The Office of Management and Budget issued Memorandum M-24-10 directing federal civilian agencies to implement zero trust architecture. The memorandum establishes binding requirements across five security pillars, assigns specific deadlines, and creates obligations that extend to contractors and third parties that connect to federal systems or process federal data. Leadership in organizations serving federal agencies now faces accountability for security outcomes that require coordinated ownership across technology, compliance, legal and executive functions.
The Direct Answer
OMB M-24-10 is a federal directive that requires civilian agencies to adopt zero trust architecture—a security model that treats every access request as untrusted until verified, regardless of whether it originates inside or outside the network perimeter. The memorandum specifies implementation requirements across five pillars: identity, devices, networks, applications and data. While the directive is binding only on federal civilian executive branch agencies, its practical effect reaches any organization that connects to federal systems, processes federal data, or provides services to covered agencies.
The requirements are not recommendations. They create enforceable obligations with specified deadlines. Organizations that fail to meet these requirements risk losing access to federal systems, contract modifications, or disqualification from future procurements.
Why This Matters to the Business
Federal procurement represents a substantial portion of revenue for many organizations. OMB M-24-10 changes the baseline security posture required to maintain that business relationship. The consequences are commercial, not merely technical.
Agencies are directed to verify that contractors and service providers meet zero trust requirements before granting system access or handling federal data. This verification is not a one-time exercise. The memorandum establishes continuous monitoring obligations. An organization that cannot demonstrate compliance faces immediate operational disruption: loss of system connectivity, inability to perform contracted work, and potential breach of contract claims.
The timeline creates urgency. The memorandum sets phased deadlines beginning in fiscal year 2024 and extending through fiscal year 2027. Organizations that delay implementation will find themselves caught between contractual delivery obligations and security requirements they cannot yet meet. This is not a scenario where noncompliance can be quietly managed. Federal agencies are required to report implementation progress to OMB. Contractor compliance status becomes part of that reporting chain.
The Five Pillars and What They Require
Zero trust architecture as defined in OMB M-24-10 is structured around five interdependent pillars. Each pillar addresses a distinct category of security control, but implementation requires coordination across all five. Organizations cannot achieve compliance by addressing pillars in isolation.
Identity
The identity pillar requires that agencies authenticate and authorize users before granting access to any resource. This means implementing multi-factor authentication for all users, including privileged accounts and non-person entities such as service accounts. Agencies must verify identity continuously, not merely at initial login. The memorandum requires phishing-resistant authentication methods, which eliminates SMS-based codes and certain push notification systems that remain vulnerable to social engineering attacks.
For contractors, this creates a direct obligation to support the authentication methods agencies specify. Organizations that rely on legacy authentication systems or that have not deployed enterprise identity management will need to make substantial changes to their authentication infrastructure. This is not a configuration adjustment. It requires capital investment, vendor selection, integration work and user retraining.
Devices
The device pillar requires that agencies inventory all hardware that connects to federal systems and assess the security posture of each device before granting access. Devices must be managed by the organization, updated with current security patches, and configured according to specified security baselines. Agencies are directed to deny access to devices that do not meet these requirements, regardless of who owns the device or where the access attempt originates.
Contractors must ensure that any device used to access federal systems or process federal data meets the agency's security requirements. This affects remote work policies, bring-your-own-device programs, and the use of subcontractors who may operate their own device fleets. Organizations that have not maintained complete device inventories or that lack automated patch management will need to implement these capabilities before they can demonstrate compliance.
Networks
The network pillar eliminates the concept of a trusted internal network. Agencies must encrypt all DNS requests and HTTP traffic. They must segment networks to limit lateral movement following a breach. The memorandum requires that agencies treat all network traffic as potentially hostile, applying access controls and monitoring at every connection point rather than relying on perimeter defenses.
For contractors, this changes the architecture of connectivity to federal systems. VPN access is no longer sufficient. Organizations must implement application-level access controls, encrypt traffic end-to-end, and provide detailed logging of all network activity. This has implications for network design, cloud service configuration, and the selection of connectivity providers.
Applications and Workloads
The application pillar requires agencies to treat applications as untrusted until verified. This means implementing application-level access controls that verify both user identity and device security posture before granting access. Agencies must maintain inventories of all applications and assess the security of each application continuously. The memorandum directs agencies to migrate applications to cloud environments that support zero trust principles, which creates pressure on contractors to modernize legacy applications that cannot operate in these environments.
Contractors that develop or maintain applications for federal agencies will face requirements to implement specific security controls within those applications. This includes support for modern authentication protocols, detailed logging of user actions, and the ability to enforce granular access policies. Applications that were architected for traditional network perimeter security will require substantial re-engineering.
Data
The data pillar requires agencies to categorize data based on sensitivity, apply appropriate protections to each category, and monitor data access continuously. Agencies must encrypt data at rest and in transit. They must implement access controls that are based on data classification rather than user role or network location. The memorandum requires automated detection of unauthorized data access or exfiltration.
For contractors, this creates obligations around data handling, storage and transmission. Organizations must implement data classification systems, apply encryption appropriately, and maintain detailed logs of who accessed what data and when. This affects database architecture, file storage systems, backup procedures, and incident response capabilities. Contractors that store federal data in multi-tenant environments will need to demonstrate that data segregation and access controls meet zero trust requirements.
Implementation Deadlines and Phased Requirements
OMB M-24-10 establishes a phased implementation timeline with specific milestones beginning in fiscal year 2024. Agencies are required to submit implementation plans, achieve initial capability targets, and report progress at regular intervals. While the specific dates apply directly to federal agencies, contractors face derivative deadlines based on contract terms, system access requirements, and agency-specific implementation schedules.
The practical effect is that contractors cannot wait for agencies to specify requirements. By the time an agency issues a formal directive to contractors, the deadline for compliance will be near. Organizations that begin implementation now will have time to make necessary changes deliberately. Organizations that wait for explicit notification will be forced into rapid, costly remediation work under time pressure.
The Relationship to Cloud Security Architecture
Zero trust architecture and cloud security are not separate initiatives. OMB M-24-10 explicitly directs agencies to leverage cloud environments that support zero trust principles. This reflects a recognition that traditional on-premises infrastructure was not designed for zero trust and cannot easily be retrofitted to meet these requirements.
Organizations that have already implemented modern [cloud security architecture and governance](/vciso/) will find that many zero trust requirements align with cloud-native security controls. Identity federation, API-based access controls, encryption in transit and at rest, and detailed audit logging are standard capabilities in mature cloud environments. Organizations that have not yet migrated to cloud infrastructure or that operate hybrid environments will need to address both cloud migration and zero trust implementation simultaneously.
This creates a strategic decision point. Leadership must determine whether to implement zero trust controls in existing on-premises infrastructure, accelerate cloud migration, or pursue a hybrid approach. Each path has different cost structures, timelines and risk profiles. The decision requires coordination between IT leadership, security leadership, procurement, legal and executive management. It is not a decision that can be delegated solely to technical staff.
Who Is Accountable and What Ownership Looks Like
OMB M-24-10 creates accountability for a security outcome that spans multiple organizational functions. No single role typically owns all five pillars of zero trust architecture. This is where many organizations encounter their most significant obstacle. The technical work can be planned and executed. The governance gap is harder to close.
The Chief Information Officer or Chief Technology Officer typically owns network architecture, device management and application infrastructure. The Chief Information Security Officer owns security policy, access controls and monitoring. The Chief Compliance Officer owns regulatory obligations and reporting. General counsel owns contract terms and liability exposure. Each function has legitimate ownership of part of the requirement, but no one owns the complete outcome.
Adequate ownership requires executive-level coordination across these functions. Someone must have authority to make risk decisions, allocate resources, resolve conflicts between competing requirements, and report progress to the board or chief executive. This is not a project management role. It is a governance role that sits at the intersection of technology strategy, regulatory compliance, commercial risk and operational delivery.
Organizations that lack this executive ownership will experience predictable failures: delayed decisions while stakeholders negotiate scope, duplicated effort as functions work independently, conflicting implementations that create new security gaps, and inability to demonstrate compliance because no one owns the complete picture. These are not hypothetical risks. They are the documented pattern of failure in complex security implementations.
The Strategic Role of Virtual CISO Leadership
The gap between technical implementation and governance accountability is where [virtual CISO (vCISO) leadership](/vciso/) creates measurable value. A vCISO provides executive-level security ownership without the overhead of a full-time C-suite appointment. This is particularly relevant for organizations where federal contracts represent important but not dominant revenue, or where the organization has strong technical capabilities but lacks security governance experience.
Virtual CISO leadership addresses the OMB M-24-10 implementation challenge through four specific functions. First, it establishes clear accountability for the security outcome. The vCISO owns the implementation plan, risk decisions, and progress reporting. Second, it provides the regulatory expertise required to interpret the memorandum, map requirements to existing controls, and identify gaps that must be closed. Third, it coordinates across organizational functions to ensure that technical implementation, compliance obligations and commercial objectives remain aligned. Fourth, it creates the reporting structure that leadership needs to understand status, make informed decisions, and demonstrate compliance to federal agency customers.
This is not a consulting engagement that delivers a report. It is ongoing executive ownership that operates at the same level as the CIO, CFO and general counsel. The vCISO participates in leadership meetings, owns risk decisions, reports to the board or chief executive, and is accountable for the outcome.
Practical Next Steps for Leadership
Leadership facing OMB M-24-10 requirements should take the following steps immediately:
- Inventory all federal contracts, subcontracts and system connections to identify which relationships create zero trust obligations. Include contracts where the organization processes federal data even if it does not connect directly to federal systems.
- Review contract terms to identify existing security requirements, compliance deadlines, and provisions that allow agencies to modify security standards. Determine whether current contracts give agencies authority to impose OMB M-24-10 requirements without formal amendments.
- Assess current security controls against the five zero trust pillars to identify gaps. This assessment should be conducted by someone with expertise in zero trust architecture and federal compliance requirements, not merely someone familiar with the organization's existing security posture.
- Assign clear ownership for zero trust implementation at the executive level. Identify who will make risk decisions, allocate budget, resolve conflicts between functions, and report progress to leadership. If no existing role has the authority and expertise to own this outcome, acknowledge that gap explicitly.
- Develop an implementation plan that addresses all five pillars, specifies deadlines aligned with contract obligations and agency schedules, identifies required investments, and establishes measurable milestones. The plan should be reviewed and approved by executive leadership, not merely by IT or security management.
- Establish a governance structure that brings together IT, security, compliance, legal and business leadership at regular intervals to review progress, make decisions, and address obstacles. This is not a technical working group. It is an executive governance body.
Organizations that lack the internal expertise to conduct the gap assessment, develop the implementation plan, or provide ongoing governance should consider engaging external leadership rather than attempting to build these capabilities while simultaneously executing implementation. The timeline does not allow for learning by trial.
Heights Consulting Group provides virtual CISO leadership that addresses this specific challenge. If your organization serves federal civilian agencies, processes federal data, or connects to federal systems, and you need executive-level ownership of the OMB M-24-10 implementation, a confidential consultation can clarify whether vCISO leadership is the appropriate solution for your circumstances. Contact Heights to discuss your specific situation and determine the most effective path forward.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Cloud Security Architecture and Governance
Design and governance for cloud environments: what the provider secures, what remains yours, and how you keep track of a platform that changes underneath you.