---
type: "Specification"
title: "Zero trust architecture (NIST SP 800-207)"
description: "No implicit trust based on network location."
resource: "https://csrc.nist.gov/pubs/sp/800/207/final"
tags: [zero-trust, security, standard]
generated: { by: human:crpage, at: 2026-07-09T09:44:00Z }
status: stable
sources: [{ id: primary, resource: "https://csrc.nist.gov/pubs/sp/800/207/final" }]
---

Eliminates implicit trust derived from network position; every request is authenticated, authorised and continuously evaluated. A foundation for agent runtimes, paired with [workload identity](spiffe-spire.md) and [sender-constrained](../glossary/sender-constrained-token.md) credentials.

# Terms
Glossary terms used here: [Workload identity](../glossary/workload-identity.md).
