7 MIN READ
Zero trust in 2026 is finally a thing that ships. The frameworks (NIST SP 800-207, the CISA Zero Trust Maturity Model, the UK NCSC Zero Trust Architecture) read like playbooks now, not white papers. The vendors (Zscaler, Palo Alto Networks, Cloudflare, Cisco, Fortinet, Microsoft) have platforms mature enough to deliver on the value. The market sits at a $60B annual run rate, up from $20B in 2022. The interesting question is no longer whether to do the rollout. It is how to do the rollout without breaking everything else.
Five phases, four patterns, three mistakes. The phases are what every serious rollout goes through, in roughly the order the field has settled on. The patterns are what works in production after a decade of vendors trying things. The mistakes are what kills the project before it reaches the second year, and they are depressingly common across industries.
The 5 phases of the rollout
These five phases show up in every serious rollout, in the order the field has settled on after a decade of doing this wrong.
1. Inventory. Without an accurate map of users, devices, applications, data, and services, the rest of the rollout gets built on guesses. A living inventory, not a one-time spreadsheet, has to be the source of truth for everything downstream. The common failure mode is treating it as a project that ends when the spreadsheet ships. The inventory has to keep moving as the systems change.
2. Policy. Written down, specific, enforceable, auditable. Who can access what, under which condition, with which device posture. A policy that does not name the role, the resource, the action, and the condition is a policy that will get ignored in production. A policy the audit cannot verify will not survive the first regulator call.
3. Enforcement. Three layers handle it. Network access control, identity and access management, application access control. The piece the user actually feels, and the piece that has to hold. Three qualities matter. Transparent to the person with the right credentials, impossible to bypass, measurable on both sides. If any of those is missing, the rollout is theatre.
4. Monitoring. Access attempts, blocked attempts, anomalous behaviour. Real time, integrated with the SIEM, reviewed on a weekly cadence. The signal that proves the policy is working, that the enforcement is doing its job, and where the next incident is most likely to land. Without it, the rollout is flying blind.
5. Improvement. The policy iterates on the monitoring signal, and the work continues for the lifetime of the programme. Tighter rules, smoother user experience, harder paths for anyone trying to break in. The five phases are not a sequence to complete. They are a loop to run.
The 4 patterns that work
Four patterns the field has settled on after a decade of trying things. Each one is mature enough to ship in 2026.
1. Identity as the perimeter. The identity aware proxy replaces the firewall, the identity verification replaces the network control, and the policy engine makes the access decision per request. The most mature pattern, the most widely deployed, and the one every other pattern builds on. Start here.
2. Device trust. Add the device posture as an additional signal in the policy. Managed or unmanaged. Patched or out of date. Running the expected OS or running something the SOC has never seen. A device that fails the posture check is a device that does not get the request, regardless of who is asking. Add this after the identity is in place.
3. Network segmentation. For the high value assets, segment the network so the policy can enforce at the application layer rather than the network layer. A flat network means a single breach moves laterally without resistance. Segmentation sits as the additional control for the parts of the estate that cannot survive a compromise.
4. Data centric access. Classify the most sensitive data, encrypt it at the field level, and add the classification as a signal in the policy. The least mature of the four, the least widely deployed, and the one that matters most for the regulated industries. Plan for this over a multi year horizon, not a single quarter.
The 3 mistakes that kill the rollout
Three mistakes show up again and again in the rollouts that fail before they reach the second year. None of them are exotic. All of them are common.
1. The big bang. Trying to roll zero trust out across the entire organisation in a single project. It cannot iterate. It cannot adjust to feedback. It cannot recover from the mistakes. Rollouts that succeed start with a small surface, iterate on the small surface, and expand outward as the lessons come in.
2. The policy that is too strict. Writing a policy that blocks everything by default and treats the user as the enemy. The experience breaks. The support tickets pile up. The workaround culture takes root, and the workaround is usually less secure than the thing the policy was trying to prevent. The right amount of friction matches what people will tolerate, not what sounds good on paper.
3. The project that has no owner. Launching the rollout without a named owner, a budget, or a timeline. Without an owner, the project has no authority to make the decisions. Without a budget, it has no resources to fund the work. Without a timeline, it has no urgency to keep the work moving. Each gap on its own is a risk. Together, they are a slow death.
What to do this quarter
Pick the small surface and ship it this quarter. A user group, an application group, a device group, one of them, not all three. The point of the small surface is to learn. What do people actually do when the policy is enforced? What does the help desk have to handle? What does the next incident look like when the policy holds? The first quarter answers those questions in production. The second quarter scales based on what the answers were.
Measure the success. Block rate, allow rate, false positive rate, satisfaction score, help desk ticket volume. These go to the executive team as the case for the next quarter. The block rate proves the policy is working. The allow rate proves no one is blocked. The false positive rate proves the policy is not generating noise. The satisfaction score proves the rollout is not breaking the business. The help desk ticket volume proves the same thing from a different angle.

The bottom line
Phases, patterns, mistakes. None of it lands without the iteration. The work that decides whether the rollout pays off lives in the loop, and most of the failure comes from skipping it.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



