Mandate explainers for capture and delivery teams
Short writeups on the authorities that show up in our scopes - PQC timelines, AI governance, logging, visibility, FedRAMP, and zero trust - with links back to work packages.
Why the PQC deadline matters for federal programs
Harvest-now-decrypt-later risk, CNSA 2.0 exclusive-use dates, and NSM-10's 2035 goal make crypto-agility a near-term authorization issue—not a distant R&D topic.
OMB M-25-21: what high-impact AI actually requires
High-impact determinations, impact assessments, monitoring plans, and human oversight are recurring work—not a one-time checklist.
OMB M-25-22 and AI acquisition terms that stick
Data rights, lock-in, and CUI inference constraints belong in architecture—not only in the contract appendix.
CISA BOD 26-04: risk-based remediation replaces the old KEV reflex
BOD 26-04 consolidates vulnerability remediation guidance and supersedes BOD 19-02 and BOD 22-01—shifting agencies toward risk-based prioritization.
CISA BOD 23-01 and the asset visibility problem that never stays solved
Automated asset discovery every seven days sounds simple until EDR, CMDB, cloud, and OT inventories disagree.
OMB M-26-14: logging maturity after M-21-31
M-26-14 rescinds M-21-31 and resets logging and network visibility expectations with maturity milestones into 2027.
FedRAMP Rev. 5 and the 2027 close for new applications
Rev. 5 transition, key security indicators, and the approaching close for new Rev. 5 applications make readiness sprints time-boxed work.
Zero trust after M-22-09: identity, devices, and TIC 3.0 still decide outcomes
Zero trust strategy remains the backbone for IAM/PAM, device posture, segmentation, and secure access—especially when AI and logging mandates accelerate.

