Skip to Main Content

Want to stay up-to-date with the latest IT news?
Subscribe to our mailing list to hear the latest news, events, free resources, and more for your industry.

Sign up now
Blog

A guide to the NCSC’s eight zero trust design principles

3 minute read

Ricky Phillips

April 28th, 2026

A guide to the NCSC’s eight zero trust design principles

3 minute read

Ricky Phillips

April 28th, 2026

If you work in or around UK public sector IT, you’ve probably heard “zero trust” thrown around a lot lately. But between the NCSC updating its guidance in January 2026 and the Home Office Engineering Guidance now mandating zero trust principles outright, it’s gone from a buzzword to a genuine compliance requirement.

But we understand zero trust can be hard to understand. So, here’s your plain-English walkthrough of the NCSC’s eight design principles, what they actually mean, and why they matter for your organisation.

First, what does “zero trust” actually mean? 

The name is a little dramatic, but the idea is straightforward. Traditional network security worked a bit like a castle, thick walls on the outside, and once you were in, you were trusted. Zero trust is the opposite. It says: don’t trust any request by default, regardless of where it comes from. Not from inside your network. Not from a known device. Not even from a user you recognise. 

The Home Office Engineering Guidance puts it plainly: access policies must be based on least privilege and the assumption that all requests are potentially hostile.  

The NCSC’s Eight Design Principles 

The NCSC updated its zero trust architecture guidance on 16 January 2026. Here’s what each principle means in practice. 

  1. Know your architecture, including users, devices, services, and data

You can’t protect what you can’t see. This principle is about having a clear, current picture of everything on your network, who’s using it, what devices are connecting, and where your sensitive data lives. For many public sector organisations, this alone is a significant undertaking. 

  1. Know your user, service, and device identities

Identity is the new perimeter. Before granting any access, you need to be confident about who is asking, whether that’s a person, a service account, or an automated process. Strong identity management, including multi-factor authentication, sits at the heart of this principle. 

  1. Assess your user behaviour, and device and service health

 Zero Trust asks: is this request normal? Is the device up to date and uncompromised? Is the user logging in from an unusual location at an unusual time? Continuous assessment is the goal here. 

  1. Use policies to authorise requests

Access decisions should be driven by policy, not by someone manually approving requests. Those policies should be granular, consistent, and based on the principle of least privilege, giving users access to what they need, nothing more. 

  1. Authenticate and authorise everywhere

This one challenges the old assumption that traffic inside your network is safe. Under zero trust, every request needs to be authenticated and authorised. There’s no trusted zone. 

  1. Focus your monitoring on users, devices, and services

Logs and monitoring aren’t just a compliance checkbox. Knowing what’s happening across your environment in real time means you can spot anomalies quickly and respond before a breach becomes a crisis. 

  1. Don’t trust any network, including your own

This is perhaps the most psychologically difficult shift for teams used to traditional perimeter security. The NCSC is explicit: your internal network should be treated with the same suspicion as the public internet. Network location tells you nothing about trustworthiness. 

  1. Choose services designed for zero trust 

Legacy systems often weren’t built with zero trust in mind. When procuring or building new services, organisations should actively choose tools and platforms that support zero trust principles, including granular access controls, strong identity integration, and audit logging. 

What does this mean for UK public sector teams? 

The Home Office Engineering Guidance now requires zero trust principles as a baseline, and the NCSC’s January 2026 update signals that this is the direction of travel for the whole of government. 

The good news is that you don’t have to do everything at once. The NCSC’s guidance is clear that zero trust is a journey, not a switch you flip. Most organisations will start with the basics, solid identity and access management, MFA, and device health checks, and build from there. 

The less good news? Many public sector IT environments are carrying years of legacy infrastructure, complex supplier relationships, and fragmented data estates. Applying these principles consistently across all of that takes time, resource, and a clear strategy. 

Where to start 

If you’re trying to make sense of where your organisation sits against the NCSC’s principles, a good first step is an honest audit of your identity and access management practices. Who has access to what? How is that access granted, reviewed, and revoked? Are your monitoring tools giving you visibility across users and devices and services? 

From there, the NCSC’s own guidance gives a practical framework for prioritising your next steps. Zero trust isn’t just a technical architecture. It’s a mindset shift, one that the UK’s own regulatory and guidance landscape is now firmly behind. 

Need help applying the NCSC’s zero trust principles in your organisation? Get in touch to find out how we work with public sector teams to build practical, compliant security strategies. 

Headshot of Ricky Phillips

About the author

Ricky Phillips, Cyber Security Solutions Manager

Ricky joined Phoenix in 2018 to focus on the Mimecast potfolio, later moving into a broader security role sitting in the Alliances Team. Ricky now manages a team of seven Security Specialists tasked to ensure our customers get the right solutions for their issues. Ricky is passionate about ensuring we advise customers on what is the best fit for them as an organisation, taking into account the multitude of factors involved in choosing a solution, Ricky is commited to make sure that Phoenix is seen as a trusted partner in the cyber security space.

Connect with Ricky on LinkedIn.