Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Executive Order 14028 was a broad federal cybersecurity modernization package, not a zero-trust mandate alone. Its zero-trust direction became more concrete through the Office of Management and Budget’s M-22-09 memo, which set agency objectives for the end of fiscal year 2024; CISA’s later maturity model offers a framework for understanding and advancing those capabilities. Later policy actions amended portions of the cybersecurity policy landscape, so the original order should not be treated as an unchanged statement of current law.

What did Biden’s cybersecurity executive order do?

President Joe Biden signed Executive Order 14028 on May 12, 2021; it was published in the Federal Register on May 17, 2021. The order aimed to improve the federal government’s ability to identify, deter, protect against, detect, and respond to cyber threats. Zero trust was one part of that larger agenda, which also addressed:

  • Information sharing between the government and private sector.
  • Federal cloud security and stronger cybersecurity standards.
  • Multifactor authentication (MFA) and encryption.
  • Software supply-chain security.
  • Incident response playbooks and detection improvements.
  • Logging and investigative capabilities, as well as a Cyber Safety Review Board.

CISA’s overview of Executive Order 14028 describes these workstreams. The order set policy direction and instructed agencies; the practical objectives and implementation frameworks came through later OMB memoranda and CISA guidance.

What does zero trust mean in this federal policy?

Zero trust changes the basis for granting access. Being connected to an organization’s network is not, by itself, proof that a user or device should be trusted. OMB’s M-22-09 states, “A key tenet of a zero trust architecture is that no network is implicitly considered trusted.” Agencies are expected to authenticate and authorize access in context, control access at the application or resource level, and encrypt traffic as practicable. The memo also says federal applications should not rely on network-perimeter protection as their access control and envisages application access over the public internet.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In operational terms, zero trust is an architecture and way of managing access, not a single appliance or a guarantee that threats will disappear. Access should be limited to what is needed, with legitimacy evaluated using relevant identity, device, network, application, and data signals. CISA describes this as limiting access to the minimum necessary and continuously verifying legitimacy.

How did OMB turn the direction into agency objectives?

On January 26, 2022, OMB issued M-22-09, “Moving the U.S. Government Toward Zero Trust Cybersecurity Principles.” It established agency objectives intended to be met by the end of fiscal year 2024. That was a federal implementation target—not evidence that every agency achieved every objective, or a deadline for household users or private organizations.

The memo organized the federal approach around five control domains and also addressed cross-cutting considerations such as visibility, analytics, automation, and governance. It is a strategy for federal agencies rather than a product checklist: the central question is whether agencies can make and review access decisions based on more than network location.

What are CISA’s five zero-trust pillars?

CISA’s Zero Trust Maturity Model, Version 2, published in April 2023, provides a gradient for moving from traditional approaches toward more mature capabilities. Its five pillars identify the main areas where an organization can assess and advance its zero-trust practices:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Zero Trust Security: An Enterprise Guide
  • Zero Trust Security: An Enterprise Guide
  • Apress
  • ABIS BOOK

Identity

Identity is one of the policy’s core access domains. The model treats it as a pillar for assessing how mature an organization’s identity-related capabilities are; the cited summary does not prescribe one particular identity product.

Devices

Devices are a separate pillar, reflecting their role in contextual access decisions alongside identity and other signals. An organization can use the model to consider its device-related capabilities as part of its overall maturity, rather than treating identity as the only access factor.

Network

The network pillar belongs in a zero-trust framework, but network location alone does not establish trust. M-22-09 calls for moving beyond perimeter protection as the access-control decision and for encrypting traffic as practicable.

Applications and Workloads

This pillar focuses on applications and workloads as resources to which access is controlled. M-22-09 says federal applications should not depend on network-perimeter protection alone and envisages access over the public internet.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Data

Data is the fifth pillar. Its inclusion makes clear that zero trust is not just about who can enter a network: organizations also need to consider access to the information and resources they are protecting.

CISA tailored the model to federal agencies, while recommending that other organizations consider its approaches too. It is a reference framework for maturity, not a head-to-head product assessment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should an organization use the maturity model?

For an agency or other organization applying the model, a useful way to make it actionable is to treat it as a map of current and next capabilities, rather than as a shopping list:

  1. Set the scope. Decide which organization, systems, applications, and data the assessment covers. Federal agency objectives and voluntary use by other organizations are different contexts.
  2. Assess each pillar. Record what capabilities are in place across Identity, Devices, Network, Applications and Workloads, and Data, and where the organization still relies mainly on implicit trust or perimeter location.
  3. Look across the pillars. Consider whether visibility and analytics can show how access decisions are made and what security events occur, and whether automation and governance support those decisions.
  4. Choose a measurable next capability. Prioritize a gap that can be implemented and observed, then use the model’s maturity progression to guide further work.

This is a practical way to apply the model’s domains and maturity concept; CISA’s framework itself is not a product recommendation or a single prescribed deployment sequence.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do the order, OMB memo, CISA model, and later amendments differ?

Policy layer Date What it does
Executive Order 14028 Signed May 12, 2021; published May 17, 2021 Sets a broad federal cybersecurity agenda, including but not limited to zero trust. CISA overview
OMB M-22-09 January 26, 2022 Sets federal zero-trust objectives intended for the end of FY2024. OMB memorandum
CISA Zero Trust Maturity Model v2 April 2023 Provides a maturity framework with five pillars, tailored to federal agencies and also recommended for consideration by other organizations. CISA model
Later cybersecurity policy action June 2025 Amends portions of earlier cybersecurity policy; the cited action includes striking an EO 14028 reference from one provision. White House action

Is Executive Order 14028 still in effect?

A blanket yes-or-no answer would overstate what the available official material establishes. The June 2025 White House action amended portions of cybersecurity executive policy and struck an EO 14028 reference from one provision, but that fact alone does not establish the current status of every section, deadline, or implementing memorandum. The original order and its implementation documents should therefore be distinguished from later amendments; anyone relying on a particular provision for a current legal or compliance decision should check the effective official text and applicable current guidance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.