Agencies must build a zero trust architecture anchored to NIST SP 800-207 and CISA's Zero Trust Maturity Model, and the first move is not a product purchase. It's an inventory. Identify and classify mission-critical resources, appoint a Zero Trust lead to coordinate across IT, security, and procurement, and treat continuous verification and least privilege as the operating principle for every subsequent decision.
TL;DR:
- Completing an accurate full inventory of mission-critical resources is essential before implementing microsegmentation or advanced controls; data classification should precede segmentation efforts.
- Agencies should focus on closing MFA gaps for privileged accounts, finishing device inventories, and encrypting internal DNS or HTTP traffic within the current fiscal year to advance their maturity stage.
- The first steps are defining a Zero Trust lead with authority, tracking key performance indicators, and tying progress to budget cycles, rather than trying to overhaul all pillars simultaneously.
- Legacy system integration relies on placing policy enforcement points at network boundaries and prioritizing data tagging and encryption to unlock phased improvements, not immediate wholesale modernization.
- Agencies must prioritize organizational alignment through cross-functional leadership and sequencing work logically, with early focus on data classification, to avoid stalled progress and unmanaged complexities.
Table of Contents
- Federal Guidance at a Glance: CISA, NIST, and OMB Requirements
- Mapping the Zero Trust Maturity Model to Agency Priorities
- Use NIST SP 800-207 and RMF to Plan an Incremental Transition
- Technical Controls by Pillar: Identity, Devices, Networks, Applications, and Data
- Governance, Roles, Metrics, and Budget Alignment
- Procurement and Acquisition: GSA Pathways and RFI/RFP Guidance
- Publisher Perspective: Practical Lessons From Modernization Work
- Challenges and Common Pitfalls Agencies Face When Implementing Zero Trust
- Case Studies and Real-World Examples of Zero Trust Adoption
- Continuous Monitoring and Real-Time Analytics in Zero Trust
- Integration Strategies for Legacy Systems in a Zero Trust Framework
- Training and Awareness Programs for Agency Staff
- The Overlooked Cost of Treating Zero Trust as a Checklist
- Request a Zero Trust Readiness Briefing
- Sources
- FAQ
Federal Guidance at a Glance: CISA, NIST, and OMB Requirements
Three documents govern nearly every agency zero trust decision made today. NIST SP 800-207 defines the architectural principles: trust is never granted implicitly, and authentication and authorization happen as discrete, continuous functions rather than one-time gate checks at login. CISA's Zero Trust Maturity Model translates that theory into a measurable roadmap. OMB's M-22-09 memorandum turns both into binding federal policy, requiring civilian agencies to submit implementation plans tied to specific technical actions.
What the guidance requires, in practice:
- Identity: enterprise-managed accounts, phishing-resistant MFA using FIDO2 or PIV
- Devices: complete inventories paired with endpoint detection tools
- Networks: encrypted DNS and HTTP for internal traffic, not just external-facing systems
- Data: classification and protection tied to sensitivity, not network location
By the numbers: OMB's memo set the original target window at FY22 through FY24 for baseline actions, tying agency budget submissions directly to demonstrated progress against these controls, per the M-22-09 memorandum.
Mapping the Zero Trust Maturity Model to Agency Priorities
CISA's model defines four stages: Traditional, Initial, Advanced, and Optimal, spanning five pillars covering identity, devices, networks, applications and workloads, and data, according to CISA's Zero Trust Maturity Model. A Traditional agency still relies on perimeter firewalls and manual access reviews. An Optimal agency authenticates continuously, enforces access decisions per session, and automates policy enforcement across every pillar.
Most agencies land somewhere between Traditional and Initial, and three signals confirm it:
- MFA gaps — if phishing-resistant MFA isn't universal, identity maturity is Initial at best.
- Device blind spots — an incomplete device inventory means the Devices pillar can't advance regardless of other progress.
- Flat network trust — if internal traffic moves unencrypted or unsegmented, the Networks pillar is still Traditional.
Pick three objectives to move one stage forward this fiscal year: close the MFA gap for privileged accounts, finish the device inventory, and encrypt one class of internal DNS traffic as a pilot.
Pro Tip: Don't try to advance all five pillars simultaneously. Pick the pillar with the lowest maturity and the highest mission risk, and fund that one first. Spreading effort evenly across all five usually means none of them move.
Use NIST SP 800-207 and RMF to Plan an Incremental Transition
The NIST planning guide maps the Risk Management Framework's seven steps directly onto zero trust migration tasks, which means agencies don't need a separate planning methodology. PREPARE becomes your resource inventory phase. CATEGORIZE is where you rank systems by mission impact. IMPLEMENT and ASSESS map to phased technical rollout and validation.
Data inventory and classification have to come before microsegmentation, not after. Segmenting a network you haven't mapped just recreates old trust boundaries with new labels. NIST SP 800-207 also acknowledges that per-transaction authorization is the goal, not the starting point. Legacy systems typically need coarser controls first, refined as they're re-architected, per NIST SP 800-207.
Structuring the work across fiscal years:
- Year one: inventory, classification, and identity consolidation
- Year two: device posture integration and network encryption pilots
- Year three: application-level access controls and expanded segmentation
This sequencing also gives budget officers a defensible story when zero trust milestones show up in appropriations requests. Agencies weighing broader modernization sequencing may find useful context in this risk management guide for public sector agencies.
Technical Controls by Pillar: Identity, Devices, Networks, Applications, and Data
Each pillar has a short list of controls that move the needle fastest, based on what OMB and CISA guidance actually prioritize.
Identity: Centralize identity management under one enterprise system rather than per-application logins. Require phishing-resistant MFA, specifically FIDO2 or PIV-based methods, not SMS codes. Extend federation to contractor and partner accounts rather than issuing shadow credentials.
Devices: A device inventory is only useful if it's complete, including personally owned and IoT devices touching agency networks. Layer endpoint detection and response (EDR) or extended detection and response (XDR) tools on top, and feed device posture signals into access decisions in real time.
Networks: Encrypt DNS and HTTP traffic internally, not just at the perimeter. M-22-09 explicitly directs agencies to treat internal applications as if they were internet-accessible from a security standpoint, per the M-22-09 memorandum. Microsegmentation follows, not precedes, that mindset shift.
Applications and workloads: Move toward continuous security testing rather than annual assessments. Retire VPN as a default access method where the underlying application can support direct, authenticated access instead.
Data: Classify by sensitivity, automate tagging where volume makes manual labeling impractical, and pair encryption with disciplined key management and access logging.
By the numbers: M-22-09 specifically calls out enterprise-managed identity, phishing-resistant MFA, complete device inventories, and encrypted DNS/HTTP as baseline actions federal civilian agencies must demonstrate, per the M-22-09 memorandum.
Governance, Roles, Metrics, and Budget Alignment
A zero trust program without a named owner tends to stall the moment two departments disagree on priorities. The Zero Trust lead role has to sit above any single office, coordinating IT, security, procurement, and the mission teams who actually own the data being protected.
- Name a Zero Trust lead with authority to convene cross-functional decisions, not just report status upward.
- Track four KPIs: MFA coverage rate for privileged accounts, device inventory completeness, percentage of internal HTTP/DNS traffic encrypted, and maturity stage progress per pillar.
- Tie milestones to budget cycles so funding requests reflect demonstrated progress rather than aspirational plans.
Pro Tip: Build your KPI dashboard before you build your first technical control. Agencies that measure from day one catch stalled pillars months earlier than those that wait for an annual review.
Procurement and Acquisition: GSA Pathways and RFI/RFP Guidance
Write requirements around capabilities, not brand names. A requirement asking for "phishing-resistant MFA supporting FIDO2 with SAML/OIDC federation" survives a protest challenge far better than one naming a specific vendor product.
Common acquisition routes include the GSA Multiple Award Schedule and GWAC vehicles, both of which support modular, capability-based statements of work suited to AI for agencies zero trust rollouts. When drafting an RFI or RFP, specify:
- Interoperability with existing identity providers and SIEM platforms
- Telemetry export capabilities for CISA's continuous diagnostics requirements
- FedRAMP authorization status for any cloud-hosted component
- Automation and orchestration APIs, since manual policy updates don't scale past a pilot
Shared services are worth evaluating before building custom infrastructure. CISA's Protective DNS service, for example, accelerates the encrypted DNS requirement without agencies standing up their own resolver infrastructure, according to CISA's zero trust resource hub. Agencies choosing between building internally and buying a defined-scope engagement often benefit from reviewing how to select IT partners for public sector success before finalizing acquisition strategy.
Publisher Perspective: Practical Lessons From Modernization Work
Legacy re-architecture, compliance automation, and DevOps pipeline work all touch the same nerve zero trust programs hit: agencies rarely fail on technology choice. They stall on scope. A modernization engagement that tries to touch everything at once usually delivers on nothing within budget.
Outcome-owned, defined-scope engagements reduce that risk because the deliverable is fixed before work starts, not negotiated mid-project as requirements drift. That structure matters more in zero trust work than most modernization categories, because the temptation to expand scope into "just segment everything now" is constant.
Rutledge & Associates operates as an SDVOSB and SBA-certified firm serving public-sector clients across Maryland, New York, and Florida, with work concentrated in exactly the compliance-heavy programs where scope discipline pays off fastest.
Challenges and Common Pitfalls Agencies Face When Implementing Zero Trust
The most common failure mode isn't technical. It's organizational. Operational challenges tend to arise from cultural and structural issues more than from any specific tool falling short, and cross-functional leadership matters more than most agencies initially budget for. When the Zero Trust lead role reports into IT alone, procurement and mission owners frequently treat the program as someone else's initiative, and adoption slows accordingly.
A second recurring pitfall: attempting network segmentation before data classification is complete. Segmenting resources you haven't mapped by sensitivity just relocates old trust assumptions onto new network boundaries, and agencies often discover this only after the segmentation project is already underway. The fix is sequencing discipline: finish the inventory and classification pass, even a rough one, before committing budget to segmentation tooling.
A third pitfall is treating zero trust as a single procurement event rather than a multiyear program. Agencies that buy one platform expecting it to satisfy all five pillars typically find gaps in at least two, usually Data and Applications/Workloads, because those pillars require organizational process changes that no single tool automates away.
Mitigation strategies that actually work tend to share three traits: they name a single accountable owner, they sequence data work ahead of network work, and they build KPI tracking into the program from month one rather than adding it retroactively. Agencies that skip any of the three usually end up re-planning the effort within eighteen months, which costs more than getting the sequence right initially.
Case Studies and Real-World Examples of Zero Trust Adoption
Federal civilian agencies operating under M-22-09 have published implementation plans that show a consistent pattern: the agencies furthest along the maturity curve started with identity, not network segmentation. Enterprise-managed identity and phishing-resistant MFA rollouts tend to move fastest because they touch a well-defined population, employees and contractors with existing accounts, rather than an open-ended set of applications and network paths.
State-level adoption follows a looser timeline than federal civilian agencies, since OMB's mandate applies specifically to federal agencies. CISA has encouraged state and local governments to adopt the maturity model voluntarily as a planning baseline, and agencies that have done so report the same sequencing advantage: identity and device inventory work first, network and application changes second.
A recurring theme across agencies further along the maturity curve is scope containment. Programs that defined a single pilot, often one high-value application or one user population, before expanding showed measurably faster progress through the Initial-to-Advanced transition than programs that attempted agency-wide rollout from the outset. The pilot approach also produces a working reference architecture that later phases can copy, rather than requiring each subsequent rollout to solve integration problems from scratch.
The common thread across successful adoption stories isn't a specific vendor stack. It's sequencing: identity first, devices second, then networks and data in parallel, with applications and workloads modernized incrementally as legacy systems are refactored rather than replaced wholesale.

Continuous Monitoring and Real-Time Analytics in Zero Trust
Zero trust isn't a configuration you set once. It's a posture that depends on continuous signal collection to make each access decision, which means visibility and analytics function as a cross-cutting capability rather than a separate pillar, consistent with CISA's own framing in the Zero Trust Maturity Model.
Real-time analytics feed three distinct functions inside a mature program. First, they inform access decisions directly. A device posture change, a location anomaly, or an unusual authentication pattern should be able to trigger a re-authentication challenge or an outright access denial without waiting for a human analyst to notice. Second, analytics support the audit and compliance reporting agencies must submit under OMB's memo. Third, they surface the slow drift that turns an Optimal-stage control back into an Initial-stage one, such as a device inventory that quietly falls out of sync with actual deployed hardware.
Agencies that treat monitoring as an afterthought, bolted on after core controls are deployed, tend to lose visibility into exactly the failure modes zero trust is designed to catch. A misconfigured segmentation rule or an expired certificate on an internal service can silently degrade the security posture for weeks without continuous telemetry catching it.
The practical requirement for procurement teams: any tool acquired for identity, device, or network control needs a telemetry export path into a central analytics platform. A point solution that doesn't export usable signal data creates a blind spot regardless of how well it performs its narrow function.
Integration Strategies for Legacy Systems in a Zero Trust Framework
Rip-and-replace is rarely realistic for agencies running mainframe applications or decades-old case management systems that mission programs depend on daily. NIST SP 800-207 explicitly acknowledges this, noting that legacy systems generally require coarser-grained controls initially, with per-transaction authorization applied as those systems are refactored over time, according to NIST SP 800-207.
Practical integration usually starts with a policy enforcement point placed in front of the legacy system rather than inside it. This lets identity and access controls apply at the network boundary of the legacy application without touching its internal code, buying time for a deeper refactor later. Encrypting the DNS and HTTP traffic around a legacy system, even when the system itself can't be modernized quickly, satisfies a meaningful chunk of the Networks pillar without a rewrite.

Data classification often reveals the highest-value integration point. Legacy systems frequently hold the most sensitive agency data, precisely because they've never been migrated, which makes them a priority target for data tagging and encryption controls even before any architectural changes happen. A short, focused data inventory and tagging effort on a legacy system can unblock downstream segmentation work that would otherwise wait for a multiyear replacement project.
Agencies weighing modernization sequencing against zero trust deadlines may find it useful to review broader modernization solutions for government agencies before committing to a legacy integration approach, since the two efforts often share the same underlying inventory work.
Training and Awareness Programs for Agency Staff
Zero trust changes daily user experience in ways that technical rollouts alone don't prepare staff for. An employee accustomed to logging in once each morning and staying authenticated all day will notice, and often resist, a shift toward continuous re-authentication challenges triggered by device posture or location changes.
Effective training programs address three audiences differently. End users need practical guidance on what MFA prompts look like, why they appear, and how to report a suspicious one, since phishing-resistant MFA still depends on users recognizing legitimate versus fraudulent authentication requests. IT and security staff need deeper training on the specific tools deployed for each pillar, since a poorly configured EDR alert threshold generates as much operational noise as a well-configured one generates useful signal. Procurement and program staff need enough conceptual grounding in zero trust principles to write and evaluate capability-based requirements without defaulting to brand-name specifications.
Awareness campaigns work best when tied to the actual rollout timeline rather than delivered as a one-time briefing months before any control goes live. Staff retain almost nothing from a zero trust orientation session if the first MFA prompt they encounter arrives six months later. Sequencing training to land just before each phased control activates, tied to the same fiscal-year rollout plan governing the technical work, keeps the concepts fresh when they're actually needed.
The Overlooked Cost of Treating Zero Trust as a Checklist
The gap between what zero trust promises and what agencies actually deliver almost always comes down to sequencing, not funding. Agencies with adequate budgets still stall when they buy tools before finishing the inventory work those tools depend on. That's the pattern this guidance keeps surfacing: identity moves fast because the population is bounded, data classification moves slowly because nobody wants to do the unglamorous tagging work first, and network segmentation gets attempted prematurely because it feels like visible progress.
Conventional advice treats zero trust as a five-pillar checklist to complete in parallel. That framing is backward. CISA's own maturity model rewards agencies that advance unevenly, pushing hardest on whichever pillar carries the most mission risk, rather than agencies that spread effort evenly and end up mediocre across all five.
If there's one priority a reader should take from this guide, it's this: fund the data inventory and classification work before anything else, even if it feels like the least impressive line item in a budget request. Every stalled zero trust program traced back far enough usually stalls at that exact gap.
— Randy
Request a Zero Trust Readiness Briefing
Agencies weighing whether to build zero trust capability internally or bring in a defined-scope partner face a real tradeoff: internal builds take longer to staff and often expand past their original scope, while typical staff-augmentation contracts add headcount without necessarily owning outcomes. Rutledge & Associates works differently, taking ownership of a clearly defined deliverable, such as a data classification pass, an identity consolidation project, or a device inventory campaign, rather than supplying bodies to a program that still has to manage the work itself. That structure fits agencies trying to hit a specific maturity milestone on a fixed budget line without absorbing the coordination overhead of a large internal build. If your agency needs to move a pillar forward before the next reporting cycle, request a readiness briefing to scope the work against your current maturity stage and budget window.
Sources
- NIST Special Publication 800-207, Zero Trust Architecture
- CISA Zero Trust Maturity Model Version 2.0
- M-22-09: Moving the U.S. Government Toward Zero Trust Cybersecurity Principles
- Planning for a Zero Trust Architecture: A Planning Guide for Federal Administrators
FAQ
What Are the Five Pillars of Zero Trust?
CISA's model defines five pillars: Identity, Devices, Networks, Applications and Workloads, and Data, supported by cross-cutting capabilities in Visibility and Analytics, Automation and Orchestration, and Governance, per the Zero Trust Maturity Model.
Why Are Federal Agencies Required to Implement Zero Trust?
OMB's M-22-09 memorandum mandates zero trust actions for federal civilian agencies to reduce risk from increasingly sophisticated intrusions that exploit implicit trust in traditional perimeter defenses, per the M-22-09 memorandum.
What Are Concrete Examples of Zero Trust Controls?
Phishing-resistant MFA using FIDO2 or PIV, complete device inventories paired with EDR tools, encrypted internal DNS and HTTP traffic, and data tagging tied to sensitivity classification are all specific controls named in federal guidance.
How Do State Agencies Approach Zero Trust Differently Than Federal Agencies?
OMB's mandate applies to federal civilian agencies, while state agencies typically adopt CISA's maturity model voluntarily as a planning baseline rather than under a binding deadline.
Who Can Help Agencies Scope a Zero Trust Implementation Project?
Firms offering defined-scope, outcome-owned engagements, such as Rutledge & Associates, can take ownership of specific zero trust deliverables like data classification or identity consolidation without the overhead of a full internal build.
