Governance Briefing — OMB issues Federal Zero Trust Strategy (M-22-09)
On 26 January 2022 the White House released OMB Memorandum M-22-09, directing U.S. civilian agencies to adopt zero trust architectures across identity, devices, networks, applications, and data by FY2024.
The Office of Management and Budget published Memorandum M-22-09 on 26 January 2022, setting a government-wide Zero Trust Strategy for U.S. federal civilian agencies. The policy requires agencies to meet specific targets by the end of FY2024 across identity (phishing-resistant MFA), device inventory and compliance, network segmentation, application security, and data tagging and encryption.
Program leaders should map existing modernization and TIC 3.0 efforts to the memorandum’s pillars, prioritize phishing-resistant authentication rollout, and align application and data security plans with the required milestones to secure budget and oversight approval.
- OMB Memorandum M-22-09 outlines zero trust outcomes, deadlines, and reporting expectations for civilian agencies.
- White House fact sheet summarizes the priority actions on identity, endpoints, applications, networks, and data.
Continue in the Governance pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Public-Sector Governance Alignment Playbook — Zeph Tech
Align OMB Circular A-123, GAO Green Book, OMB M-24-10 AI guidance, EU public sector directives, and UK Orange Book with digital accountability, risk management, and service…
-
Third-Party Governance Control Blueprint — Zeph Tech
Deliver OCC, Federal Reserve, PRA, EBA, DORA, MAS, and OSFI third-party governance requirements through board reporting, lifecycle controls, and resilience evidence.
-
Governance, Risk, and Oversight Playbook — Zeph Tech
Operationalise board-level governance, risk oversight, and resilience reporting aligned with Basel Committee principles, ECB supervisory expectations, U.S. SR 21-3, and OCC…




