Zero trust is a good idea wrapped in bad marketing. Stripped of vendor language it says something simple: stop granting access because of where a request came from, and start granting it because of what the requester proved.
The technology to do that mostly exists. Programmes stall somewhere else.
Where they stall
Inventory. You cannot make per-workload decisions about workloads you cannot enumerate. Most organisations discover halfway in that their inventory is a spreadsheet with a confidence interval.
Identity for machines. Human identity is a solved problem in most enterprises. Service identity is often a shared credential in a config file that three teams depend on and nobody owns.
The exception path. Every real environment has something that cannot be brought into the model this quarter. If there is no honest, time-boxed exception process, teams will route around the whole programme instead.
What to do first
Pick one segment where the inventory is genuinely known and the workloads are genuinely owned. Do it properly there. A working example inside your own organisation is worth more than any reference architecture, because it settles the arguments about feasibility with evidence.