M-22-09: The Memo That Made Zero Trust Federal Law

📋 Key Takeaways
  • What happened
  • The five pillars as mandated
  • Impact and numbers
  • Timeline
  • Why it still matters in 2026
7 min read · 1,305 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.

On 26 January 2022, the White House Office of Management and Budget delivered the document that turning zero trust from conference slide-deck fashion into federal law-adjacent mandate: Memorandum M-22-09, “Moving the U.S. Government Toward Zero Trust Cybersecurity Principles.” Building on Executive Order 14028 (May 2021) and the sweeping 2021 zero-trust-adjacent guidance that followed the SolarWinds and Colonial Pipeline shocks, the memo required every federal civilian agency to achieve specific zero-trust goals by the end of fiscal year 2024 — staff identity protection with phishing-resistant MFA, application-level access decisions replacing network-perimeter trust, environment hardening, and dedicated teams with budget. What made M-22-09 historically interesting was less its ambition than its specificity: it named technologies (FIDO2/PIV smart cards over SMS and phone-based 2FA, DNS filtering, email security with DMARC enforcement), set an actual date, tied progress reporting to OMB and CISA oversight, and — by dictating procurement requirements across the world’s largest IT buyer — reshaped vendor roadmaps far beyond government. For the security industry, the memo is the clearest single marker of the paradigm shift’s institutional arrival: assume breach, verify explicitly, never trust network location — not as philosophy but as compliance line-items with deadlines.

Quick Answer
OMB Memorandum M-22-09 (2022-01-26) ordered US federal civilian agencies to implement zero-trust security. Requirements: (1) Phishing-resistant MFA — FIDO2/WebAuthn or PIV — for all agency staff on public-facing and internal systems, explicitly singling out SMS and voice-call factors as inadequate; (2) a dedicated zero-trust strategy and implementation plan per agency, with named senior official ownership, due to OMB/CISA within 60 days; (3) identity-first security including enterprise-managed identity as the new control plane with encrypted DNS and HTTP everywhere; (4) microsegmentation and application-level access policy rather than network-location trust; (5) specific FY2024 end-state goals for identity, devices, networks, applications/workloads, and data, with progress tracked through OMB-led reporting and CISA technical support (including the Cloud Security Technical Reference Architecture co-released alongside). Historical context: it operationalised Executive Order 14028’s zero-trust language and was the federal response to the SolarWinds supply-chain espionage and Colonial Pipeline ransomware era. Market impact: by making the largest IT buyer mandate phishing-resistant MFA and identity-centric architecture with deadlines and reporting teeth, the memo accelerated the entire industry’s move off perimeter-VPN models and SMS 2FA — effects visible in every 2023–2026 product roadmap and in CISA’s own Zero Trust Maturity Model iterations.

What happened

The memo landed as the capstone of a two-year policy cascade. Executive Order 14028 (May 2021) had ordered “advancing toward zero trust architecture” in the abstract; CISA had published its Zero Trust Maturity Model and Cloud Security Technical Reference Architecture in 2021 to give agencies a map; M-22-09 gave the map deadlines. Agencies were told to name accountable senior officials, produce implementation plans within 60 days, and report progress against FY2024 end-states across five pillars: identity, devices, networks, applications and workloads, and data. The requirements spanned the mundane and architectural: centrally-managed identity with phishing-resistant factors, encrypted DNS filtering as default, government-wide email protections (DMARC at enforcement, plus anti-phishing and malware scanning), endpoint inventory with device compliance gating access, application-level proxies replacing implicit network trust, and logs teed to SOC platforms under the government-wide logging baseline.

Enforcement was budgetary and reputational rather than carceral: OMB review of agency plans, quarterly-ish progress reporting, and CISA assistance (including shared-services telemetry). But because federal procurement moves markets — civilian agencies alone spend tens of billions annually on IT — the memo’s technology preferences became de facto product requirements.

The five pillars as mandated

M-22-09 FY2024 end-states (summary):
  IDENTITY
    - enterprise identity as primary
      control plane
    - phishing-resistant MFA (PIV or
      FIDO2/WebAuthn) for staff,
      public-facing systems included
    - SSO consolidated; legacy password
      auth retired where feasible

  DEVICES
    - complete asset inventory
    - device compliance checks gate
      access decisions

  NETWORKS
    - encrypted DNS (DNS-over-HTTPS or
      DNS-over-TLS) agency-wide
    - HTTPS everywhere, unencrypted
      HTTP dropped
    - application-level access in place
      of network-location trust
      (BeyondCorp-style proxies)

  APPLICATIONS & WORKLOADS
    - dedicated app security testing
    - modern protections for code and
      CI/CD pipelines

  DATA
    - automated sensitivity labelling
    - enterprise-wide DLP-style
      protections
    - role-based, need-to-know access
      enforced at data layer
data-hmmnm-seam="2">

Impact and numbers

Metric Value Source
Document OMB Memo M-22-09 whitehouse.gov archive
Signed/published 2022-01-26 OMB record
Authority chain EO 14028 (2021-05) → CISA ZTMM (2021) → M-22-09 public policy record
Scope All US federal civilian agencies memo text
Core deadline FY2024 end-states (Sept 2024) memo text
Plan deadline 60 days from memo (2022) memo text
MFA mandate Phishing-resistant (FIDO2/PIV); SMS/voice excluded memo text
Oversight OMB plan review + CISA support/tracking memo text
data-hmmnm-seam="3">

Timeline

Date Event
2020-12 SolarWinds Orion campaign public — perimeter-era federal security discredited
2021-05 EO 14028 orders zero-trust advancement, logging baselines, incident reporting
2021-06→09 CISA Zero Trust Maturity Model + Cloud Security TRA published
2022-01-26 M-22-09: specific FY2024 zero-trust goals, phishing-resistant MFA mandate
2022→2024 Agency plans, OMB reviews, CISA ZTMM v2 (2023) iterations; FY2024 targets
data-hmmnm-seam="4">

Why it still matters in 2026

Because it worked as a market instrument, and its FY2024 deadlines have quietly become the baseline that private-sector regulation copies. The phishing-resistant-MFA mandate accelerated the FIDO2/passkey transition even for vendors with no federal sales — product teams standardised on the federal requirement rather than maintain two lines. The application-level-access (BeyondCorp-style) architecture the memo normalised is now the default pattern for hybrid work, and the memo’s DNA is visible in subsequent state-level zero-trust requirements, healthcare and financial-sector guidance, and CISA’s cross-sector performance goals. Meanwhile the critiques aged instructively: zero-trust programmes that treated the memo as a checklist (SSO licence procured, box ticked) without decommissioning legacy implicit trust learned that ZT is an ongoing property of access decisions, not a product SKU — a lesson every 2024–2026 maturity assessment repeats. For practitioners, M-22-09 remains the best-written requirements document to hand a CIO who asks “so what does zero trust actually mean we must do?” — five pillars, concrete technologies, dates, and an oversight structure, all in public domain.

data-hmmnm-seam="5">

Implementation lessons for any estate

  • Identity is the control plane. The memo’s core architectural bet: consolidate authentication into enterprise identity with phishing-resistant factors, then hang every other decision off it. Estates that skipped this and bought “zero-trust network” boxes re-created perimeter fragility with new logos.
  • Retire SMS 2FA explicitly. Naming inadequate factors (SMS, voice) in policy forced migrations that voluntary guidance never achieved; the same explicit-exclusion pattern now appears in banking and big-tech standards.
  • Access decisions belong at the application. Network-location trust (VPN + flat internal) was the designated legacy to kill; application-level proxies with per-request identity and device context are the mandated shape.
  • Inventoried, compliant devices or no access. Device posture as an input to every authorization decision is what turns MFA from a login event into a continuous trust evaluation.
  • Deadlines plus named owners plus reporting. The memo’s enforcement genius was administrative simplicity: a date, a name, a report. Private-sector programmes that copy this structure outperform those with architecture-only mandates.

FAQ

Did agencies actually meet the FY2024 goals?

Fully and universally, no — federal reporting through 2024 showed strong progress on phishing-resistant MFA and DNS/HTTPS defaults, with the long tail concentrated in legacy application modernisation and data-labelling automation. The memo anticipated this by structuring goals as end-states with tracked progress rather than binary compliance gates, and successor guidance (and CISA’s maturity-model iterations) keeps the pressure on the stragglers.

Is zero trust a product I can buy?

No — and M-22-09 is the clearest official statement of that. Products serve pillars (identity providers, FIDO2 keys, proxy architectures, DLP), but zero trust is the property that no access decision relies on network location or implicit trust. Agencies that tried to procure it as a SKU produced the checklist-ZT failures the maturity assessments later flagged.

Why does a US federal memo matter outside the US?

Procurement gravity and clarity. The US civilian federal estate is among the world’s largest IT buyers, so its mandated technologies (FIDO2, DMARC enforcement, encrypted DNS, app-level access) became default vendor capabilities worldwide; and because the memo is public and unusually concrete, regulators and enterprises globally adopted its five-pillar framing as their own zero-trust requirement language.

data-hmmnm-seam="end">

Prabhu Kalyan Samal

Application Security Consultant at TCS. Certifications: CompTIA SecurityX, Burp Suite Certified Practitioner, Azure Security Engineer, Azure AI Engineer, Certified Red Team Operator, eWPTX v3, LPT, CompTIA PenTest+, Professional Cloud Security Engineer, SC-900, SC-200, PSPO I, CEH, Oracle Java SE 8, ISP, Six Sigma Green Belt, DELF, AutoCAD. Writing about ethical hacking, security tutorials, and tech education at Hmmnm.