micro-segmentation Archives - iSecPrep https://www.isecprep.com/tag/micro-segmentation/ Your Guide to IT Certification Success Tue, 25 Aug 2026 09:18:21 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 Zero Trust Certification: Reading the CCZT Syllabus Like an Architect https://www.isecprep.com/2026/08/25/cczt-zero-trust-certification-csa/ Tue, 25 Aug 2026 00:00:00 +0000 https://www.isecprep.com/?p=87025 More people search for what zero trust means than for the credential that certifies it, and CCZT answers both. This guide walks the five syllabus sections, the pillars and cross-cutting capabilities, the eighty percent pass mark, and how CCZT sits against CSA's cloud credential.

The post Zero Trust Certification: Reading the CCZT Syllabus Like an Architect appeared first on iSecPrep.

]]>

CCZT is the exam code for the Cloud Security Alliance Certificate of Competence in Zero Trust, and it is the closest thing the industry has to a vendor-neutral zero trust certification. Sixty questions, one hundred and twenty minutes, eighty percent to pass, $175 for the exam. That fee includes two attempts, which is unusual enough to change how you should plan the booking. Search demand tells its own story here: far more people search for what zero trust actually is than for the credential that certifies it, and the two questions have the same answer.

This guide covers what zero trust means in practice, walks the five syllabus sections CSA publishes, names the pillars and the cross-cutting capabilities the exam expects you to place, and settles the question CSA itself raises by recommending its cloud security certificate as a precursor: which of the two you should sit first.

What Is Zero Trust and Why Does It Need a Certification?

Zero trust is a security model that removes implicit trust from a network. Nothing is trusted because of where it sits, and every access request is authenticated, authorised and continuously validated. CCZT certifies that you can plan and implement that model rather than merely describe it, across five syllabus sections covering architecture, software-defined perimeter, strategy, planning and implementation.

The reason a certification exists at all is that zero trust has become a procurement word. Every vendor sells a zero trust product, and most of them mean something different by it. A vendor-neutral credential is a way of proving you can tell an architecture from a marketing claim.

CSA describes CCZT as the industry’s first vendor-neutral zero trust certificate, and the syllabus incorporates zero trust components released by the US Cybersecurity and Infrastructure Security Agency. The credential also carries a Silver 2025 Globee Award for Cybersecurity, which is a reasonable proxy for industry recognition in a young field. For a neutral primer on the concept itself before you commit, the zero trust architecture overview is a better starting point than any vendor page.

“Zero Trust is the future of information security. Investing in Zero Trust and the CCZT is an investment in our organization’s future.”

Rob LaMagna-Reiter, VP, Information Security and Compliance, and CISO at Hudl

What Does the CCZT Syllabus Actually Cover?

The CCZT syllabus has five sections. It opens with zero trust architecture, then gives software-defined perimeter a section of its own, then moves through strategy, planning and implementation. That order is not accidental. It runs from concept to architecture to programme, which is the sequence an organisation actually follows.

The five sections

  • Introduction to Zero Trust Architecture – history, definitions, tenets, design principles, pillars, objectives, benefits, planning considerations, implementation options and use cases.
  • Introduction to Software-Defined Perimeter – SDP history and concepts, the problems it solves, core tenets, underlying technology, architecture components, the secure workflow and deployment models.
  • Zero Trust Strategy – levels of strategy, drivers and buy-in, the maturity model, the five implementation steps, and the cultural and operational shift.
  • Zero Trust Planning – stakeholders, business impact assessment, risk register, supply chain risk, scope and business case, gap analysis, protect surface and attack surface, transaction flows, policy and target architecture.
  • Zero Trust Implementation – gap analysis report, policy alignment, migration from existing architectures, preparation activities, target architecture delivery, testing, continual improvement and project closure.

No published weightings

CSA does not attach percentages to the five sections, so there is no heaviest domain to chase. Judge by depth instead: architecture and planning carry by far the largest sub-topic trees, while implementation is comparatively compact. Treat that as the closest thing to a distribution signal the blueprint offers, and be sceptical of any resource quoting CCZT section percentages as fact. If you want a fast orientation before reading the full syllabus, the CCZT exam overview collects the format and section list in one place.

Why Does Software-Defined Perimeter Get a Whole Section?

Software-defined perimeter is the architectural pattern that made zero trust deployable, which is why CSA gives it one of five sections rather than a paragraph. SDP hides infrastructure behind an authentication step, so a resource is not addressable until the requester has been verified. The exam expects the relationship between SDP and zero trust, not just a definition of each.

What the section actually asks

Four objective groups sit under it. The first covers SDP history, definition, principles and its relationship to zero trust, plus the technology and business benefits. The second covers the problems in traditional architectures that SDP addresses and the threats it protects against. The third covers core tenets, underlying technology, architecture components and the secure workflow. The fourth covers architectural considerations and deployment models.

CSA has published SDP research since long before zero trust became a procurement term, and the CSA zero trust research library is where the syllabus content originates. Reading the source material is more efficient than reading a summary of it.

The other implementation options

SDP is one route among several, and the architecture section names the alternatives explicitly: the NIST approach to zero trust, zero trust network access, and Google BeyondCorp. The exam wants you to know which is which. NIST SP 800-207 is the document behind the first of those, and its policy engine, policy administrator and policy enforcement point vocabulary appears throughout zero trust discussion.

Use cases are examined too, and they are specific: remote access and VPN replacement, micro-segmentation, software as a service, hybrid and multi-cloud, operational technology and 5G. Operational technology and 5G surprise candidates who assume zero trust is an office-network topic.

What Are the Zero Trust Pillars the Exam Expects You to Name?

The pillars are the domains a zero trust programme has to cover, and CCZT uses them in two places: in the architecture section as part of the core concepts, and again in the implementation section as pillars plus cross-cutting capabilities. The five pillars are identity, device or endpoint, network and environment, workload and application, and data.

The five zero trust pillars and three cross-cutting capabilities tested in the CCZT exam

Pillars and cross-cutting capabilities

The three cross-cutting capabilities sit across all five pillars rather than beside them: visibility and analytics, automation and orchestration, and governance. The planning section requires you to develop a target architecture with considerations for each pillar and each cross-cutting capability, which is eight separate design conversations rather than five.

That structure is worth memorising as a shape, not a list. Scenario questions frequently describe a partial programme and ask what is missing, and the missing thing is usually a cross-cutting capability rather than a pillar. Organisations tend to buy identity and network products and forget that nobody owns governance.

Protect surface, not attack surface

One planning objective distinguishes the protect surface from the attack surface, and the distinction is the practical heart of zero trust. The attack surface is everything an adversary could reach and it only grows. The protect surface is the small, definable set of data, assets, applications and services that actually matter, and it is what you build controls around. Getting these two the wrong way round is a reliable way to lose marks.

How Do Strategy and Planning Differ in the CCZT Blueprint?

Strategy in CCZT is about why an organisation adopts zero trust and how leadership is convinced. Planning is about what you do in the first ninety days once they agree. The syllabus keeps them apart deliberately, and questions that feel like duplicates are usually testing which of the two a described activity belongs to.

What sits under strategy

The strategy section covers the levels of strategy from organisational goal down through cybersecurity strategy, IT strategy, tactics and operations. It covers drivers and buy-in, with risk management named as the primary driver and leadership buy-in as its own objective. It also covers the zero trust maturity model, the five steps for implementation, and the operational realities: cultural and organisational shift, training and education, regulatory shift, legacy systems, and usability and friction.

That last item deserves attention. Usability and friction is examined because zero trust programmes fail on user tolerance more often than on technology, and the exam treats that as a first-class concern rather than a footnote.

What sits under planning

Planning is the longest section by sub-topic count. It covers stakeholders, technology strategy, business impact assessment, risk register, supply chain risk management, organisational security policies, architecture and compliance. Then scope, priority and business case. Then gap analysis across current state, target state and roadmap. Then defining the protect surface and attack surface, documenting transaction flows, defining policies with a policy workflow and continual improvement, and finally developing the target architecture pillar by pillar.

Transaction flow documentation is the objective candidates most often skip and most often meet. The syllabus works through an eCommerce example and covers functional analysis and tooling for discovery, because you cannot write a policy for traffic you have not mapped.

What Does CCZT Cost and What Score Do You Need?

CCZT costs $175 USD and that fee includes two test attempts. The exam runs 60 multiple choice questions in 120 minutes, and the minimum passing score is 80 percent, which means 48 correct answers out of 60. It is delivered through CSA’s own exam platform rather than through a third-party test centre network.

Detail Value
Exam name CSA Certificate of Competence in Zero Trust
Exam code CCZT
Questions 60, multiple choice
Duration 120 minutes
Passing score 80 percent
Price $175 USD, two attempts included
Delivery CSA Exams

Eighty percent is the number that matters

An 80 percent threshold is high by certification standards, and it changes the risk profile. You can afford twelve wrong answers and no more, on a syllabus with no published weightings and a very wide surface. Two minutes per question is generous, so the pressure is knowledge coverage rather than time.

The two included attempts soften that considerably. Effectively you are buying $87.50 per attempt, and candidates who fail narrowly on a first sitting usually pass the second without further study. CSA requires no work experience to book, so the only real gate is the material itself. CSA’s own CCZT page confirms both the attempt allowance and the absence of an experience requirement.

CCZT or CCSK: Which CSA Credential Comes First?

CSA names its Certificate of Cloud Security Knowledge as an excellent precursor to CCZT training, but stops short of making it a prerequisite. In practice the right order depends on your work. If you run cloud workloads, take CCSK first. If you have been handed a zero trust programme with a deadline attached, take CCZT first and treat the cloud material as background.

What each one actually validates

CCSK validates breadth across cloud security: governance, architecture, data, identity, operations and compliance in a cloud context. CCZT validates depth in a single architectural model that applies on-premises, in cloud and in operational technology alike. They overlap on identity and on architecture thinking, and almost nowhere else.

Candidates who already hold the cloud credential tend to find the CCZT planning section familiar in shape, because business impact assessment, risk register and gap analysis are programme-management skills rather than zero trust ones. If you are weighing the two, the write-up on the CCSK credential covers what that exam demands in the same level of detail as this one.

Neither is a career-defining credential on its own. Held together they read as a coherent cloud and architecture story, which is why CSA promotes them as a pair.

How Should You Work Through the CCZT Material?

The efficient approach is to secure the definitions first, then the architecture patterns, then the programme sections, and to leave implementation until last because it assumes everything before it. An 80 percent pass mark rewards even coverage far more than depth in one favourite section.

Four steps of a zero trust roll out: protect surface, transaction flows, access policy and monitoring

“CCZT is not an easy exam. I recommend reading all of the provided study materials, and then reading them again.”

Shruti Kulkarni, Information Security Architect, Elexon
  1. Learn the tenets, design principles and five pillars until you can recite them without prompting, because everything later in the syllabus refers back to them.
  2. Separate the four implementation options, the NIST approach, software-defined perimeter, zero trust network access and Google BeyondCorp, so a described architecture can be named on sight.
  3. Work the SDP section as a self-contained block, ending with the secure workflow and the deployment models rather than starting there.
  4. Map the protect surface against the attack surface using a system you actually know, since the distinction is far easier to hold once you have applied it once.
  5. Trace a single transaction flow end to end and write the policy that would govern it, which is the planning section’s central skill.
  6. Read the strategy section last among the concept material, because leadership buy-in and maturity questions make more sense once the architecture is settled.
  7. Finish with timed practice at two minutes a question, checking coverage across all five sections rather than accuracy in your strongest one.

Most candidates report three to six weeks of part-time study, with architects at the shorter end and generalist security staff at the longer one. The material rewards a second pass more than most syllabuses, largely because the same pillars reappear in three different sections with different questions attached. Anyone approaching this after CSA’s cloud credential will recognise the pattern from the CCSK study approach, which faces the same broad-and-shallow problem.

Frequently Asked Questions

How many questions are on the CCZT exam?

The CCZT exam has 60 multiple choice questions and a 120-minute time limit, which is two minutes per question. That is generous by certification standards, so most candidates finish with time in hand. The difficulty comes from syllabus breadth rather than from time pressure.

What is the CCZT passing score?

You need 80 percent, which is 48 correct answers out of 60. That is a high threshold and it leaves room for only twelve mistakes across five syllabus sections. Even coverage matters far more than depth in any single area, because no section is published as heavier than the others.

How much does the zero trust certification cost?

CCZT costs $175 USD and that fee includes two test attempts rather than one. Effectively that is $87.50 per attempt, which is unusual and worth factoring into the decision. Candidates who fail narrowly on a first sitting commonly pass the second without buying anything further.

Are there prerequisites for the CCZT exam?

No. CSA requires no work experience and no prior certification to book CCZT. It does recommend its Certificate of Cloud Security Knowledge as a precursor to the training, but that is guidance rather than a gate, and plenty of candidates take CCZT first.

What are the five zero trust pillars?

Identity, device or endpoint, network and environment, workload and application, and data. Three cross-cutting capabilities sit across all five: visibility and analytics, automation and orchestration, and governance. The exam expects you to design against all eight rather than to list the five.

Is CCZT a hands-on exam?

No. CCZT is a knowledge and judgement exam delivered as multiple choice questions, with no lab component. It tests whether you can plan and reason about a zero trust programme, not whether you can configure a specific product, which is what makes it vendor-neutral.

What is the difference between the protect surface and the attack surface?

The attack surface is everything an adversary could potentially reach, and it only grows. The protect surface is the defined set of data, assets, applications and services that genuinely matter. Zero trust builds controls around the protect surface, because it is small enough to actually defend.

Does CCZT cover NIST zero trust guidance?

Yes. The architecture section names the NIST approach to zero trust as one of four implementation options, alongside software-defined perimeter, zero trust network access and Google BeyondCorp. CSA also states that the syllabus incorporates zero trust components released by CISA.

How long does it take to prepare for CCZT?

Most candidates report three to six weeks of part-time study. Security architects who already work with these patterns sit at the shorter end. Generalist security staff and those new to architecture work usually need the longer end, because the planning section assumes programme experience.

Should I take CCZT or CCSK first?

Take the cloud credential first if your day job is cloud workloads and zero trust is a future concern. Take CCZT first if you have already been handed a zero trust programme. They overlap on identity and architecture thinking and very little else, so the order follows your work rather than a rule.

Conclusion

CCZT is a wide exam with a high bar. Five sections, no published weightings and an 80 percent pass mark mean the credential rewards steady coverage rather than a favourite topic, and the material genuinely repays a second reading because the same pillars keep reappearing in different framings. The parts that catch people out are consistent: the protect surface, the cross-cutting capabilities, and the difference between a strategy activity and a planning one.

Two included attempts and no experience requirement make it a low-risk booking by the standards of the field. Once the definitions and the four implementation options are secure, working practice items across all five sections is the fastest way to find the gaps that would cost you those twelve marks.

Rating: 5 / 5 (1 votes)

The post Zero Trust Certification: Reading the CCZT Syllabus Like an Architect appeared first on iSecPrep.

]]>