A guide to the NCSC’s eight zero trust design principles
3 minute read
Ricky Phillips
April 28th, 2026
If you work in or around UK public sector IT, you’ve probably heard “zero trust” thrown around a lot lately. But between the NCSC updating its guidance in January 2026 and the Home Office Engineering Guidance now mandating zero trust principles outright, it’s gone from a buzzword to a genuine compliance requirement.
But we understand zero trust can be hard to understand. So, here’s your plain-English walkthrough of the NCSC’s eight design principles, what they actually mean, and why they matter for your organisation.
First, what does “zero trust” actually mean?
The name is a little dramatic, but the idea is straightforward. Traditional network security worked a bit like a castle, thick walls on the outside, and once you were in, you were trusted. Zero trust is the opposite. It says: don’t trust any request by default, regardless of where it comes from. Not from inside your network. Not from a known device. Not even from a user you recognise.
The Home Office Engineering Guidance puts it plainly: access policies must be based on least privilege and the assumption that all requests are potentially hostile.
The NCSC’s Eight Design Principles
The NCSC updated its zero trust architecture guidance on 16 January 2026. Here’s what each principle means in practice.
- Know your architecture, including users, devices, services, and data
You can’t protect what you can’t see. This principle is about having a clear, current picture of everything on your network, who’s using it, what devices are connecting, and where your sensitive data lives. For many public sector organisations, this alone is a significant undertaking.
- Know your user, service, and device identities
Identity is the new perimeter. Before granting any access, you need to be confident about who is asking, whether that’s a person, a service account, or an automated process. Strong identity management, including multi-factor authentication, sits at the heart of this principle.
- Assess your user behaviour, and device and service health
Zero Trust asks: is this request normal? Is the device up to date and uncompromised? Is the user logging in from an unusual location at an unusual time? Continuous assessment is the goal here.
- Use policies to authorise requests
Access decisions should be driven by policy, not by someone manually approving requests. Those policies should be granular, consistent, and based on the principle of least privilege, giving users access to what they need, nothing more.
- Authenticate and authorise everywhere
This one challenges the old assumption that traffic inside your network is safe. Under zero trust, every request needs to be authenticated and authorised. There’s no trusted zone.
- Focus your monitoring on users, devices, and services
Logs and monitoring aren’t just a compliance checkbox. Knowing what’s happening across your environment in real time means you can spot anomalies quickly and respond before a breach becomes a crisis.
- Don’t trust any network, including your own
This is perhaps the most psychologically difficult shift for teams used to traditional perimeter security. The NCSC is explicit: your internal network should be treated with the same suspicion as the public internet. Network location tells you nothing about trustworthiness.
- Choose services designed for zero trust
Legacy systems often weren’t built with zero trust in mind. When procuring or building new services, organisations should actively choose tools and platforms that support zero trust principles, including granular access controls, strong identity integration, and audit logging.
What does this mean for UK public sector teams?
The Home Office Engineering Guidance now requires zero trust principles as a baseline, and the NCSC’s January 2026 update signals that this is the direction of travel for the whole of government.
The good news is that you don’t have to do everything at once. The NCSC’s guidance is clear that zero trust is a journey, not a switch you flip. Most organisations will start with the basics, solid identity and access management, MFA, and device health checks, and build from there.
The less good news? Many public sector IT environments are carrying years of legacy infrastructure, complex supplier relationships, and fragmented data estates. Applying these principles consistently across all of that takes time, resource, and a clear strategy.
Where to start
If you’re trying to make sense of where your organisation sits against the NCSC’s principles, a good first step is an honest audit of your identity and access management practices. Who has access to what? How is that access granted, reviewed, and revoked? Are your monitoring tools giving you visibility across users and devices and services?
From there, the NCSC’s own guidance gives a practical framework for prioritising your next steps. Zero trust isn’t just a technical architecture. It’s a mindset shift, one that the UK’s own regulatory and guidance landscape is now firmly behind.
Need help applying the NCSC’s zero trust principles in your organisation? Get in touch to find out how we work with public sector teams to build practical, compliant security strategies.

