OMB Memorandum M-22-09
OMB Memorandum M-22-09 is a U.S. Office of Management and Budget policy document that directs federal executive agencies to adopt a zero trust approach to cybersecurity. In general terms, zero trust means that no user or device is automatically trusted and that access must be continuously verified rather than assumed based on network location. Because no external evidence was supplied for this entry, the specific requirements, deadlines, and provisions cannot be detailed here without risking inaccuracy.
OMB Memorandum M-22-09 is a directive issued by the U.S. Office of Management and Budget that establishes a federal zero trust architecture strategy for executive branch agencies, commonly associated with the goals set out in prior federal cybersecurity executive action. It typically frames requirements across security pillars such as identity, devices, networks, applications, and data, emphasizing strong authentication, continuous verification, and least-privilege access. Note, however, that this entry was generated without a supporting evidence packet; the precise obligations, target dates, and pillar-level controls stated in the memorandum should be verified against the authoritative published text before being relied upon. A virtual or fractional CISO advising a federal agency or a contractor in its supply chain would generally support readiness and alignment with such a directive at the governance and strategy level, while legal and organizational accountability for compliance remains with the agency or organization and its officers.
Why it matters
OMB Memorandum M-22-09 signals a decisive federal shift away from perimeter-based security models toward a zero trust approach, in which no user or device is automatically trusted and access must be continuously verified rather than assumed based on network location. For federal executive agencies, and by extension the contractors and vendors in their supply chains, this reframes cybersecurity as an ongoing governance and architecture commitment rather than a checklist of point defenses. Because the memorandum is directive in nature for the agencies it covers, understanding its intent matters even for organizations that only interact with the federal ecosystem indirectly.
The broader significance is that a strategy of this kind establishes an expected baseline that tends to influence security thinking well beyond its formal scope. Commercial organizations and state or local entities often look to federal zero trust guidance as a reference model when maturing their own programs, even though they are not legally bound by it. Leaders should be cautious, however: this entry was generated without a supporting evidence packet, so the specific requirements, deadlines, and pillar-level controls attributed to the memorandum should be verified against the authoritative published OMB text before being relied upon for planning or attestation.
A recurring mistake is to treat alignment with a zero trust directive as equivalent to a guarantee of breach prevention, or to assume that adopting the language of zero trust automatically satisfies the underlying obligations. Zero trust is an architecture and governance philosophy that depends on sustained execution across identity, devices, networks, applications, and data. The value of any advisory support in this area depends heavily on organizational maturity, stakeholder cooperation, and a clearly defined scope of work.
Who it's relevant to
Inside M-22-09
Common questions
Answers to the questions practitioners most commonly ask about M-22-09.