Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Zero trust is a cybersecurity approach that verifies access instead of assuming a request is safe because it comes from inside an agency network. The federal strategy in OMB Memorandum M-22-09 translated that principle into goals across five pillars—Identity, Devices, Networks, Applications and Workloads, and Data—with shared capabilities such as analytics and governance supporting all five. The memorandum set an end-of-FY2024 target for its specified goals; that deadline is not evidence that every agency met them.

What zero trust means

In a zero-trust approach, network location alone does not make a user, device, or request trustworthy. Access decisions must be verified, and traffic should be encrypted and authenticated as soon as practicable. OMB captured the shift this way: “A key tenet of a zero trust architecture is that no network is implicitly considered trusted—a principle that may be at odds with some agencies’ current approach to securing networks and associated systems.” OMB Memorandum M-22-09

This is an architectural and operational approach, not a single product or perimeter appliance. It applies across cloud, on-premises, and hybrid systems. The aim is to make access and protections depend on relevant identity, device, application, and data conditions rather than on a broad assumption that an internal network is safe.

The five pillars in the federal strategy

M-22-09 organized its agency goals around CISA’s five pillars. The directions below describe what the memorandum called for; they are not a universal product specification.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Pillar Federal direction
Identity Use enterprise-managed identities and enforce strong multifactor authentication (MFA) at the application layer. Require phishing-resistant MFA for agency staff, contractors, and partners; where MFA is supported, make phishing-resistant MFA an option for public users. Consider at least one device-level signal, in addition to identity, when authorizing access. OMB M-22-09
Devices Maintain reliable, complete inventories of devices authorized or operated for official business, and deploy endpoint detection and response capabilities consistent with federal guidance. OMB M-22-09
Networks Encrypt DNS requests wherever technically supported, require authenticated HTTPS for production HTTP traffic—including internal traffic—and plan to isolate applications and environments instead of relying on a broadly trusted perimeter. OMB M-22-09
Applications and Workloads Approach applications as internet-connected from a security perspective, test them rigorously, welcome external vulnerability reports, and plan for application-level access rather than requiring users to enter a particular network first. OMB M-22-09
Data Categorize data according to protection needs, monitor access to sensitive data, apply protections suited to those categories, and implement enterprise logging and information sharing. OMB M-22-09

Capabilities that support every pillar

The pillars rely on capabilities that cross organizational and technical boundaries: visibility and analytics, automation and orchestration, and governance. For example, an agency needs useful information about access and activity to assess risk, and coordinated governance to make security decisions consistent across systems. These capabilities are part of the strategy, not a sixth technical pillar. OMB M-22-09

How federal agencies were told to organize implementation

Executive Order 14028 required agencies to develop implementation plans. M-22-09 instructed agencies to build on those plans, incorporate the memorandum’s additional requirements, and submit implementation plans covering FY2022–FY2024 to OMB and CISA for OMB concurrence, along with budget estimates. The memorandum set a submission deadline of within 60 days. It also called for designated implementation leads and coordination among agency leadership and IT, security, acquisition, finance, and privacy functions. OMB M-22-09

The work therefore involved agency-wide planning, not only technical deployment by a security team. Plans needed to connect security goals with mission needs, budgets, existing systems, and the functions responsible for buying and operating technology.

Using maturity and architecture guidance

M-22-09 describes itself as a starting point rather than a complete blueprint for a fully mature zero-trust architecture. It points agencies toward CISA’s Zero Trust Maturity Model and Cloud Security Technical Reference Architecture, and toward NIST SP 800-207 and other agency reference architectures for longer-term design. CISA’s overview describes its maturity model as complementary to OMB’s strategy. OMB M-22-09 framing and references CISA overview of the Executive Order

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Zero Trust Security: An Enterprise Guide
  • Zero Trust Security: An Enterprise Guide
  • Apress
  • ABIS BOOK

A maturity model helps an agency assess where it is and plan progression across pillars and shared capabilities; it does not substitute for architecture decisions tailored to the agency’s mission and environment. The memorandum does not prescribe one universally applicable product or vendor.

How to assess an implementation approach

Agencies evaluating designs or tools can use the memorandum’s goals as a requirements checklist. A credible approach should fit the agency’s architecture and mission and account for:

  • Whether identities are managed enterprise-wide, authentication is enforced at the application layer, phishing-resistant MFA is supported for the required populations, and device context can inform access decisions.
  • Whether device inventories and endpoint detection cover the agency’s authorized and officially operated fleet.
  • Whether the design supports encrypted DNS where technically available, authenticated HTTPS, application and environment isolation, and the agency’s cloud, on-premises, or hybrid systems.
  • Whether applications can be rigorously tested and external vulnerability reports handled, and whether sensitive-data access can be monitored and logged.
  • Whether visibility, analytics, automation, orchestration, governance, and integration with existing systems are adequate.

These are evaluation dimensions derived from the OMB goals and planning references, not a ranking of commercial offerings.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the FY2024 deadline does—and does not—tell you

M-22-09 set the end of FY2024 as the target for agencies to achieve its specified zero-trust security goals. That is a policy deadline, not an adoption statistic or proof of universal completion. The cited policy and reference material do not establish the present government-wide completion picture or whether a successor strategy has replaced the memorandum. OMB M-22-09

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.