ediverse Explore the platform

Spotlight PEPPOL BIS Billing 3.0 The EU e-invoicing mandate is here — France Sept 2026, Belgium Jan 2026, Germany 2025.

— 01

Foundations

— 02

Standards

— 03

Flagship messages

— 04

Tools

Zero Trust Architecture

On this page

NIST never trust, always verify.

Definition

ZTA controls access via policy enforcement point (PEP) and policy decision point (PDP). Components: identity (OAuth, OIDC), device posture, context (location, time), risk score, micro-perimeter segmentation. Adopted by US Executive Order 14028 (2021).

Origin

Forrester concept 2010 by John Kindervag ; standardised NIST SP 800-207 August 2020.

Example in context

A cloud EDI applies ZTA — each API call requires OIDC token + MFA + device posture check, never IP allow-listing alone.