A CISO reviewing a Zero Trust roadmap must separate legal requirements, OMB policy targets, and CISA maturity recommendations.
Each category affects funding, ownership, contracts, and audit evidence.
EO 14028 remains the strategic federal directive. OMB M-22-09 sets measurable outcomes for civilian agencies across identity, devices, networks, workloads, and data.
EO 14028 sets direction; OMB M-22-09 sets targets
EO 14028 directs the federal shift toward Zero Trust Architecture. OMB M-22-09 turns that direction into policy, deadlines, reporting expectations, and accountable outcomes.
Section 3 directs agencies toward Zero Trust Architecture and secure cloud services. It is not a full technical checklist.
It does not require one vendor, access model, or network design. Instead, it replaces implied network trust with explicit access decisions that undergo continuous review.
Agencies should treat the order as strategic direction. That direction flows through OMB policy, agency strategies, and implementation plans.
OMB M-22-09 was issued in January 2022. It established FY2024 objectives across five pillars: identity, devices, networks, applications and workloads, and data.
Expired target dates do not end the duty to assess coverage. Agencies must document exceptions, maintain corrective actions, and identify accountable owners.
Status determination: EO 14028 remains in force unless later executive action expressly revokes or supersedes the relevant provision. Confirm its legal status through
The White House and the Federal Register. Do not rely on assumptions about an administration change.
Federal agencies should measure Zero Trust through enforced policy and repeatable evidence. Licenses, product inventories, and approved diagrams do not prove control operation.
Build the four-document traceability chain
A traceability matrix should link each technical control to its policy source, owner, scope, evidence source, exception process, and remediation plan.
This prevents teams from calling CISA guidance a direct legal mandate. It also prevents broad executive direction from becoming a configuration standard.
The matrix gives auditors a defensible path from strategic direction to tested controls and operating evidence. This link must remain current as systems and policies change.
| Source | Primary function | Best audit evidence |
| EO 14028, Section 3 | Strategic federal Zero Trust direction | Agency strategy and executive governance record |
| OMB M-22-09 | Civilian-agency policy and target outcomes | Objective mapping, assessment results, corrective plans |
| Federal Zero Trust Strategy | Required target state by pillar | Control coverage and exception register |
| CISA Maturity Model | Capability and maturity guidance | Maturity scoring, telemetry, improvement plan |
Retain evidence that proves enforcement
Identity evidence should show phishing-resistant authentication coverage, conditional access rules, privileged-access reviews, dormant-account removal, and sign-in risk logs.
Device evidence should show inventory completeness, encryption, endpoint detection and response health, patch status, and blocks on noncompliant endpoints.
Network, workload, and data evidence should show segmentation, secure delivery gates, workload identities, cloud findings, classification, encryption, and access logs.
Screenshots support claims, but policy exports and machine-generated logs prove controls operate.
EO 14028 also links prevention to a more consistent federal response during vulnerabilities or incidents. Agencies need a repeatable process for vulnerability reports, severity checks, containment, log preservation, notifications, and remediation tracking.
CISA's incident-response role and federal playbooks reduce variation that can delay cross-agency action during a major event.
In practice, audit evidence should link a risky sign-in to the policy decision that restricted access. It should also link the event to its incident record and remediation owner.
The same evidence should show any corrective action plan left open after containment.
Map the five CISA pillars to enforced controls
The five CISA pillars make Zero Trust testable. Each control domain needs an enforcement point, telemetry source, owner, and exception process.
Identity and device decisions must connect
Identity, Credential, and Access Management should enforce least privilege, role governance, privileged access management, and continuous authentication and authorization.
MFA is a baseline. Phishing-resistant authentication is stronger for privileged users and high-value systems.
Device posture must affect access decisions. Managed endpoints with active EDR, encryption, supported software, and current patches should receive different access than unmanaged devices.
Agencies must inventory human and nonhuman identities separately. Each service account needs an owner, rotation method, permitted scope, and retirement date.
The most frequent error is treating identity and device controls as separate projects. A valid identity on an unmanaged endpoint must not receive the same access.
Networks, workloads, and data need policy
Network Zero Trust replaces broad internal trust with application-aware access, microsegmentation, and inspection based on workload and user context.
Applications and workloads need workload identity, secure software development, vulnerability remediation, secrets management, and cloud monitoring.
Data controls need classification, encryption in transit and at rest, access policy, loss prevention, and logs for sensitive repositories.
NIST SP 800-207 protects resources rather than network segments. That principle applies to cloud, SaaS, and on-premises systems.
Zero Trust evidence flow
Identity
Authenticate
→
Device
Check posture
→
Policy engine
Authorize
→
Resource
Log access
Evidence must show both the decision and the resulting access path.
Zero Trust work should also connect to EO 14028 Section 4. That section addresses software supply-chain security.
The order directed NIST to publish secure software development guidance. This guidance appears in the NIST Secure Software Development Framework, SP 800-218.
Agencies and suppliers should treat software provenance, code review, dependency management, vulnerability handling, build protection, and release integrity as security controls.
They are not merely procurement paperwork.
A workload security program is stronger when deployment pipelines show approved component versions. The pipelines should also show vulnerability assessment, exception approval, and replacement speed for vulnerable components.
Start with live telemetry, not architecture slides. Map each pillar to enforced controls, named owners, and retained evidence.
That method applies directly to civilian agencies under OMB M-22-09. Contractors need it when contract terms or agency requirements impose federal controls. Private firms should first map their own legal duties, including PCI DSS, HIPAA, GLBA, SEC rules, GDPR, or customer terms. The federal model remains useful, but it is not an automatic private-sector mandate.
MFA is not zero trust or perimeter security
MFA verifies an authentication factor. Zero Trust evaluates whether a specific request should reach a resource under current conditions.
Compare the three security approaches
| Approach | Decision point | Required evidence |
| Perimeter-based access | Network entry or VPN connection | Firewall and VPN logs |
| MFA-centered access | User authentication event | Enrollment and authentication logs |
| Zero Trust access | Each resource request and session change | Identity, device, policy, workload, and data telemetry |
MFA alone fails when a valid user authenticates from a compromised device. It also fails when users access overprivileged applications or sensitive data through flat internal networks.
Measure progress through enforcement rates. Track privileged accounts with phishing-resistant MFA, healthy managed endpoints, and applications behind context-aware access.
Also measure the time needed to revoke access after compromise.
EO 14028 and OMB M-22-09 do not directly bind every private company or contractor. They apply directly chiefly to Federal Civilian Executive Branch agencies. Contractors must review contract clauses, agency security requirements, FedRAMP duties, and data-handling terms. Banks and private organizations should prioritize PCI DSS, HIPAA, GLBA, SEC rules, GDPR, and customer commitments. The federal strategy is a useful reference framework, not an automatic legal mandate.
Questions & answers
Is executive order 14028 still in effect?
Yes. EO 14028 remains effective unless a later executive order expressly revokes or supersedes a relevant provision.
Agencies should check official White House and Federal Register records before reaching a legal conclusion.
Does OMB M-22-09 apply to contractors?
Not automatically. A contractor is bound when its contract, agency terms, system role, or data duties include federal security requirements.
Those requirements can differ across programs and agencies.
What are the five CISA zero trust pillars?
The five pillars are identity, devices, networks, applications and workloads, and data. CISA also names visibility and analytics, automation and orchestration, and governance as cross-pillar functions.
Is MFA enough for EO 14028 compliance?
No. MFA supports identity assurance, but Zero Trust also needs context-aware authorization, device posture checks, workload protections, and data controls.
Agencies also need evidence that policies operate across the relevant environment.
Start with an auditable gap decision
Determine whether OMB M-22-09 directly applies to your organization. Also determine whether contracts impose federal requirements or whether you use the approach as a reference.
Then build traceability and test each pillar against live telemetry. Assign every unsupported exception to a remediation owner.
An auditable gap decision turns federal direction into accountable control work.
Related sources
These articles can help you explore the topic in more depth: