Summary
ZTNA is widely deployed, but often still built on old trust assumptions. New NCSC guidance explains how to design ZTNA architectures aligned with zero trust principles. Zero Trust Network Access (ZTNA) is often introduced to modernise access to applications. However, without changes to the underlying design, these deployments can continue to reflect older models of trust. In many cases, ZTNA tools are deployed in environments that still treat network location as a primary signal of trust. This means the tools may be new, but the underlying approach continues to rely on broad, network-based access rather than more granular, context-driven decisions.