A working architecture eventually has to answer a practical question that the conceptual posts in this series have not yet addressed directly.
Where, specifically, is the organisation in front of me on this journey?
Not in the abstract. Not in terms of aspiration. At what level, across which layer, with which gaps that matter and which gaps that do not? Without an answer to that question, an architecture may be interesting, but it is not yet actionable. Once that answer exists, the architecture becomes a diagnostic tool, and a diagnostic tool is something a CISO can actually use when deciding where to spend the next quarter’s effort.
This post introduces a maturity model for Stacked Zero Trust, the framework the series has been moving toward from the beginning. It uses five levels, assessed separately across the three layers, while acknowledging a reality that most maturity models struggle to accommodate: real organisations rarely sit at a single level. They are mature in some places, immature in others, and the distance between those places often represents the greatest source of risk.
The model is deliberately not aligned slavishly to the CISA Zero Trust Maturity Model or the DoD Zero Trust Reference Architecture. Both were developed for environments dominated by humans and workloads. Where the substrate layer of this model resembles them, that resemblance is intentional. Where the mediator and subject layers diverge, the divergence is largely the point.
To make the discussion concrete rather than theoretical, the model will be applied to a composite organisation.
Barnard Financial Group is a fictional UK-headquartered financial-services group with approximately 14,000 employees, assembled over fifteen years from four separate entities: Barnard, the original retail bank; Finchale Wealth, acquired in 2014; Usworth Insurance, acquired in 2019; and Auckl, a fintech acqui-hire completed in 2023. Barnard Financial Group is not a real institution, and any resemblance to one is coincidental, but it is constructed from patterns that appear repeatedly across enterprise assessments and customer engagements. Anyone who has spent time inside a multi-entity organisation will probably recognise parts of it.
The composite matters because organisations are rarely at a single maturity level. They are at one level in one business unit, another somewhere else, and frequently at a third where acquisitions, legacy systems or newer technologies have changed the shape of the estate. The gaps between those levels often become more important than the levels themselves, because that is where assumptions begin to break down.
The five levels
The levels need to be memorable enough to survive a meeting and specific enough to support a decision. Five levels have proved sufficient.
Level 1, Ad Hoc, describes an environment where controls exist, sometimes even strong controls, but their existence is largely accidental. Coverage depends on history, individual effort or local priorities rather than a coherent architectural approach. Different parts of the estate often solve the same problem in different ways and, while pockets of excellence may exist, they are not yet part of a repeatable pattern.
Level 2, Defined, is the point at which intent becomes visible. The organisation has articulated an approach, documented expectations and established a framework within which improvement can occur. Coverage may remain uneven, and implementation may lag behind ambition, but there is now a basis for measuring progress because the destination has been described.
Level 3, Managed, is where the architecture moves from paper into operation. Controls are being applied consistently across the relevant estate, evidence exists that they are functioning, and the organisation can demonstrate that the practices it describes are actually being performed. This is often the point at which Zero Trust stops being a programme and starts becoming part of normal operations.
Level 4, Measured, is characterised by visibility rather than implementation. The organisation is no longer asking whether a control exists. It is asking whether that control is effective. Telemetry is available. Gaps can be quantified. Trends become visible. Conversations increasingly shift away from deployment and towards outcomes.
Level 5, Self-Correcting, represents an architecture that learns from its own operation. Evidence produced by the controls influences the design of the controls. In Stacked Zero Trust terms, this is the mediator-subject loop from Post 3 becoming self-tuning: the mediator observes the subject, the subject’s behaviour reshapes what the mediator learns, and the resulting adjustments feed back into policy and configuration without waiting for a manual review cycle. This level is uncommon, and it is worth recognising just how uncommon it is.
These levels are deliberately descriptive rather than judgemental. A Level 2 organisation tackling a genuinely difficult problem may be making excellent progress, while a Level 4 organisation operating in a relatively straightforward environment may have achieved maturity with far less effort. The purpose of the model is not to award grades. It is to describe reality honestly enough that useful decisions can be made.
Applying the levels across the three layers
A single maturity score collapses precisely the distinctions the architecture has spent ten posts establishing. The model therefore applies the levels independently across the three layers, because maturity in one layer tells us surprisingly little about maturity in the others.
For the substrate, Level 3 typically looks like consistent identity hygiene, reliable segmentation, mature data classification and a control environment broadly aligned with the expectations of NIST SP 800-207 and the CISA Zero Trust Maturity Model. By Level 4, the organisation has moved beyond implementation and into measurement. Privilege exposure, federation friction, third-party access pathways and policy exceptions are no longer anecdotal observations but measurable characteristics of the environment. Level 5 appears when those measurements begin driving architectural change and the substrate evolves in response to what operational evidence reveals.
The mediator follows a slightly different path. Reaching Level 3 means the core mediator functions are operating on real estate rather than living inside demonstrations, pilots or presentations. Behavioural scoring, anomaly detection, policy synthesis and automated response are all participating meaningfully in operational decision-making. By Level 4, the effectiveness of those functions is itself being measured. False-positive rates are understood. Response actions are reviewed. Blind spots are visible. Level 5 arrives when the mediator begins improving through the evidence it produces, with buyers able to answer the questions from Post 5 using operational data rather than vendor claims.
The subject layer remains the least mature area for most organisations. A genuine Level 3 position requires agents to be governed as first-class subjects with their own identities, continuously assessed posture, intent-bounded privileges and task-relative behavioural baselines. Very few organisations operate at that level today. Level 4 assumes those controls can be measured and assessed systematically. Level 5, self-correcting subject governance, remains largely theoretical territory as of 2026. It exists in the model because the destination is visible, not because many organisations have arrived there.
The honest picture for most large organisations today is therefore uneven. The substrate is often operating somewhere between Level 2 and Level 3. The mediator is frequently sitting between Level 1 and Level 2, with isolated islands of greater maturity inside security operations. The subject layer remains predominantly Level 1, accompanied by a widespread belief that the subject layer is still somebody else’s problem. One of the model’s purposes is to make that reality difficult to ignore.
The composite: Barnard Financial Group
What does Barnard look like when assessed honestly?
The answer is uneven, which is exactly what makes it useful. Real organisations rarely exhibit a smooth maturity profile. They accumulate history, acquisitions, exceptions, compensating controls and locally optimised decisions. Maturity therefore tends to appear as a patchwork rather than a progression, and Barnard reflects that reality.
The substrate inside the original retail bank, the Barnard portion of the group, sits at approximately Level 3. Identity has been consolidated around a Microsoft estate for more than a decade. MFA enforcement is strong, conditional access is reasonably mature, segmentation exists across much of the banking infrastructure, and regulated data is handled within a mature classification framework. The remaining issues are largely understood: a collection of legacy systems that never fully entered the programme and a number of service accounts retaining broader privileges than their roles strictly require.
The picture changes as soon as the architecture crosses into Finchale Wealth. Here the substrate drops toward Level 1 or, viewed generously, low Level 2. The 2014 acquisition included plans to consolidate identity into the Barnard estate, but the integration stalled. Finchale still operates a separate identity provider federated into the wider environment. The federation functions adequately most of the time, which is often enough to discourage further investment, but it remains a classic break-of-gauge problem from Post 4. The seam exists, the organisation depends upon it, and very few people fully understand it. Privilege boundaries across that seam are blurred in places and difficult to assess confidently.
The Usworth Insurance estate presents a different challenge. The organisation inherited a complex web of managed-service arrangements and third-party access relationships that were never fully mapped during integration. There are controls. There are contracts. There are governance processes. What is missing is complete visibility. Assigning a precise maturity level is therefore difficult because part of the challenge is uncertainty itself. In practice, this is one of those situations where the organisation does not yet know enough about the environment to assess it honestly.
The situation changes again within Auckl. The fintech acquisition enters the model at approximately Level 3 and, in places, approaches Level 4. Identity hygiene was strong from the beginning. Cloud-native platforms dominate the estate. Access management is comparatively disciplined, and API-centric design has avoided many of the historical problems carried by the older businesses. Ironically, that strength is precisely why some of the largest layer-three risks are concentrated there.
The mediator layer across Barnard Financial Group places the organisation at roughly Level 2. Commercial SIEM, XDR and behavioural-analysis platforms are in production. Anomaly detection exists. Behavioural scoring exists. Automated response exists within carefully defined limits. What does not yet exist is a coherent mediator operating across all three layers. The mediator is performing meaningful work, but much of that work remains focused on the traditional subjects rather than the new ones.
The subject layer remains largely Level 1, although the reason deserves attention. The organisation is not lacking AI deployments. Quite the opposite. Auckl has deployed multiple autonomous agents into production, including an underwriting assistant capable of gathering information from systems across the wider group, generating recommendations and publishing outputs into shared repositories. The agents inherit service accounts carrying privileges that would be considered excessive by the standards applied elsewhere in the estate. None of this happened maliciously. The deployments occurred because the organisation treated AI as a feature of an application rather than as a subject within the trust algorithm.
Security architecture was not formally involved because the deployment velocity of the fintech business was fundamentally different from that of the parent organisation.
That is the most consequential finding in the assessment.
It is also remarkably common.
The largest layer-three exposure is concentrated in the technically strongest part of the group, because the technically strongest part of the group is where innovation is occurring. The legacy businesses carry substantial substrate debt, but they carry relatively little layer-three risk simply because they have not yet deployed autonomous subjects at meaningful scale.
The lesson is not that maturity and risk are inversely related. It is that different kinds of maturity expose different kinds of risk, and the architecture has to recognise the distinction.
What the model is for
The maturity model is not intended to be a grading exercise. Its real purpose is to give organisations a vocabulary for discussing Stacked Zero Trust readiness without collapsing the three layers into a single number, and to make visible the unevenness that characterises almost every large estate.
The first discipline is to assess by layer rather than by organisation. A single maturity score is neat, but it is usually misleading. Three scores tell a more complicated story, which is precisely why they are more useful.
The second discipline is to assess by business unit whenever the estate is heterogeneous. Barnard, Finchale, Usworth and Auckl are all part of the same group, yet their maturity characteristics are materially different. The overall picture emerges from understanding those differences rather than averaging them away.
The third discipline is simple but frequently uncomfortable: be honest about Level 1 on the subject layer. Most organisations are still there, and many of them are deploying agents anyway. In practice, the first step towards Level 2 is rarely a technology purchase. It is recognising that agents are subjects and accepting that the existing identity and posture mechanisms were never designed to govern them.
Finally, resist the temptation to chase Level 5 before earning Level 4. Self-correcting controls require measurement. Measurement requires operation. Operation requires implementation. Every vendor promising to shortcut that sequence is, consciously or otherwise, attempting to sell the future before the prerequisites exist. The journey through the levels is cumulative. It cannot be skipped.
The model in its full form, with assessment criteria, evidence indicators and common failure patterns for each layer and each maturity level, sits within the reference document that accompanies this series. The purpose of this post is simply to establish the framework, because the remaining posts depend on a common understanding of what maturity actually means.
One thing to take from this
A maturity model for Stacked Zero Trust only becomes useful when it treats the three layers independently. Real organisations are rarely mature everywhere at once. They are usually strong in one area, developing in another and largely unaware of a third, which means the gaps between layers often matter more than the average maturity level itself.
The Barnard Financial Group case illustrates that unevenness deliberately. Its strongest substrate exists alongside its most significant layer-three exposure, while the parts of the organisation carrying the greatest integration debt create a different class of risk altogether. That pattern is not unusual. If anything, it is one of the most common findings in large, acquisition-driven enterprises.
The purpose of the model is therefore not to assign a score. It is to make unevenness visible, to show where effort should go next, and to give organisations a way of discussing readiness that does not conceal their most important risks behind a single number.
The next post moves from internal assessment to the external market and, in doing so, tackles what is probably the most uncomfortable subject in the series: where vendors are over-claiming, where buyers are over-trusting, and how to distinguish genuine capability from well-marketed aspiration.
Post 11 of 13 in Stacked Zero Trust.
Previously: Post 10 - Shadow AI Is the New Shadow IT, Only Faster.
*Next: Post 12 - What Vendors Are Over-Claiming Right Now.*
The reference document at the end of the series includes the full maturity model with assessment criteria, evidence indicators, and common failure patterns per level per layer, plus a more detailed treatment of the Barnard Financial Group composite.
References drawn on in this post: NIST Special Publication 800-207, Zero Trust Architecture (August 2020); the CISA Zero Trust Maturity Model and the DoD Zero Trust Reference Architecture as the two reference maturity frameworks that the substrate layer of this model is informed by but deliberately distinct from. Barnard Financial Group is a fictional composite; any resemblance to a real institution is coincidental.


