Zero Trust Network Access (ZTNA) is defined by its architecture — identity-based access, least privilege, no implicit network trust, and continuous verification — not by which protocol carries the traffic. A service can use the OpenVPN protocol as its encrypted transport and still meet every NIST SP 800-207 and CISA Zero Trust Maturity Model requirement, because protocol and architecture sit at different layers of the stack.