Zero Trust Implementation Module 1 · The Architecture

The Federal Map

Last reviewed · content updated

Intermediate

What you'll learn

~18 min
  • Navigate the eight documents a Zero Trust program is actually graded against
  • Use an AI CLI to verify whether a cited authority is still in force - before trusting it
  • Read the federal corpus as engineering documentation, not compliance homework

Why a commercial engineer should care about federal memos

If you’re not in government, here is the frame that makes this lesson worth eighteen minutes: the federal Zero Trust corpus is the most complete public reference architecture in existence — requirements, maturity model, implementation guides, and the lessons of the world’s largest enforced rollout, all free. Read it as engineering documentation. If you are in government, this map is what your program is graded against — and every stale citation you inherit is budget spent building evidence against a dead standard, and a finding waiting in the next assessment. If you are commercial, you are graded against a different map — NIST’s Cybersecurity Framework (CSF 2.0), ISO 27001, and increasingly your cyber-insurer’s renewal questionnaire — and the same currency discipline applies to it. The answer below is an applicability register: one row per source, marked binding / advisory / implementation guidance for federal readers (reusable architecture / benchmark / not applicable for commercial ones), with an owner and a last-checked date. The table that follows seeds that register — the columns you add when you adopt it are applicability (binding for whom), an owner, and a last-checked date. Which brings us to this lesson’s real skill.

The map, at cruising altitude

Eight documents carry the weight. Depth on each arrives in the pillar lesson that uses it — this is the map, not the territory:

#DocumentWhat it isOne-line takeaway
1NIST SP 800-207 (2020)The architectureTenets + PDP/PEP — Lesson 1.1
2CISA Zero Trust Maturity Model v2.0 (2023)The measuring stick5 pillars, 3 cross-cutting capabilities, 4 stages — your roadmap’s axes (Lesson 1.3)
3OMB M-22-09 (2022)The civilian mandatePer-pillar floors: phishing-resistant MFA, encrypt everything, treat every network as hostile
4NIST SP 1800-35 (final 2025)The how19 example builds from 24 collaborators — proof no single product does this
5DoD ZT Strategy (2022) + NSA implementation guidelines (2026)The big rollout152 activities; 91 = “target level” due FY2027; the NSA phases sequence them
6OMB M-26-14 (2026)The logging rulesReplaced the old EL0-EL3 memo entirely — Lesson 5.1 lives here
7EO 14028 (2021) + the 2025 orders around itThe legal spine14028 itself stands unamended; ZT preserved while adjacent mandates were trimmed
8CISA 2026 guides (OT · SASE/TIC 3.0)The expansionsZT extended to operational technology and network modernization — Lessons 3.4 and 3.2
🔍Status detail, as of August 2026 (the volatile layer — verify before citing)

M-22-09’s FY2024 deadlines were not extended by a successor memo; the regime became continuous maturity measured through FISMA metrics and the updated implementation plans agencies filed in fall 2024. There is no “Federal ZT Strategy 2.0”; DoD’s “ZT Strategy 2.0” was announced for early 2026 and remains unpublished. CISA ZTMM is still v2.0 — no v3. EO 14028 stands unamended; the 2025 orders (14144, then 14306) trimmed digital-identity and software-attestation mandates around it while explicitly preserving Zero Trust. M-26-05 (2026) rescinded the attestation/SBOM memos (the forms vendors had to sign about their build practices); BOD 26-04 (2026, a Binding Operational Directive — an order agencies must follow) superseded the KEV-based patching directive (KEV = CISA’s Known Exploited Vulnerabilities list); SP 800-63-4 (2025, the digital-identity standard) recognizes syncable passkeys at AAL2 (Authenticator Assurance Level 2 — the strength most systems require). Every sentence in this box is the kind that rots — which is the point of what comes next.

The real skill: is this memo alive?

The corpus mutates quarterly. Documents get rescinded, superseded, and — most dangerously — cited for years after they die. A real 2026 audit of one organization’s security corpus found the Zero Trust maturity model cited without a version, a governance plan tracking a deadline that had lapsed two years earlier as if it were upcoming, and control narratives split between the current identity standard and its withdrawn predecessor. None of those documents were wrong when written. Citations rot; the skill is checking.

Your artifact — run the currency check:

For each authority cited below, determine with current sources: (1) is it in
force, superseded, or rescinded as of today; (2) if superseded, by what; and
(3) one sentence on what changed. Cite where you verified each. Then rank the
list from most to least likely to have changed again in 12 months.
Authorities: NIST SP 800-207 · CISA ZTMM v2.0 · OMB M-22-09 · OMB M-21-31 ·
NIST SP 800-63B rev 3 · DoD ZT Strategy (2022) · EO 14028 · BOD 22-01

Run it honestly and the trap springs: M-21-31 — the logging memo half the internet still cites — was rescinded and replaced in May 2026 (its EL0-EL3 tiers no longer exist), 800-63B rev 3 was withdrawn for rev 4, and BOD 22-01 was folded into a successor directive. Three of the eight are dead. If your AI CLI reported all eight as current, it answered from stale training data — which is its own lesson: the currency check requires live sources, and “the model said so” is not a citation.

Make the check a standing habit: it runs at program start, before every audit response, and quarterly — it costs minutes and it is the difference between a roadmap graded against the real rules and one graded against 2022.

KNOWLEDGE CHECK

A consultant's 2025-vintage Zero Trust assessment template requires your logging program to demonstrate 'EL2 maturity per M-21-31.' It's August 2026. What is the correct response?

Practice status — among mature regulated delivery programs, commercial and federal

(a few rows carry a more specific status - principle, canon, suspended - where one of the five would mislead)

PracticeStatusAlso called
binding memos and directives (M-26-14, BODs)required (agencies) applicability depends on the memo; check each—
ZTMM, NSA guidance, DoD strategyadvisory guidance binds nobody outright (DoD strategy governs DoD components); a free blueprint for everyone else—
applicability registerstrong optionalrequirements / regulatory-change register
AI-CLI currency check against live sourcesemerging the model drafts; the source verifies—
commercial map (CSF 2.0, ISO 27001, insurer questionnaire)common baseline what commercial estates are actually graded against—

Scale: required | common baseline | strong optional | reference-shop (seen only at organizations that publish their own practice) | emerging

Key takeaway

Eight documents form the map: the architecture (800-207), the measuring stick (ZTMM), the mandates (M-22-09, M-26-14, the EO spine), the how (SP 1800-35, NSA guidelines), and the expansions (OT, SASE). Hold the map loosely and the checking skill tightly — a citation is only as good as its last verification: the currency-check list above found three of its eight one-time authorities dead in the last eighteen months, and this map’s eight only stay current because someone keeps checking. Next: turning the map into a program that survives contact with your org chart.

LEADERSHIP DECISION fund a maintained applicability register (owner, status,
last-checked) over a one-time compliance mapping
PRACTITIONER ACTION run the currency check at program start, before every
audit response, and quarterly; keep the register in the
repo
SUCCESS MEASURE zero roadmap items graded against a rescinded source; a
stale citation found in minutes, not at assessment
Search lessons