More and more enterprise organizations are considering adopting a zero-trust approach to security, but there are challenges that need to be addressed. There is no zero trust-in-a-box product available and the approach requires a shift in thinking, policy, and practice. In 2021, the National Institute of Standards and Technology (NIST) finalized a zero trust architecture, which should serve as the starting point for every enterprise new to the space. This Nemertes report covers a recommended, 3-step process of consideration and implementation of a zero trust approach along with a checklist of points to consider in evaluating zero trust solutions.