EDIH, EEN, Interreg: the platform for European programmes.Find out more

Zero Trust Maturity · Strategy and cloud environment security

Your Zero Trust trajectory, measured by domain and translated into a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Zero Trust Maturity · Strategy and cloud environment security

Zero Trust strategy and governanceN1 → N5
Identities and authenticationN1 → N5
Access and privilege managementN1 → N5
Device and endpoint securityN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Zero Trust strategy and governance6484
Identities and authentication5379
Access and privilege management6182
Device and endpoint security3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • CNES
  • Docaposte
  • Cetim
  • Aerospace Valley
  • Pôle SCS
  • Cap'Tronic

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Zero Trust Architecture, NIST SP 800-207, complemented by cloud security principles (CSA Cloud Controls Matrix, ANSSI) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

This mechanism (one level, the next level up, and the action that links the two) is what turns a finding into a trajectory.

Is privileged access to cloud environments granted according to the principle of least privilege and for a limited time?

  1. N1

    Permanent administration rights are assigned to named or shared accounts, with no consolidated inventory.

  2. N2

    Privileged accounts are identified and documented, but rights remain permanent and reviews are irregular.

  3. N3

    Rights are assigned by role, reviewed periodically, and privilege elevation is requested then logged for sensitive operations.

  4. N4

    Privileged access is granted just in time, for a bounded duration, with systematic approval and logging across all environments.

  5. N5

    Rights are automatically derived from context and roles, gaps are detected and corrected, and the policy is revised after every incident or architecture change.

Action to move from L2 to L3

Define administration roles per environment, replace permanent individual assignments with these roles, and add a review of privileged accounts to the quarterly security committee, with a named owner per environment.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon ZERO TRUST.

What this framework covers

Zero Trust is not a product but an architecture model. Formalised by NIST in publication SP 800-207, it holds that trust cannot be inferred from network position: every access to a resource is authenticated, authorised and continuously evaluated, based on identity, device state and the context of the request. Applied to a cloud environment, this model covers identity and privilege management, workload segmentation, data encryption, managed service configuration and access monitoring.

In practice, steering this is difficult because the subject cuts across several teams. Identity belongs to IT, network to infrastructure, cloud configurations to product teams, monitoring to the SOC. Three questions come up systematically. Does multi factor authentication genuinely cover all privileged access, including service accounts and emergency access? Does segmentation exist at workload level, or does it stop at the VPC perimeter? Are authorisation decisions re evaluated during the session, or only once at login?

One common confusion deserves clearing up: deploying zero trust network access as a VPN replacement does not constitute a Zero Trust architecture. Replacing the VPN addresses remote access, but it addresses neither internal flows between services, nor administrators’ access to cloud consoles, nor machine identities, whose number often exceeds that of human identities. Add to this the shared responsibility model: the provider secures the infrastructure, while service configuration and rights management remain the customer’s responsibility.

The maturity assessment answers a different question from the compliance audit. The audit asks whether a requirement is met, yes or no. The assessment places each domain on a progressive scale and indicates the precise action that moves it up a level. This is what allows a Zero Trust transformation programme to be sequenced over several cycles, rather than noting an overall gap without knowing where to start.

In Datamensio, the framework is ready to use. You can also adapt it to your context: the AI adjusts themes, questions and levels according to the CMMI method, or builds a variant from your own architecture documents and access policies.

Reference standard: Zero Trust Architecture, NIST SP 800-207, complemented by cloud security principles (CSA Cloud Controls Matrix, ANSSI)

The themes assessed

  • Zero Trust strategy and governance

    Existence of a documented target architecture, scope of protected resources, roles and responsibilities across security, infrastructure and product teams, multi year trajectory and follow up.

  • Identities and authentication

    Unified identity store, multi factor authentication coverage, phishing resistance of factors, handling of emergency accounts and machine identities.

  • Access and privilege management

    Least privilege, just in time access, rights reviews, tracked elevation, separation of administration roles across cloud environments.

  • Device and endpoint security

    Device inventory, compliance state assessment prior to access, patch management, coverage of unmanaged devices and contractors.

  • Segmentation and traffic security

    Workload micro segmentation, east west traffic control, encryption of internal communications, service to service authentication.

  • Data protection

    Classification, encryption at rest and in transit, key and secrets management, control of sharing and exports outside the managed perimeter.

  • Configuration and posture of cloud environments

    Configuration baselines, drift detection, infrastructure as code, management of public exposure, shared responsibility with providers.

  • Access decision and continuous evaluation

    Centralised authorisation policy, signals factored into the decision, re evaluation during the session, effective access revocation.

  • Monitoring, logging and detection

    Coverage of access and API logs, correlation within the SOC, cloud specific detection use cases, alert handling times.

  • Continuous improvement and measurement

    Coverage indicators, penetration tests and targeted exercises, post incident lessons learned, refresh of the target architecture.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Is Zero Trust certifiable?

No. It is an architecture model, described notably by NIST in publication SP 800-207, with no associated certification body. Certification applies to management systems such as ISO 27001, of which Zero Trust can be an architectural choice. The assessment measures the maturity of your practices, it does not issue any certificate.

What is the difference between this assessment and a compliance audit?

The audit checks whether a requirement is present and concludes with a gap or a compliance finding. The assessment places each domain on a maturity scale and indicates the action that moves it up to the next level. The assessment is used to build the roadmap, the audit to validate a state.

How long does the assessment take?

The short version takes about thirty minutes for a security manager to complete. The full version, run collaboratively, typically spans one to two weeks: most of the time is spent gathering input from identity, infrastructure and cloud teams.

Can the framework be adapted to our architecture?

Yes. Questions, levels and themes can all be modified, and you can add your own domains, for example an industrial environment or a specific cloud provider. The AI generates a variant from your architecture documents and access policies.

Does answering require technical expertise?

The questions focus on management and control practices, not on the settings of a specific service. Some require input from an architect or cloud administrator: the collaborative mode allows these questions to be assigned to the right person, with responses logged.

How can several entities or environments be compared?

The same framework can be completed by each business unit or environment, then compared by theme. Cross cutting roadmaps consolidate action plans from several assessments to avoid funding the same project twice.

How does this assessment relate to NIS 2 or DORA?

These texts impose access control, logging and third party management requirements that rely on the same mechanisms. Findings from the Zero Trust assessment are reusable, and the cross cutting roadmap allows frameworks to be cross referenced without duplicating actions.

Where is the data hosted?

In France, with OVH, with backup at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European solutions.

Take your first measurementon ZERO TRUST.