Most enterprises claim to be "doing zero trust," but Gartner says only 10% will have a mature program by year's end. Here's the data behind the gap.
The GetCoreTech Team Sep 13, 2026 · 9 min read
Zero Trust in 2026: The Data Behind Why Most Programs Still Aren't What They Claim
By Gartner's own forecast, only 10% of large enterprises will have a mature, measurable zero trust program in place by the end of 2026 — up from less than 1% in 2023 — even though a large majority of organizations now claim to be "doing zero trust" in some form. That gap between claimed adoption and measured maturity is the actual story in 2026, not whether zero trust "works." The framework hasn't changed much this year; the honest accounting of who's actually implemented it has.
The Term Has Drifted Further From the Framework Than the Data Suggests
Zero trust has a specific technical definition, laid out in NIST SP 800-207 and operationalized for the federal government through CISA's Zero Trust Maturity Model (ZTMM). The model scores an organization across five pillars — Identity, Devices, Networks, Applications and Workloads, and Data — on a four-stage scale from Traditional to Optimal.
What's easy to miss, because so much 2026 marketing copy references "the latest zero trust framework," is that CISA's ZTMM hasn't actually been updated since version 2.0 in April 2023. Security teams researching the topic in 2026 repeatedly ask whether a newer version exists; it doesn't. The three-year-old document remains the current federal standard, which means every vendor claim about being aligned to "current" zero trust guidance is, at minimum, referencing a framework from before most of today's AI-driven attack surface existed.
The Federal Deadline That Already Passed
The clearest test case for "does zero trust marketing match zero trust reality" isn't a vendor at all — it's the U.S. federal government, which had a hard, legally documented deadline. OMB Memorandum M-22-09, issued in January 2022 under Executive Order 14028, required federal civilian agencies to meet specific zero trust objectives — phishing-resistant multi-factor authentication, a complete device inventory, encrypted DNS and HTTP traffic, and more — by the end of fiscal year 2024, which closed on September 30, 2024.
That deadline has now been gone for nearly two years. CISA's own January 2025 report to Congress on federal zero trust implementation, and inspector-general assessments at individual agencies, describe uneven results rather than a clean pass: agencies at dramatically different points of maturity, some meeting requirements only through documented compensating controls rather than full technical compliance. OMB followed up with M-25-04 in January 2025, explicitly directing agencies to keep maturing their architectures — language that wouldn't be necessary if the FY 2024 goals had actually closed the gap. Zero trust maturation is now baked into OMB's FY 2026 budget cybersecurity priorities under M-24-14, which is itself an admission that this remains an active, funded, multi-year build rather than a completed initiative.
If a legally mandated program with a hard deadline and a dedicated oversight agency hasn't reached full maturity, that's a useful baseline for how much skepticism a vendor's "we deliver zero trust" claim deserves.
What the Maturity Numbers Actually Say
Beyond the federal case, private-sector data tells a consistent story: broad adoption of the label, thin adoption of the substance.
Okta's State of Zero Trust Security report — the most recent edition with a full published dataset covers 2023 — found 61% of organizations had launched some form of zero trust initiative, up from 24% in 2021. That's real movement. But "launched an initiative" and "operating a mature architecture" are different claims, and the same survey data points to why: identity sprawl, with the average enterprise running dozens of disconnected identity stores that don't share signal with each other — which is precisely the kind of fragmentation the Identity pillar is supposed to eliminate.
Gartner's maturity benchmark is the more direct read. Its 2023 forecast — reiterated in Gartner's 2025 Strategic Roadmap for Zero Trust — puts the share of large enterprises with a mature, measurable program at just 10% by the end of 2026. Multiple industry surveys published this year land in a similar range: one widely cited 2026 zero trust market report puts full implementation at 17% of organizations, even though 82% consider zero trust essential to their security strategy. Whatever the exact percentage, every credible source describes the same pattern — a wide gap between organizations that have adopted the language and posture of zero trust and the smaller subset that can actually demonstrate Advanced or Optimal maturity against a defined framework like CISA's ZTMM.
The Cost Data That Justifies the Effort Anyway
None of this means zero trust is failing to deliver where it's genuinely implemented — the opposite case is also well documented. IBM's 2025 Cost of a Data Breach Report lists zero trust architecture among the largest measurable cost mitigators, associated with roughly $1.76 million in average breach-cost savings, behind only a tested incident response plan and extensive AI/automation use in security operations. Given that credential compromise remains one of the most common initial access vectors in breach data, an architecture built around continuously verifying identity rather than trusting network location is addressing a real, current risk — not a theoretical one.
That's the nuance vendor marketing tends to flatten: zero trust isn't hype in the sense of being ineffective. It's hype in the sense that the word gets applied to security postures that haven't reached the point where the framework's own benefits would show up.
The Actual New Problem: Zero Trust Wasn't Built for Machines
Here's the part of the 2026 landscape that's genuinely different from prior years, rather than a continuation of the same maturity-gap story: the identity pillar that most zero trust programs spent years hardening was built almost entirely around human users, and the fastest-growing category of identity in the enterprise now isn't human at all.
Non-human identities — service accounts, API keys, OAuth tokens, workload credentials, and increasingly autonomous AI agent credentials — have grown fast enough that estimates of how far they outnumber human accounts vary widely by source and methodology: KPMG's Cybersecurity Considerations 2026 report puts the ratio at roughly 80 to 1 in the average enterprise, while Cloud Security Alliance research citing Entro Security data puts it at 144 to 1 in cloud-native environments specifically, up from 92 to 1 just two years earlier. The wide spread between estimates is itself telling — it means most organizations don't have a precise count of their own non-human identities, which is a Visibility and Analytics failure at the exact cross-cutting capability CISA's model treats as foundational.
The structural problem is that non-human identities can't do the things human-centric zero trust controls rely on. They can't complete multi-factor authentication. They rarely get deactivated when a project ends. And unlike a human account, a compromised or over-permissioned AI agent credential can chain actions across multiple systems in seconds, which is a fundamentally different threat model than a single stolen employee password. Extending continuous verification and least-privilege enforcement to machine and agent identities — not just adding another human-focused MFA rollout — is the specific, concrete work that separates a 2026 zero trust program built for the current threat surface from one still describing a 2022 architecture with a fresh coat of marketing.
Where the Real Debate Still Sits
There's genuine, unresolved disagreement about sequencing this work, not just execution speed. Federal zero trust guidance for the Department of Defense sets separate target-level and advanced-level deadlines (FY 2027 and FY 2032, respectively) precisely because pillars have dependencies — automation tooling like SOAR, for instance, depends on standardized APIs and enriched telemetry being in place first, which means organizations that buy visible, marketable tools out of sequence often generate rework rather than progress. That's a planning problem more than a marketing problem, but it compounds the same underlying issue: it's easy to demonstrate zero trust activity, and much harder to demonstrate zero trust maturity.
What This Means for a Security Leader Evaluating a Vendor Claim Right Now
Ask which pillar and which stage, not just the word. A credible claim references a specific CISA ZTMM pillar (Identity, Devices, Networks, Applications and Workloads, Data) and stage (Traditional, Initial, Advanced, Optimal) — not just "we enable zero trust."
Treat the framework's age as a fact, not a criticism. CISA's ZTMM v2.0 dates to April 2023. That's not disqualifying, but "aligned to the latest zero trust guidance" should not be read as "current with 2026's threat surface" without checking what it actually covers.
Ask specifically about non-human and agentic identity coverage. If a vendor's zero trust pitch is entirely about human user authentication, it's addressing last decade's identity problem, not this year's fastest-growing one.
Use the federal timeline as a sanity check. If a legally mandated program with dedicated funding and oversight is still working toward full maturity years past its deadline, "we're fully zero trust" from a private vendor deserves the same scrutiny you'd apply to any other unverified claim.
FAQ
Q: Is zero trust actually a real security framework, or is it just marketing?
A: It's a real, specific technical framework — defined in NIST SP 800-207 and operationalized through CISA's Zero Trust Maturity Model, which scores organizations across five pillars and four maturity stages. The "marketing" problem isn't that the framework is fake; it's that the term gets applied loosely to security postures that haven't been measured against that framework at all.
Q: How mature is zero trust adoption really, in 2026?
A: By Gartner's benchmark, only about 10% of large enterprises will have a mature, measurable zero trust program by the end of 2026, even though a majority describe themselves as having some zero trust initiative underway. Other 2026 industry surveys report full implementation rates in the high teens as a percentage of organizations. The consistent theme across sources is a large gap between claimed adoption and demonstrated maturity.
Q: Did federal agencies meet the government's zero trust deadline?
A: The deadline set by OMB Memorandum M-22-09 for specific zero trust objectives was the end of fiscal year 2024 (September 30, 2024). CISA's reporting and individual agency inspector-general assessments describe uneven progress rather than full compliance, and subsequent OMB guidance in 2025 explicitly directs agencies to continue maturing their architectures — indicating the work is ongoing rather than complete.
Q: What's the biggest zero trust gap that most organizations aren't addressing?
A: Extending zero trust principles — continuous verification, least privilege, no implicit trust — to non-human identities: service accounts, API keys, and especially autonomous AI agent credentials. Estimates vary, but multiple 2026 industry reports put non-human identities at 80-to-1 or higher relative to human accounts in the average enterprise, and most existing zero trust deployments were built around controls, like MFA, that only work for human users.
Q: Does implementing zero trust actually reduce breach costs?
A: According to IBM's 2025 Cost of a Data Breach Report, organizations with zero trust architecture in place saw meaningfully lower average breach costs — roughly $1.76 million in savings — making it one of the largest documented cost mitigators in that year's data, behind incident response planning and extensive AI/automation use in security operations.
Q: Is CISA planning to update the Zero Trust Maturity Model?
A: As of mid-2026, CISA's Zero Trust Maturity Model remains at version 2.0, published in April 2023, with no newer version released. Organizations citing "the latest CISA zero trust guidance" are referencing a document that predates significant parts of the current AI-driven threat landscape.
FAQ
It's a real, specific technical framework — defined in NIST SP 800-207 and operationalized through CISA's Zero Trust Maturity Model, which scores organizations across five pillars and four maturity stages. The "marketing" problem isn't that the framework is fake; it's that the term gets applied loosely to security postures that haven't been measured against that framework at all.
By Gartner's benchmark, only about 10% of large enterprises will have a mature, measurable zero trust program by the end of 2026, even though a majority describe themselves as having some zero trust initiative underway. Other 2026 industry surveys report full implementation rates in the high teens as a percentage of organizations. The consistent theme across sources is a large gap between claimed adoption and demonstrated maturity.
The deadline set by OMB Memorandum M-22-09 for specific zero trust objectives was the end of fiscal year 2024 (September 30, 2024). CISA's reporting and individual agency inspector-general assessments describe uneven progress rather than full compliance, and subsequent OMB guidance in 2025 explicitly directs agencies to continue maturing their architectures — indicating the work is ongoing rather than complete.
Extending zero trust principles — continuous verification, least privilege, no implicit trust — to non-human identities: service accounts, API keys, and especially autonomous AI agent credentials. Estimates vary, but multiple 2026 industry reports put non-human identities at 80-to-1 or higher relative to human accounts in the average enterprise, and most existing zero trust deployments were built around controls, like MFA, that only work for human users.
According to IBM's 2025 Cost of a Data Breach Report, organizations with zero trust architecture in place saw meaningfully lower average breach costs — roughly $1.76 million in savings — making it one of the largest documented cost mitigators in that year's data, behind incident response planning and extensive AI/automation use in security operations.
As of mid-2026, CISA's Zero Trust Maturity Model remains at version 2.0, published in April 2023, with no newer version released. Organizations citing "the latest CISA zero trust guidance" are referencing a document that predates significant parts of the current AI-driven threat landscape.
The GetCoreTech Team
We write about the SaaS, AI, and infrastructure decisions builders actually have to make.
Comments
Log in or sign up to join the discussion.
Loading comments…