BLOG · GUIDE ·

Zero trust architecture for a mid-size company: where to start and in what order

Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software

IN BRIEF
  • Under NIST SP 800-207 (August 2020), zero trust grants no implicit trust based on network location or asset ownership, and each access to a resource is authenticated and authorised per session under a dynamic policy
  • CISA’s Zero Trust Maturity Model, written for US federal agencies, splits the work into five pillars (identity, devices, networks, applications and workloads, data), with visibility and analytics, automation and orchestration, and governance across them, and gives examples per pillar from traditional through initial and advanced to optimal
  • For SP 1800-35 (June 2025), NIST built 19 example implementations with 24 collaborators, starting with identity-based controls, which it calls “foundational components of ZTA”
  • For 200 to 2,000 staff we recommend this order: identity with phishing-resistant MFA, device inventory and posture, privileged access, separate management and backup networks, per-application access instead of a flat VPN, and central logging
  • The NIST CSF 2.0 document does not use the term zero trust; the outcomes sit mainly in its PR.AA and PR.IR categories, and NIS2 Recital 89 lists zero-trust principles among basic cyber hygiene practices

Eurokommerz × Vixen.UNO: Cyber Resilience  Talk to an expert →

Zero trust architecture and where a mid-size company starts

Zero trust architecture is a security design that gives no user or device implicit trust because of its network location or because the company owns it: every request to an application or data source is authenticated and authorised for that session, under a policy that checks the identity, the device and its state. For a company of 200 to 2,000 staff we recommend this order: identity with phishing-resistant multi-factor authentication, device inventory and posture, privileged access, separate networks for management and backup, per-application access in place of a flat VPN, and central logging that grows with each step.

The reference definition is NIST Special Publication 800-207, Zero Trust Architecture, of August 2020, which describes zero trust as moving defences from static, network-based boundaries to users, assets and resources. The UK National Cyber Security Centre (NCSC), in guidance of October 2025, lists “a product” among the things zero trust is not. A co-author of NIST’s implementation guide, quoted in NIST’s announcement of June 2025, said that “every ZTA is a custom build”.

NIST SP 800-207: the seven tenets in plain terms

The table sets the seven tenets of SP 800-207 next to what each changes in a mid-size estate.

TENETWHAT NIST SAYSIN A MID-SIZE ESTATE
Everything is a resource“All data sources and computing services are considered resources”laptops, SaaS, file shares, hypervisor management and BMCs come under one access policy
Location gives no trustall communication is secured, as “Network location alone does not imply trust”a request from the office network is checked like one from a hotel network
Access per sessionaccess per resource and session, “with the least privileges needed to complete the task”a sign-in to the ERP system opens no other system
Dynamic policythe policy includes the state of identity, application and requesting device, and may include behavioural and environmental attributesa known user on an unpatched laptop receives less access, or none
Posture is measuredthe company monitors and measures the integrity and security posture of all owned and associated assetsa laptop whose EDR agent stops reporting loses access
Enforced before accessauthentication and authorisation are dynamic and strictly enforced before accesssessions expire, and each new resource means a new check
Data improves policyas much data as possible on assets, network and communications is collected and used to improve securitysign-in and policy logs inform the next rule change

NIST SP 800-207, Zero Trust Architecture (August 2020), section 2.1; the right-hand column is our summary.

Three core logical components carry this out. The policy engine makes “the ultimate decision to grant access to a resource for a given subject”, the policy administrator establishes or shuts down the communication path, and the policy enforcement point enables, monitors and terminates the connection. In a company of 200 to 2,000 staff the access policies of the identity provider can act as the engine, and application proxies, firewalls, VPN gateways and endpoint agents as enforcement points. NIST expects most enterprises to run a hybrid of zero trust and their existing network-based design while they modernise.

CISA zero trust maturity model: five pillars and a self-assessment

CISA’s Zero Trust Maturity Model was written for US federal agencies. The US Office of Management and Budget organised its agencies’ zero trust goals by this model in memorandum M-22-09 of 26 January 2022, which describes five pillars: identity, devices, networks, applications and workloads, and data. Visibility and analytics, automation and orchestration, and governance run across all five. For each pillar, CISA’s own page on the model lists examples of traditional, initial, advanced and optimal zero trust architectures.

Under identity, for example, the OMB strategy says agencies “must require their users to use a phishing-resistant method to access agency-hosted accounts”. A mid-size company can use the pillars as a self-assessment without adopting the federal targets:

  1. Rate each pillar from evidence, such as the share of accounts with MFA, of devices enrolled in MDM and of applications reached through a policy check.
  2. List the systems that cannot reach the target, such as applications without modern authentication, and the control that compensates for each.
  3. Set one target per pillar for the next budget period, and expect the pillars to move at different speeds.
  4. Repeat the rating after each step of the roadmap below.

Our Cyber Resilience assessment covers infrastructure, access and backups and ends with a risk map and a prioritised action plan. Send us your rating per pillar and the systems you expect to remain exceptions.

NIST SP 1800-35: the 19 example implementations and their order

NIST finalised its practice guide SP 1800-35, Implementing a Zero Trust Architecture, in June 2025. It documents 19 example implementations built with 24 collaborators from commercially available technology. The web edition maps the reference design and the capabilities used in the builds to CSF 2.0 subcategories and SP 800-53 controls, among other references. The project began with enhanced identity governance (EIG); in NIST’s words, “Our first implementations with minimum viable solutions were EIG deployments because the identity-based controls provided by EIG are foundational components of ZTA.” That phase ran first without cloud capabilities and then with them, and microsegmentation, SDP and secure access service edge (SASE) builds came afterwards.

For that phase the guide treats authentication and periodic reauthentication of users and endpoints as fundamental, and endpoint health checks as highly desirable. Its takeaways begin with an inventory of all assets, ask for critical resources to be isolated in their own trust zones, and note that implementation may begin with tools that continuously monitor the environment. The project also found that zero trust products from different vendors need more integration, so check how device signals reach the access policy before buying more tools.

A zero trust roadmap in six steps for 200 to 2,000 staff

Start with the inventory that NIST and the NCSC both put first; the NCSC’s first principle is “Know your architecture including users, devices, services and data”. List accounts of every kind, devices, applications with the networks they are reached from, and the administration interfaces of hypervisors, backup servers, firewalls and BMCs.

STEP, IN ORDERCONTROLSWHAT IT REMOVES
Identity and MFAone authoritative directory; phishing-resistant MFA first for administrators, remote access and email; sign-in protocols that bypass MFA turned offsign-in with a phished or stolen password
Devices and postureMDM enrolment, EDR, disk encryption and patch level as conditions of accessaccess from unknown, unmanaged or unpatched devices
Privileged accessseparate administrator accounts and workstations, time-limited elevation, service account credentials in a vaultstanding administrator rights that come with one stolen account
Admin and backup networksseparate segments for hypervisor, BMC, backup and firewall management, reached only from administrator workstationsa route from user networks to management interfaces
Per-application accessa gateway or proxy in front of each application, with identity and device checks; VPN rules narrowed per rolenetwork-wide reach after one VPN sign-in
Central loggingsign-in, administrator, policy decision and EDR events in a SIEM, with alerts and retentiongaps in the record of who reached what

The order and the controls are our recommendation, drawing on NIST SP 800-207 (2020) and SP 1800-35 (2025), OMB memorandum M-22-09 (2022) and the NCSC’s zero trust guidance (reviewed 16 January 2026).

Identity comes first because each later decision needs a verified user, and contractors and service accounts need managed identities as much as staff do. Our guide to phishing-resistant MFA compares the methods and where to enforce them first.

For devices, OMB’s strategy requires agencies to consider “at least one device-level signal” alongside identity; in this roadmap, an unenrolled, unencrypted or unpatched laptop is refused. Personal and suppliers’ devices get a narrower path, such as browser access to selected applications.

Administrator accounts should be used only from administrator workstations, never for email or web browsing. Vaults, just-in-time access and break-glass accounts are covered in the guide to privileged access management.

The fourth step moves hypervisor management, BMCs, backup servers and firewall management onto their own segments, reached only from administrator workstations, with backup credentials kept out of the production directory. Implementing Regulation (EU) 2024/2690 asks the digital providers it covers to “separate the dedicated network for administration of network and information systems” from the operational network (point 6.8.2(f)). Zones and their flows are set out in the guide to network segmentation and microsegmentation.

Logging sits last in the table because it gains value with each step, but collection starts with step one. Which tool collects what is explained in our comparison of EDR, XDR, SIEM and MDR.

Our Cyber Resilience service builds such an architecture following NIST CSF 2.0, with network segmentation, multi-factor authentication, privileged access management, MDM and DLP. Tell us which of the six steps are in place and which systems still accept a password alone.

Application access without a flat VPN

A remote-access VPN that places users on the internal network gives each connected device whatever reach the routing and firewall rules allow, often entire server subnets. SP 800-207 lists among its network requirements that remote enterprise assets “should be able to access enterprise resources without needing to traverse enterprise network infrastructure first”; its example is email hosted by a public cloud provider, reached without a VPN. OMB’s strategy says MFA should be “integrated at the application layer” rather than through network authentication such as a VPN. In a zero trust design an enforcement point, such as an identity-aware proxy, an application gateway or an agent, sits in front of each application.

The NCSC cautions against making this the aim: “Finding a replacement for your VPN should not be the goal of adopting ZT”. It advises keeping existing controls until the zero trust architecture provides equivalent or stronger protection, and not inherently trusting traffic that arrives through a VPN that stays. A mid-size company can start with web applications and supplier access, giving a supplier one application for a limited time, and narrow the VPN rules per role for what remains.

Zero trust in NIST CSF 2.0 and NIS2

The NIST CSF 2.0 document of 26 February 2024 does not use the term zero trust. The outcomes a zero trust programme delivers sit mainly in its Protect function. Identity Management, Authentication, and Access Control (PR.AA) covers managed identities and credentials (PR.AA-01), authentication of “Users, services, and hardware” (PR.AA-03) and access that incorporates “the principles of least privilege and separation of duties” (PR.AA-05). PR.IR-01 asks that networks and environments be protected from unauthorised logical access and usage. Inventories sit under ID.AM, log records under PR.PS-04 and monitoring under DE.CM.

NIS2 mentions zero trust in Recital 89 of Directive (EU) 2022/2555, which lists “zero-trust principles” among the basic cyber hygiene practices essential and important entities should adopt. Article 21(2) asks for “access control policies and asset management” in point (i) and, where appropriate, for “multi-factor authentication or continuous authentication solutions” in point (j). Our guide to NIS2 Article 21 covers all ten measures; whether NIS2 applies to a company is a legal assessment for its legal department.

Zero trust for SMB and mid-size companies: what can wait

The NCSC writes that zero trust “can be costly, disruptive and resource-intensive” and that full migration may require rearchitecting many systems over several years. Its guidance starts from the organisation’s specific security challenges. For 200 to 2,000 staff we would start with the first four steps, which remove standing trust from the accounts and networks that control everything else and can often build on the directory, MDM, EDR and firewalls already in place.

Microsegmentation of every server-to-server flow, data classification with DLP across all repositories, automated responses to behavioural signals and the optimal stage in any pillar can follow later. Exceptions need an owner from the start, among them applications without modern authentication, production machines that cannot run an agent, shared accounts and break-glass accounts. Give each a compensating control, such as a dedicated segment or a gateway, and a review date, and raise an alert on every use of a break-glass account.

What we do

Under Cyber Resilience, our engineering partner Vixen.UNO builds zero-trust architectures following NIST CSF 2.0, with network segmentation, multi-factor authentication, privileged access management, mobile device management (MDM) and data loss prevention (DLP). The same service covers firewalls, EDR/XDR on workstations and servers and event centralisation in a SIEM, on Trend Micro, Cisco and other vendors’ solutions. The technical assessment that follows the first call ends with a risk map and a prioritised action plan, and changes roll out step by step in agreed maintenance windows with a rollback plan. During the project Vixen.UNO works in your environment under your access controls, as our security and compliance page describes. Eurokommerz holds the contract; the first call is free of charge, and the price of the technical assessment is fixed before work begins.

FAQ

What is zero trust architecture?
Zero trust architecture is a security design that gives no user or device implicit trust because of its network location or ownership, and authenticates and authorises each request to a resource per session under a dynamic policy. NIST defines it in Special Publication 800-207 of August 2020, with seven tenets and three core logical components: a policy engine, a policy administrator and policy enforcement points.
How do you implement zero trust in a mid-size company?
Start with an inventory of hardware, software, applications, data and services, which NIST’s SP 1800-35 names as the first step, and of the accounts that reach them. Then, in the order we recommend, work through identity with phishing-resistant MFA, device inventory and posture, privileged access, separate management and backup networks, per-application access in place of a flat VPN, and central logging that grows with each step. NIST’s own example implementations began with identity-based controls, which it calls foundational.
What is the CISA Zero Trust Maturity Model?
It is CISA’s model for US federal agencies, which organises zero trust into five pillars (identity, devices, networks, applications and workloads, data), with visibility and analytics, automation and orchestration, and governance across them. For each pillar it gives examples of traditional, initial, advanced and optimal zero trust architectures. A mid-size company can use it as a self-assessment, rating each pillar from evidence without adopting the federal targets.
What are the seven tenets of zero trust in NIST SP 800-207?
Every data source and computing service is a resource, all communication is secured regardless of network location, and access to each resource is granted per session. Access follows a dynamic policy that includes the state of identity, application and device; the enterprise monitors the integrity and security posture of all owned and associated assets; authentication and authorisation are dynamic and enforced before access; and the enterprise collects data on its assets, network and communications to improve its security posture.
Does zero trust replace the VPN?
Zero trust allows a VPN to be replaced but does not require it. SP 800-207 says remote enterprise assets should be able to reach enterprise resources without traversing the enterprise network first, while the UK NCSC says replacing the VPN should not be the goal and that existing controls should stay until the zero trust architecture gives equivalent or stronger protection. We recommend per-application access for web applications and suppliers first, with the VPN narrowed for what remains.
Is zero trust realistic for an SMB or mid-size company?
Yes, when the scope follows risk rather than a maturity target: we would put identity, devices, administrator accounts and the management and backup networks first, and they can often start with the directory, MDM, EDR and firewalls already in place. The UK NCSC notes that zero trust can be costly and disruptive and that full migration may require rearchitecting many systems over several years, so east-west microsegmentation, data classification and automation can follow later.

Send us your headcount and sites, how staff and administrators sign in today, how remote staff and suppliers reach internal applications, and which of the six steps are in place. We reply within one business day to arrange a first call, from which you leave with two or three possible solution scenarios. The first call is free of charge.

Talk to an expert
Talk to an expert

We reply within one business day

By sending this form you agree that we process your details to answer your enquiry – see our privacy policy.

request@eurokommerz.at
Jordangasse 7, 1010 Vienna