not claim to hold a zero trust certification, does not claim to be CMMC certified, and does not sell a partner-tier product line, so a platform or tooling recommendation follows what an environment actually needs.

This work connects directly to the rest of our CMMC and NIST SP 800-171 practice. For the underlying safeguarding and incident-reporting obligation, see DFARS and NIST SP 800-171. For the readiness program itself, including scoping, gap assessment, and assessment preparation, see CMMC compliance readiness.

This guide is general information, not legal, audit, or engineering advice. The DoD Zero Trust Strategy, its reference architecture, NIST SP 800-207, NIST SP 800-171 revisions, and the CMMC model change over time. Verify any specific date, pillar definition, maturity level, or security requirement against the official source, including the DoD CIO, NIST, and OUSD Acquisition and Sustainment, and consult qualified counsel for your situation. Lightbridge Cloud is independent and is not affiliated with, endorsed by, or a partner tier of any vendor.

DoD Zero Trust and CMMC: frequently asked questions

What is Zero Trust Architecture in simple terms?
Zero Trust Architecture is a security model built on the idea that no user, device, or application should receive implicit trust, even if it already sits inside a network perimeter. Instead, access is evaluated using identity, device posture, and other context under applicable policy. NIST SP 800-207 describes the model in detail. Lightbridge Cloud helps organizations apply these concepts as an independent advisor, without steering them toward any single vendor.
What is DoD Zero Trust and how is it different from generic zero trust?
DoD Zero Trust refers to the Department of Defense Zero Trust Strategy and its accompanying reference architecture, published by the DoD CIO. It applies zero trust concepts described by NIST SP 800-207, but ties them to a specific reference architecture, target and advanced maturity levels, and a timeline for DoD component networks. A defense contractor is generally not required to build the DoD's own reference architecture on its systems. What matters is applying zero trust principles to strengthen implementation of its NIST SP 800-171 Revision 2 security requirements. Those requirements predate the October 2022 DoD strategy; zero trust techniques can support their implementation, but the strategy is not their source. Verify current scope and timelines against the DoD CIO, since the strategy is updated over time.
What is NIST SP 800-207 and what are its core principles?
NIST SP 800-207 is the National Institute of Standards and Technology publication that describes zero trust architecture through seven basic tenets: treating data sources and computing services as resources, securing communication regardless of network location, granting access per session, using dynamic policy, monitoring asset posture, enforcing dynamic authentication and authorization, and collecting security information to improve the security posture. It describes concepts and components rather than one product or certification, so organizations can apply them through different combinations of identity, network, and data capabilities. Lightbridge Cloud uses the publication as an independent advisor without recommending a specific vendor stack.
Does CMMC require Zero Trust Architecture?
CMMC does not name zero trust as a standalone, separately scored requirement. CMMC Level 2 incorporates the 110 security requirements in NIST SP 800-171 Revision 2, and zero trust principles can support implementation of several of them, particularly those associated with access control, identification and authentication, and audit and accountability. As of this guide's August 30, 2026 update, the DoD states that the CMMC program is paused in Phase I, where only Level 1 and Level 2 self-assessments may be required. Any later C3PAO assessment requirement depends on the applicable rule and contract. Confirm current assessment objectives against the official CMMC model before scoping a program.
How does zero trust map to the NIST SP 800-171 Revision 2 security-requirement families?
Several NIST SP 800-171 Revision 2 security-requirement families overlap with zero trust principles. Identification and Authentication and Access Control align with identity-centric verification and least privilege. System and Communications Protection aligns with network segmentation and encryption of data in transit. Audit and Accountability aligns with logging and analytics. Configuration Management can inform device posture practices. The mapping is directional rather than one-to-one, so a gap assessment against the actual 110 security requirements is still the right starting point.
Which DoD Zero Trust pillars matter most for a CUI environment?
The DoD Zero Trust reference architecture is organized across seven pillars: User, Device, Application and Workload, Data, Network and Environment, Automation and Orchestration, and Visibility and Analytics. For a contractor scoping a controlled unclassified information environment, the applicable CMMC security requirements and the systems in scope should set priorities. The pillars can inform implementation, but CMMC does not prescribe a quantity of zero trust architecture or a maturity target across them. Verify the current pillar definitions against the DoD CIO reference architecture, since the model is revised periodically.
How does zero trust relate to DFARS and NIST SP 800-171 more broadly?
Zero trust is an architectural approach, not a separate regulatory requirement layered on top of DFARS and NIST SP 800-171. DFARS 252.204-7012 creates the obligation to provide adequate security for covered contractor information systems and, for applicable systems, points to NIST SP 800-171 requirements. CMMC Level 2 uses the 110 security requirements in Revision 2. The clause also permits approved nonapplicability or equally effective alternatives and additional measures. Zero trust principles can inform implementation of those requirements. Our companion guide on DFARS and NIST SP 800-171 explains the underlying obligation in full.
How does Lightbridge Cloud support zero trust readiness for CMMC?
Lightbridge Cloud is an independent, vendor-neutral advisory firm. It supports zero trust work as readiness and architecture advisory: mapping zero trust principles to the specific NIST SP 800-171 Revision 2 security requirements relevant to a CMMC Level 2 assessment, sizing the effort to the contractor's actual CMMC level, and designing identity, segmentation, and logging architecture that supports the evidence an applicable CMMC assessment can evaluate. Lightbridge does not claim to hold a zero trust certification or to be CMMC certified, and it does not sell a partner-tier product line, so recommendations are driven by fit rather than commission. Our CMMC compliance readiness service describes that scope in detail.

From zero trust principles to a defensible CUI architecture.

When the question shifts from what zero trust means to whether your CUI environment is ready for the applicable CMMC assessment, Lightbridge Cloud runs a vendor-neutral gap assessment and designs the path to close it.