---
title: "Zero Trust Architecture Guide: What NIST SP 800… | Firevault"
description: "A technical guide to Zero Trust architecture based on NIST SP 800-207: the tenets, the policy engine and policy enforcement point, deployment models, and the…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/zero-trust-architecture-guide#webpage",
      "url": "https://fire-vault.com/learn/guides/zero-trust-architecture-guide",
      "name": "Zero Trust Architecture Guide: What NIST SP 800…",
      "description": "A technical guide to Zero Trust architecture based on NIST SP 800-207: the tenets, the policy engine and policy enforcement point, deployment models, and the…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/zero-trust-architecture-guide.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/zero-trust-architecture-guide#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/zero-trust-architecture-guide#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Zero Trust Architecture Guide: What NIST SP 800-207 Actually Requires",
          "item": "https://fire-vault.com/learn/guides/zero-trust-architecture-guide"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Zero Trust Architecture Guide: What NIST SP 800-207 Actually Requires",
      "description": "A technical guide to Zero Trust architecture based on NIST SP 800-207: the tenets, the policy engine and policy enforcement point, deployment models, and the limits of Zero Trust in OT and recovery.",
      "url": "https://fire-vault.com/learn/guides/zero-trust-architecture-guide",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/zero-trust-architecture-guide.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-08-28T07:22:29.15904+00:00",
      "dateModified": "2026-08-28T10:12:43.171224+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/zero-trust-architecture-guide"
      },
      "inLanguage": "en-GB",
      "articleSection": "Technical Guides",
      "wordCount": 1097,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

The definition worth usingThe tenets, in operational termsThe logical architectureDeployment approachesMigration that does not stallWhere Zero Trust reaches its limitsZero Trust and physical controlsFrequently asked questionsMore

[Guides](/learn/knowledge?filter=guides)/ Technical Guides 

Technical Guides · 28 August 2026 

# Zero Trust Architecture Guide: What NIST SP 800-207 Actually Requires

A technical guide to Zero Trust architecture based on NIST SP 800-207: the tenets, the policy engine and policy enforcement point, deployment models, and the limits of Zero Trust in OT and recovery.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

6 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fzero-trust-architecture-guide)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fzero-trust-architecture-guide&text=Zero%20Trust%20Architecture%20Guide%3A%20What%20NIST%20SP%20800-207%20Actually%20Requires%0A%0AA%20technical%20guide%20to%20Zero%20Trust%20architecture%20based%20on%20NIST%20SP%20800-207%3A%20the%20tenets%2C%20the%20policy%20engine%20and%20policy%20enforcement%20point%2C%20deployment%20models%2C%20and%20the%20limits%20of%20Zero%20Trust%20in%20OT%20and%20recovery.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fzero-trust-architecture-guide)[](mailto:?subject=Zero%20Trust%20Architecture%20Guide%3A%20What%20NIST%20SP%20800-207%20Actually%20Requires&body=A%20technical%20guide%20to%20Zero%20Trust%20architecture%20based%20on%20NIST%20SP%20800-207%3A%20the%20tenets%2C%20the%20policy%20engine%20and%20policy%20enforcement%20point%2C%20deployment%20models%2C%20and%20the%20limits%20of%20Zero%20Trust%20in%20OT%20and%20recovery.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fzero-trust-architecture-guide)

![Zero Trust Architecture Guide: What NIST SP 800-207 Actually Requires](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/zero-trust-architecture-guide.jpg)

Technical Guides 

Why it matters

## What this means for organisations holding critical data

A technical guide to Zero Trust architecture based on NIST SP 800-207: the tenets, the policy engine and policy enforcement point, deployment models, and the limits of Zero Trust in OT and recovery.

**On this page**[The definition worth using](#section-0)[The tenets, in operational terms](#section-1)[The logical architecture](#section-2)[Deployment approaches](#section-3)[Migration that does not stall](#section-4)[Where Zero Trust reaches its limits](#section-5)[Zero Trust and physical controls](#section-6)[Frequently asked questions](#section-7)

On this page

1.  [The definition worth using](#section-0)
2.  [The tenets, in operational terms](#section-1)
3.  [The logical architecture](#section-2)
4.  [Deployment approaches](#section-3)
5.  [Migration that does not stall](#section-4)
6.  [Where Zero Trust reaches its limits](#section-5)
7.  [Zero Trust and physical controls](#section-6)
8.  [Frequently asked questions](#section-7)

**Written by Mark Fermor.** Zero Trust is a security architecture strategy, not a product category. This guide sets out what NIST SP 800-207 describes, how the logical components fit together, and where the model reaches its limits.

## The definition worth using

NIST Special Publication 800-207 defines Zero Trust as a set of principles that move defences from static, network-based perimeters to focus on users, assets and resources. The operating assumption is that no implicit trust is granted on the basis of network location or asset ownership. Every access request to a resource is evaluated on its own merits, and authorisation is granted per session.

Two consequences follow. Being inside a network no longer confers access. And authentication is not a one-off event at the front door; it is a continuous evaluation that can withdraw access when conditions change.

## The tenets, in operational terms

-   All data sources and computing services are treated as resources.
-   All communication is secured regardless of network location. There is no trusted internal network.
-   Access to individual resources is granted on a per-session basis, with least privilege.
-   Access is determined by dynamic policy, including client identity, application state, requesting asset posture, and behavioural or environmental attributes.
-   The organisation monitors and measures the integrity and security posture of all owned and associated assets. No asset is inherently trusted.
-   Authentication and authorisation are dynamic and strictly enforced before access is allowed, and re-evaluated during the session.
-   The organisation collects as much information as possible about assets, network infrastructure and communications, and uses it to improve its security posture.

## The logical architecture

SP 800-207 separates the decision from the enforcement, which is the structural idea that makes Zero Trust implementable.

-   **Policy Engine (PE).** Decides whether to grant access to a resource for a given subject, using policy and external inputs.
-   **Policy Administrator (PA).** Establishes or tears down the communication path, and issues the session credentials.
-   **Policy Enforcement Point (PEP).** Enables, monitors and terminates the connection between subject and resource. It sits in the data path; the PE and PA sit in the control plane.

Around these sit the inputs that make policy dynamic: identity management, device posture and compliance state, threat intelligence, activity logs, data classification, and industry or regulatory policy.

## Deployment approaches

-   **Device agent and gateway based.** An agent on the endpoint coordinates with a gateway fronting each resource. Strong control, and the most demanding to roll out across an unmanaged estate.
-   **Enclave based.** A gateway protects a group of resources rather than each one individually. Realistic where legacy applications cannot sit behind an individual gateway.
-   **Resource portal based.** Subjects reach resources through a portal that acts as the enforcement point. Simplest to adopt, with the weakest visibility of endpoint posture.
-   **Application sandboxing.** Approved applications run in isolated environments on the asset, reducing dependence on the health of the host operating system.

Most real programmes end up hybrid, and that is a legitimate outcome provided the boundaries between approaches are deliberate.

## Migration that does not stall

1.  **Inventory subjects, assets and business processes.** Zero Trust cannot enforce policy about resources you have not enumerated.
2.  **Identify the highest-value workflows** and map their actual data flows, including administrative and backup traffic, which is routinely forgotten.
3.  **Fix identity first.** Strong authentication, privileged access management and lifecycle hygiene are the substrate. Without them, dynamic policy has nothing trustworthy to evaluate.
4.  **Insert enforcement points around one workflow** in monitoring mode, then move to enforcement.
5.  **Expand by workflow, not by network.** Segmenting networks without per-resource authorisation produces smaller perimeters, not Zero Trust.
6.  **Instrument continuously,** since policy quality depends entirely on the fidelity of the telemetry feeding it.

## Where Zero Trust reaches its limits

Three limits deserve honest statement, because vendor material rarely acknowledges them.

**Operational technology.** Many industrial devices cannot authenticate, cannot run an agent, cannot tolerate the latency of an inline enforcement point, and cannot be patched on a normal cycle. In these environments Zero Trust principles are usually applied to the systems and people that reach the process, with segmentation and boundary design doing the work at the process layer. ISA/[IEC 62443](/solutions/control/frameworks/iec-62443) zone and conduit design remains the primary construct there, and the Purdue Model remains a useful functional reference.

**The control plane itself.** The Policy Engine, Policy Administrator, identity provider and their logs become the most valuable target in the estate. An attacker who compromises policy administration inherits the ability to authorise themselves. Zero Trust concentrates trust rather than eliminating it, and the control plane needs its own containment and recovery design.

**Recovery.** Zero Trust governs access to resources. It does not, by itself, guarantee that a clean copy of a resource exists after a successful intrusion. If recovery data is authorised by the same identity plane and reachable over the same fabric, a sufficiently privileged compromise can authorise its destruction, and every policy decision along the way will have been correct.

## Zero Trust and physical controls

The recovery and control plane limits are the two places where physical measures usefully complement dynamic policy. A logical authorisation decision, however well designed, is only as trustworthy as the credentials and control plane that produced it. A physical state change is not authorised by that plane at all.

Firevault works on this narrow seam. **[Offline Secure Storage](/offline-secure-storage)®** holds selected recovery, configuration and evidential material on storage that is physically disconnected when it is not in use, so that a copy which must survive a compromise of the identity plane is not reachable by it. **Control by Firevault** is a suite of nine purpose-built tools and techniques that give physical control over the paths into and across an estate, applied through Blueprints that treat a specific risk, which is relevant where a path such as vendor access or a management route does not need to exist continuously.

This is complementary to a Zero Trust programme rather than an alternative to one. Identity, posture, per-session authorisation and telemetry remain the core of the architecture.

## Frequently asked questions

### Can we buy Zero Trust?

No. Products implement components such as enforcement points and policy engines. The architecture is yours to design.

### Is Zero Trust the same as micro-segmentation?

No. Micro-segmentation is one technique that can serve an enforcement objective. Zero Trust requires per-request authorisation of access to resources.

### Does Zero Trust replace VPNs?

It usually replaces the model in which a VPN grants broad network access, in favour of authorised access to specific resources.

### Does Zero Trust work in OT?

The principles apply to the people and systems reaching the process. At the process layer, segmentation, boundary design and 62443 zones and conduits do most of the work.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

## Continue learning

-   [
    
    ### Physical Layer Security Architecture
    
    Firewalls, endpoint detection, identity management, and immutable backups are all software layers. Every software layer depends on the integrity of the layer beneath it. The physical layer is the foundation that no software attack can compromise.
    
    Read guide ](/learn/guides/physical-layer-security-architecture)

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up