Skip to main content
Category: Zero Trust & Network Security

OMB Memorandum M-22-09

Also known as: M-22-09, Federal Zero Trust Strategy, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles
Simply put

OMB Memorandum M-22-09 is a U.S. Office of Management and Budget policy document that directs federal executive agencies to adopt a zero trust approach to cybersecurity. In general terms, zero trust means that no user or device is automatically trusted and that access must be continuously verified rather than assumed based on network location. Because no external evidence was supplied for this entry, the specific requirements, deadlines, and provisions cannot be detailed here without risking inaccuracy.

Formal definition

OMB Memorandum M-22-09 is a directive issued by the U.S. Office of Management and Budget that establishes a federal zero trust architecture strategy for executive branch agencies, commonly associated with the goals set out in prior federal cybersecurity executive action. It typically frames requirements across security pillars such as identity, devices, networks, applications, and data, emphasizing strong authentication, continuous verification, and least-privilege access. Note, however, that this entry was generated without a supporting evidence packet; the precise obligations, target dates, and pillar-level controls stated in the memorandum should be verified against the authoritative published text before being relied upon. A virtual or fractional CISO advising a federal agency or a contractor in its supply chain would generally support readiness and alignment with such a directive at the governance and strategy level, while legal and organizational accountability for compliance remains with the agency or organization and its officers.

Why it matters

OMB Memorandum M-22-09 signals a decisive federal shift away from perimeter-based security models toward a zero trust approach, in which no user or device is automatically trusted and access must be continuously verified rather than assumed based on network location. For federal executive agencies, and by extension the contractors and vendors in their supply chains, this reframes cybersecurity as an ongoing governance and architecture commitment rather than a checklist of point defenses. Because the memorandum is directive in nature for the agencies it covers, understanding its intent matters even for organizations that only interact with the federal ecosystem indirectly.

The broader significance is that a strategy of this kind establishes an expected baseline that tends to influence security thinking well beyond its formal scope. Commercial organizations and state or local entities often look to federal zero trust guidance as a reference model when maturing their own programs, even though they are not legally bound by it. Leaders should be cautious, however: this entry was generated without a supporting evidence packet, so the specific requirements, deadlines, and pillar-level controls attributed to the memorandum should be verified against the authoritative published OMB text before being relied upon for planning or attestation.

A recurring mistake is to treat alignment with a zero trust directive as equivalent to a guarantee of breach prevention, or to assume that adopting the language of zero trust automatically satisfies the underlying obligations. Zero trust is an architecture and governance philosophy that depends on sustained execution across identity, devices, networks, applications, and data. The value of any advisory support in this area depends heavily on organizational maturity, stakeholder cooperation, and a clearly defined scope of work.

Who it's relevant to

Federal executive branch agencies
As the primary audience of the directive, these agencies are expected to move toward a zero trust architecture across their security pillars. Their leadership and officers retain accountability for meeting the memorandum's requirements, and they should consult the authoritative OMB text for exact obligations and deadlines rather than relying on summarized descriptions.
Federal contractors and supply chain vendors
Organizations that provide products or services to federal agencies may be affected indirectly, as agencies extend zero trust expectations to the systems and vendors they rely on. These organizations often benefit from readiness assessments and governance-level planning, while recognizing that specific contractual flow-down obligations must be confirmed against the actual terms they are subject to.
Virtual, fractional, and advisory CISOs
Security leaders engaged by covered agencies or their contractors typically support strategy, governance, risk management, and readiness alignment with zero trust principles. Their role is advisory and directive rather than hands-on operational; they generally do not assume compliance accountability, which remains with the client organization and its officers, unless a contract explicitly states otherwise.
Commercial and non-federal organizations using it as a reference
Private-sector, state, and local entities that are not legally bound by the memorandum sometimes use federal zero trust guidance as a model to inform their own program maturity. For these organizations, the memorandum is a reference point rather than an obligation, and its principles should be adapted to their own risk profile and regulatory environment.

Inside M-22-09

Zero Trust Architecture Mandate
The memorandum directs Federal Civilian Executive Branch agencies to adopt zero trust principles, replacing implicit network-based trust with continuous verification of users, devices, and access requests. It frames zero trust as a strategic direction rather than a single product to purchase.
Identity and Phishing-Resistant MFA
It emphasizes enterprise-wide identity management and the use of phishing-resistant multi-factor authentication for agency staff. This pillar focuses on strong, centralized identity as a foundation for access decisions.
Device Security Focus
The memorandum addresses the need for agencies to maintain reliable inventories of devices and to incorporate device posture into access decisions, so that trust is not granted based on network location alone.
Network Segmentation and Encryption
It calls for encrypting network traffic and moving away from perimeter-based trust models, reflecting the principle that internal network position should not by itself confer access.
Applications and Workloads Security
The memorandum highlights improved application-layer security, including security testing of applications, so that protections apply at the workload level rather than only at the network boundary.
Data Categorization and Access Controls
It directs agencies to improve how they categorize and protect data, applying access controls informed by data sensitivity as part of the zero trust model.
Alignment with Federal Framework and Timeline
The memorandum is anchored to Executive Order 14028 and coordinated with the CISA Zero Trust Maturity Model and NIST guidance, with agencies expected to work toward its goals on a federal timeline. It represents a governance and strategy directive rather than a certifiable standard.

Common questions

Answers to the questions practitioners most commonly ask about M-22-09.

Does OMB Memorandum M-22-09 apply to my private-sector company, and can a virtual CISO make us compliant with it?
M-22-09 is a federal directive that sets a zero trust architecture strategy for U.S. federal civilian executive branch agencies; it does not, by its own terms, impose obligations on private-sector organizations. It is often cited outside government as a reference model for zero trust maturity, but that is a matter of adopting its principles voluntarily rather than being subject to it. A virtual CISO can help translate its concepts into a strategy appropriate to your organization, but where the memorandum does not apply to you, there is no compliance status to be granted or certified against it. For agencies that are in scope, a vCISO typically supports readiness, governance, and program planning aligned to the strategy rather than declaring the agency 'compliant.'
Isn't zero trust under M-22-09 mainly a set of security tools a vCISO or a managed service provider can deploy for us?
This is a common misconception worth correcting. The strategy described in M-22-09 is an architectural and governance approach, not a product you buy or a single tool you install. It spans identity, devices, networks, applications and workloads, and data, and it depends heavily on policy, process, and organizational decisions. A virtual CISO operates at the strategy, governance, and program-direction level and advises on how these pillars fit together and how to prioritize them; a vCISO is not a managed security service provider and generally does not perform hands-on tool administration, monitoring, or configuration unless that work is explicitly and separately contracted. Treating zero trust as purely a technical purchase, rather than a governance and business-risk effort, tends to be where implementations struggle.
How can a virtual CISO help our organization use M-22-09 as a reference for planning a zero trust program?
In many engagements a virtual CISO uses the memorandum's pillars as a structuring lens: assessing current state across identity, devices, networks, applications and workloads, and data, then helping leadership set priorities and a sequenced roadmap. The vCISO typically focuses on strategy, governance, and risk management, defining target outcomes, decision criteria, and how initiatives map to organizational risk. The value of this depends significantly on organizational maturity, access to stakeholders, and a clearly defined engagement scope. The vCISO advises and directs, but the accountability for adopting and funding the resulting decisions remains with the organization and its officers.
Who is accountable for decisions and outcomes when a vCISO advises on a zero trust roadmap informed by M-22-09?
A virtual CISO advises, recommends, and can direct security program activities, but legal and organizational accountability for security decisions generally remains with the client organization and its officers unless a contract specifies otherwise. For a federal agency in scope of the memorandum, the agency retains its own directive obligations; a vCISO supporting that work does not assume those obligations. It is important to define in the engagement agreement what the vCISO is responsible for versus what remains the organization's accountability, so that expectations about direction, sign-off, and funding are clear.
What typically falls outside the scope of a virtual CISO engagement built around zero trust principles?
A virtual CISO generally provides strategy, governance, risk management, program development, and executive-level guidance. Hands-on operational tasks are typically out of scope unless explicitly contracted, including SOC monitoring, day-to-day administration of identity or network tooling, endpoint management, and incident response execution. The vCISO may define requirements, evaluate options, and oversee direction for these areas, but the execution is usually carried out by internal teams, systems integrators, or other providers. Clarifying these boundaries early helps avoid the mistaken assumption that a vCISO replaces an entire security team.
What conditions most affect whether a vCISO engagement referencing M-22-09 delivers meaningful results?
Outcomes tend to depend on organizational maturity, client cooperation, a clearly defined scope, and reliable access to the stakeholders who own identity, infrastructure, applications, and data. A zero trust strategy touches multiple functions, so progress often stalls without executive sponsorship and cross-team participation. Engagement models may vary by provider in terms of time commitment and delivery structure, and a vCISO cannot guarantee specific outcomes such as breach prevention or a defined maturity level. The realistic value is disciplined prioritization, governance, and a roadmap the organization is positioned to execute.

Common misconceptions

M-22-09 is a compliance certification that organizations can pass or fail like SOC 2 or ISO 27001.
It is an OMB policy directive setting strategic goals for Federal Civilian Executive Branch agencies, not a certification regime. Agencies demonstrate progress toward its principles rather than earning a certificate, and a virtual CISO can support readiness and alignment but should not claim an engagement guarantees compliance.
M-22-09 applies broadly to all private companies and requires them to adopt zero trust.
The memorandum is directed at Federal Civilian Executive Branch agencies. Private-sector organizations are not directly bound by it, though contractors and vendors serving affected agencies may encounter related requirements through downstream contractual obligations.
Achieving the goals in M-22-09 means buying a zero trust product that prevents breaches.
Zero trust as described in the memorandum is an architectural strategy spanning identity, devices, networks, applications, and data, not a single tool. It is a governance and risk approach that reduces certain risks but does not guarantee breach prevention, and its value depends heavily on organizational maturity, funding, and sustained execution.

Best practices

Treat M-22-09 as a strategy and governance directive, mapping its identity, device, network, application, and data pillars to your organization's existing controls rather than treating it as a checklist to buy your way through.
Confirm applicability before scoping work: verify whether an organization is a Federal Civilian Executive Branch agency directly bound by the memorandum, or a contractor affected through downstream contractual requirements, and document that distinction.
Prioritize phishing-resistant multi-factor authentication and enterprise identity management early, since strong identity underpins the zero trust access decisions the memorandum emphasizes.
Align efforts with the referenced federal frameworks, including NIST SP 800-207 and the CISA Zero Trust Maturity Model, so that progress is described accurately as readiness and alignment rather than guaranteed compliance or certification.
Clarify accountability in writing: a virtual CISO advising on M-22-09 alignment directs and guides the program, but legal and organizational accountability for security decisions and outcomes remains with the client organization and its officers.
Set expectations that progress toward the memorandum's goals depends on organizational maturity, funding, stakeholder access, and client cooperation, and phase the work accordingly rather than promising fixed timelines or breach prevention.