Quick Takeaways
What you'll learn in this article
- 1
Organizations implementing zero trust reduced the likelihood of a successful breach by up to 50 percent (Microsoft research)
- 2
Mature zero trust organizations experience 50 percent fewer security incidents and recover 40 percent faster from breaches (Forrester)
- 3
Companies with mature zero trust strategies save roughly $1 million less in breach costs on average
- 4
Zscaler research estimated zero trust could reduce global annual cyber economic losses by up to 31 percent โ a projected reduction of up to $465 billion
Keep reading for detailed implementation, code examples, and real-world results
Updated (February 2026): Complete rewrite replacing generic overview with current zero trust landscape including identity-first security (passkeys, ITDR, non-human identities), ZTNA vendor landscape and performance benchmarks, microsegmentation rankings, SASE convergence with the 2025 Gartner Magic Quadrant, cloud-native zero trust with SPIFFE/SPIRE, AI-specific threats, confidential computing, real-world deployments (BeyondCorp, DoD Thunderdome, Microsoft SFI), and the $25B CyberArk and $32B Wiz acquisitions.
The Gap Between Adoption and Maturity
Zero trust has won the narrative. In a survey of over 2,200 IT and business leaders, 43 percent have adopted zero trust principles, 46 percent are in the process of moving to zero trust, and just 11 percent have no implementation underway. The zero trust architecture market is estimated at $22 to $29 billion in 2025, projected to reach $60 to $73 billion by 2032.
But adoption and maturity are different things. Gartner predicts that by 2026, only 10 percent of large enterprises will have a mature, measurable zero trust program in place โ up from less than 1 percent previously. Through 2026, 75 percent of US federal agencies will fail to fully implement zero trust security policies due to funding and expertise shortfalls, despite the OMB M-22-09 mandate that set a compliance deadline for FY2024.
The money flowing into cloud security signals the stakes. Google is acquiring Wiz for $32 billion. Palo Alto Networks completed its $25 billion acquisition of CyberArk in February 2026. Netskope went public in September 2025 at a $7.3 billion valuation. Eight cybersecurity acquisitions exceeded $1 billion in 2025, and overall cybersecurity startup funding hit $18 billion โ up 26 percent from 2024.
Zero trust is no longer theoretical. The question is whether organizations are building it fast enough.
Zero Trust Market
$29B
Estimated zero trust architecture market in 2025, projected to reach $60-73 billion by 2032 at 17-18% CAGR
Identity Is the New Perimeter
Every zero trust architecture starts with identity. More than 80 percent of data breaches involve compromised identities according to the 2025 Verizon DBIR. The shift from network-centric to identity-centric security is not optional โ it is the foundational layer on which everything else rests.
The Passkey Revolution
FIDO2 passkeys have reached critical mass. Over 1 billion people have activated at least one passkey, and over 15 billion online accounts support passkey authentication globally. Nearly half (48 percent) of the top 100 websites offer passkeys, more than double the rate in 2022.
The enterprise numbers are equally striking: 87 percent of organizations have either deployed or are deploying enterprise passkeys, up 14 percentage points from 2022. Ninety percent reported moderate-to-strong security improvements, 82 percent noted positive user experience effects, and 77 percent observed reduced help desk calls.
The inflection point was Microsoft making passkeys the default for new accounts in May 2025, triggering a 120 percent increase in passkey-based authentication. Synced passkeys take roughly 3 seconds to authenticate versus 24 seconds for password sign-in. Google reports over 800 million accounts using passkeys, and Amazon saw 175 million users create passkeys in the first year.
For federal agencies, OMB M-22-09 mandates phishing-resistant MFA. Microsoft's Secure Future Initiative โ described as the largest cybersecurity engineering effort in digital history, with the equivalent of 35,000 full-time engineers โ enforced phishing-resistant MFA for 99.6 percent of Microsoft employees and devices by November 2025.
Identity Threat Detection and Response
ITDR has emerged as the critical layer between authentication and authorization. The global ITDR market is projected to grow from $12.8 billion in 2024 to $35.6 billion by 2029 at a 22.6 percent CAGR. CyberArk was named overall leader in the 2025 KuppingerCole ITDR Leadership Compass.
ITDR fills the "post-authentication gap" โ the space where a valid credential has been presented but the behavior does not match expectations. It continuously monitors identity behavior across pre-login signals, authentication patterns, active sessions, and privilege use. Traditional MFA stops at the door; ITDR watches what happens after entry.
The Non-Human Identity Crisis
The most underrated zero trust challenge is machine identity. Non-human identities โ service accounts, API keys, certificates, machine tokens โ now outnumber human identities by ratios of 40:1 to over 100:1 in enterprises, with some organizations reporting 500:1. Eighty percent of identity-related breaches involve compromised non-human identities, and the 2025 State of Non-Human Identities report from Entro Security found 97 percent of NHIs have excessive privileges.
According to Gartner's 2024 Identity Security Report, 60 percent of organizations cannot see their non-human identities in real time. Gartner highlighted non-human identity management as a top 2025 strategic trend and published its first dedicated reports on Machine Identity and Access Management.
This is precisely why Palo Alto Networks acquired CyberArk for $25 billion. CEO Nikesh Arora cited that machine and AI identities outnumber human users 80:1 at large enterprises โ and that gap is accelerating as AI agents proliferate.
Identity Security Adoption Metrics (2025-2026)
| category | value |
|---|---|
| Passkey users (billions) | 1 |
| Accounts w/ passkeys (billions) | 15 |
| Top 100 sites w/ passkeys (%) | 48 |
| Enterprise passkey adoption (%) | 87 |
| MS phishing-resistant MFA (%) | 99.6 |
ZTNA: VPNs Are Being Replaced
Gartner predicted that by 2025, at least 70 percent of new remote access deployments would rely on ZTNA rather than VPN services, up from less than 10 percent in 2021. Current data shows 26 percent of organizations have already deployed ZTNA, with another 53 percent in progress. The ZTNA market is projected to rise from $1.34 billion in 2025 to $4.18 billion by 2030 at a 25.5 percent CAGR.
The Vendor Landscape
The competitive dynamics have shifted significantly in 2025:
Zscaler reported fiscal year 2025 revenue of $2.67 billion (23 percent YoY growth) with over $3.2 billion in ARR. In January 2025, Zscaler partnered with SAP to integrate ZTNA natively into SAP RISE. However, Zscaler was placed as a "visionary" rather than a "leader" in the 2025 Gartner Magic Quadrant for SASE Platforms.
Cloudflare posted Q4 2025 revenue of $615 million (34 percent YoY growth) and claims 46 percent faster ZTNA performance than Zscaler and 56 percent faster than Netskope. With 4,298 customers spending over $100K annually, Cloudflare moved up to "visionary" from "niche player" in the 2025 Gartner SASE Magic Quadrant.
Netskope went public in September 2025 at $19 per share with a $7.3 billion valuation, soaring 18 percent on the first day of trading to an $8.6 billion market cap. Revenue was $328 million for the six months ending July 2025, up from $251 million the prior year. Named a "leader" in the 2025 Gartner SASE Magic Quadrant.
Palo Alto Networks (Prisma Access) was named a "leader" in all three editions of the Gartner SASE Magic Quadrant. Prisma Access delivers ZTNA through combined agent-based and agentless approaches.
ZTNA 2.0
Coined by Palo Alto Networks, ZTNA 2.0 addresses the limitations of first-generation ZTNA: least-privileged access at sub-application levels using App-IDs at Layer 7, continuous trust verification based on device posture and user behavior changes, continuous security inspection of all traffic including allowed connections, and unified DLP policy enforcement across all applications. First-generation ZTNA granted access and then trusted the connection โ ZTNA 2.0 never stops verifying.
ZTNA Vendor Performance (2025)
Cloudflare Access
Zscaler
Microsegmentation: Limiting Blast Radius
Microsegmentation โ enforcing least-privilege access between workloads, not just at the perimeter โ is the zero trust mechanism that most directly limits lateral movement after a breach. By 2026, 60 percent of enterprises are expected to adopt zero trust with microsegmentation.
Current Rankings
Forrester's 2025 assessment reshuffled the market. Illumio climbed to first in strength of current offering by mapping real-time application dependencies and automatically generating least-privilege policies. ColorTokens jumped from fifth to second. Cisco held steady at third with a fundamentally new approach integrating segmentation into the switching fabric, though Forrester criticized Cisco's recent innovation track record. Akamai Guardicore fell from first to fourth.
On Gartner Peer Insights, Illumio and Akamai Guardicore each hold 4.8-star ratings with over 140 reviews.
Approaches
Agent-based (host-based): Illumio and Akamai Guardicore deploy lightweight agents on workloads to enforce segmentation policies independent of network topology. This works across on-premises, cloud, and hybrid environments.
Network-based: Cisco integrates segmentation into network infrastructure using specialized software and hardware. This requires less per-workload deployment but ties segmentation to the network fabric.
Identity-based: The emerging approach ties segmentation to workload identity via SPIFFE/SPIRE rather than network constructs. Organizations enforcing mTLS-based microsegmentation across microservices reported 87 percent reduction in lateral movement risks, and 94 percent of security teams cited identity-based encryption as their most effective control against insider threats.
SASE: The Platform Convergence
Secure Access Service Edge has matured from concept to competitive market. The 2025 Gartner Magic Quadrant for SASE Platforms โ published July 2025 โ evaluated 11 vendors across converged SD-WAN, SWG, CASB, FWaaS, and ZTNA capabilities.
Leaders: Palo Alto Networks, Netskope, Cato Networks, Fortinet
Visionaries: Zscaler, Cloudflare
Challengers: Cisco, Versa Networks
Niche Players: Check Point, SonicWall, Hewlett Packard Enterprise
The convergence trajectory is clear: by 2026, 60 percent of new SD-WAN purchases will be part of a single-vendor SASE offering, up from 15 percent in 2022. By 2028, 30 percent of large organizations with expiring multivendor contracts will consolidate to a single SASE platform. Mid-market organizations lean toward single-vendor for unified management, while larger organizations with siloed teams often prefer dual-vendor approaches.
SASE/ZTNA Market Share (Estimated Revenue, 2025)
| Name | Value |
|---|---|
| Palo Alto Networks | 28 |
| Zscaler | 22 |
| Netskope | 15 |
| Cloudflare | 13 |
| Cato Networks | 10 |
| Other (Fortinet, Cisco, etc.) | 12 |
Cloud-Native Zero Trust
Modern cloud-native architectures require zero trust mechanisms that operate at the workload level, not the network perimeter.
Service Mesh and mTLS
Service mesh technologies โ Istio, Cilium, and Linkerd โ have matured into production-grade mTLS implementations that encrypt all pod-to-pod communications and provide fine-grained authorization based on workload identity. Analysis of 1,200 production Kubernetes clusters showed automatic mTLS reduced certificate management overhead by 73 percent compared to manual management. Organizations implementing zero trust in container environments experienced 57 percent fewer successful attacks according to the Red Hat 2024 State of Kubernetes Security Report.
SPIFFE/SPIRE for Workload Identity
SPIFFE (Secure Production Identity Framework for Everyone) provides extensible workload identity through short-lived SPIFFE Verifiable Identity Documents (SVIDs). SPIRE, the runtime implementation, integrates with Envoy and service meshes for standardized cross-platform authorization. In a zero trust architecture, SPIFFE enables workload authentication without relying on static secrets โ a critical requirement given that 97 percent of non-human identities have excessive privileges. Emerging use cases include CI/CD pipeline identity, AI agent identity, and integration with confidential computing attestation.
Cloud Provider Services
AWS Verified Access provides zero trust application connectivity without VPN, evaluating each request based on user identity and device posture.
Google BeyondCorp Enterprise is a purpose-built multicloud solution supporting resources on GCP, AWS, Azure, and on-premises. BeyondCorp provides continuous authentication, context-aware access controls, integrated DLP, and Chrome-based threat prevention. Google internally uses BeyondCorp for VPN-less access for over 100,000 employees โ the original zero trust implementation born from the 2009 Operation Aurora attacks.
Azure Conditional Access adapts access policies based on context โ location, device compliance, risk score โ combined with Microsoft Entra ID for SSO, MFA, and identity governance. Microsoft moved 94.3 percent of Entra ID security token validation to its standard identity SDK.
Zero Trust for the AI Era
AI introduces both new defensive capabilities and new attack surfaces that require zero trust controls.
AI-Powered Defense
Behavioral analytics powered by AI and ML detect subtle anomalies that static signatures and legacy rule sets miss. Modern ITDR and UEBA systems use continuous learning to identify suspicious patterns: unusual authentication timing, atypical resource access sequences, and privilege escalation chains. DLP systems increasingly use AI to learn from user behavior, detect intent, and identify risks before data leaves the environment.
AI-Specific Threats
Prompt injection is the single most exploited vulnerability in modern AI systems. Second-order prompt injection tricks a low-privilege AI agent into asking a higher-privilege agent to perform unauthorized actions โ a direct analogy to traditional privilege escalation attacks. Indirect prompt injection arrives through untrusted external content rather than direct input.
Shadow AI is the new shadow IT. The LayerX 2025 report found 77 percent of enterprise employees using AI have pasted company data into chatbot queries, and 22 percent of those instances included confidential personal or financial data.
AI agent identity is the next frontier. AI agents are a new class of non-human identities that require the same zero trust controls as service accounts โ identity verification, least-privilege access, continuous monitoring, and behavioral analytics. Defense requires input validation, output filtering, privilege minimization, and policy-driven authorization.
Zero trust for AI is not an extension of existing frameworks โ it requires treating every AI agent, model inference call, and training pipeline as an untrusted workload.
Confidential Computing: Data Protection in Use
The zero trust promise is incomplete if data is only protected at rest and in transit. Confidential computing closes the gap by protecting data during processing using hardware-based trusted execution environments (TEEs).
The confidential computing market was valued at approximately $17 to $24 billion in 2025, with projections varying wildly from $115 billion to $590 billion by 2030-2033 depending on the research firm โ reflecting different market definitions and the rapid expansion of the technology.
Intel TDX (Trust Domain Extensions) uses SEAM (Secure Arbitration Mode) for memory and state encryption. Intel enabled TDX Connect on Xeon 6 processors in February 2025, extending encrypted communication between confidential VMs and PCIe devices.
AMD SEV-SNP (Secure Encrypted Virtualization - Secure Nested Paging) uses a separate security processor for hardware-based isolation and is widely deployed across cloud providers.
NVIDIA GPU TEE adds confidential computing to GPU workloads โ critical for AI/ML where models and training data need protection during inference.
All three major cloud providers now offer confidential computing: Google Cloud launched Confidential VMs on both AMD SEV (C3D) and Intel TDX (C3) machine series in October 2024. Microsoft launched Azure Integrated HSM security chips across all Azure servers in August 2025. AWS offers Nitro Enclaves for isolated compute environments.
Confidential Computing Hardware
Intel TDX
AMD SEV-SNP
Real-World Deployments
US DoD Thunderdome
The most rigorous zero trust implementation in the world. DISA's Thunderdome program achieved a perfect 152 out of 152 score, meeting all Department of Defense zero trust capability outcomes. Thunderdome will complete the DISA terrain by June 2025, with FY2025 deployments to six defense agencies and FY2026 deployments planned for DARPA, Missile Defense Agency, and Joint Staff J-6. The architecture leverages enterprise identity credential and access management, commercial SASE capabilities, and SD-WAN security tools.
Microsoft Secure Future Initiative
Microsoft's SFI deployed phishing-resistant MFA to 99.6 percent of employees and devices. The effort involved the equivalent of 35,000 engineers working full-time on security. Microsoft moved 94.3 percent of Entra ID security token validation to its standard identity SDK and mapped progress to the NIST Cybersecurity Framework. The November 2025 progress report covers every engineering pillar with implementation guidance aligned to zero trust principles.
Google BeyondCorp
The original zero trust implementation, born from Operation Aurora in 2009. BeyondCorp shifted access controls from the network perimeter to individual users and devices, providing VPN-less secure access for Google's entire global workforce of over 100,000 employees. The commercial BeyondCorp Enterprise product supports resources across GCP, AWS, Azure, and on-premises, with configuration changes propagating in seconds.
Measurable Results
The evidence that zero trust works is now quantifiable:
- Organizations implementing zero trust reduced the likelihood of a successful breach by up to 50 percent (Microsoft research)
- Mature zero trust organizations experience 50 percent fewer security incidents and recover 40 percent faster from breaches (Forrester)
- Companies with mature zero trust strategies save roughly $1 million less in breach costs on average
- Zscaler research estimated zero trust could reduce global annual cyber economic losses by up to 31 percent โ a projected reduction of up to $465 billion
Implementation Reality
Despite the clear benefits, implementing zero trust remains challenging. The gap between Gartner's forecast (10 percent mature by 2026) and adoption surveys (89 percent claiming some implementation) reveals the difficulty of the journey.
Legacy systems often lack APIs or compatibility with modern IAM solutions. Retrofitting encryption, identity management, and API-based access control is costly and causes system outages.
Skills gaps are pronounced. There is a shortage of professionals who can implement and manage zero trust across identity, network, endpoint, application, and data layers โ especially when legacy systems are involved.
Measuring maturity is itself a challenge. CISA's Zero Trust Maturity Model v2.0 provides the most structured approach with four stages (Traditional, Initial, Advanced, Optimal) across five pillars: Identity, Devices, Networks, Applications and Workloads, and Data. The cross-cutting capabilities โ Visibility and Analytics, Automation and Orchestration, and Governance โ are often where organizations stall.
The cost of doing nothing is rising faster than the cost of implementation. The average cost of a data breach reached $4.88 million in 2024 according to IBM, and the attack surface is expanding with cloud migration, remote work, AI agents, and non-human identities multiplying at 40 percent year-over-year.
Origin and Concept
Google begins BeyondCorp after Operation Aurora (2009). Forrester analyst John Kindervag coins "zero trust" (2010). Google publishes BeyondCorp research papers. The concept remains academic and limited to a few large enterprises.
Standards and Mandates
NIST publishes SP 800-207 Zero Trust Architecture (2020). COVID-19 and remote work expose VPN limitations at scale. ZTNA vendors emerge as alternatives. Zero trust transitions from concept to strategic priority.
Federal Push
Biden Executive Order 14028 mandates federal zero trust adoption (2021). OMB M-22-09 sets FY2024 compliance deadline (2022). CISA publishes Zero Trust Maturity Model v2.0 (2023). SASE platforms consolidate ZTNA, SWG, CASB, and FWaaS.
Maturation and Consolidation
Passkeys hit 1 billion users. FIDO2 becomes default for new Microsoft accounts. DoD Thunderdome scores 152/152. Palo Alto acquires CyberArk ($25B), Google acquires Wiz ($32B), Netskope IPOs at $7.3B. AI agents create a new identity class. Only 10% of enterprises reach full maturity.
Zero trust architecture in 2026 is neither a product you can buy nor a project you can complete. It is an operating model that spans identity, network, workload, data, and device layers โ each requiring continuous investment and adaptation. The organizations seeing measurable results (50 percent fewer breaches, $1 million less in breach costs, 40 percent faster recovery) are the ones treating zero trust as an ongoing engineering discipline, not a checkbox. The technology is mature. The acquisitions signal where the market is heading. The gap is execution.

