Insights

Mandate explainers for capture and delivery teams

Short writeups on the authorities that show up in our scopes - PQC timelines, AI governance, logging, visibility, FedRAMP, and zero trust - with links back to work packages.

Topics
AI assuranceATO/FedRAMPPQCVisibilityZero trust
PQC · 2026-09-01

Why the PQC deadline matters for federal programs

Harvest-now-decrypt-later risk, CNSA 2.0 exclusive-use dates, and NSM-10's 2035 goal make crypto-agility a near-term authorization issue—not a distant R&D topic.

AI assurance · 2026-08-20

OMB M-25-21: what high-impact AI actually requires

High-impact determinations, impact assessments, monitoring plans, and human oversight are recurring work—not a one-time checklist.

AI assurance · 2026-08-12

OMB M-25-22 and AI acquisition terms that stick

Data rights, lock-in, and CUI inference constraints belong in architecture—not only in the contract appendix.

Visibility · 2026-07-15

CISA BOD 26-04: risk-based remediation replaces the old KEV reflex

BOD 26-04 consolidates vulnerability remediation guidance and supersedes BOD 19-02 and BOD 22-01—shifting agencies toward risk-based prioritization.

Visibility · 2026-07-01

CISA BOD 23-01 and the asset visibility problem that never stays solved

Automated asset discovery every seven days sounds simple until EDR, CMDB, cloud, and OT inventories disagree.

Visibility · 2026-06-15

OMB M-26-14: logging maturity after M-21-31

M-26-14 rescinds M-21-31 and resets logging and network visibility expectations with maturity milestones into 2027.

ATO/FedRAMP · 2026-05-20

FedRAMP Rev. 5 and the 2027 close for new applications

Rev. 5 transition, key security indicators, and the approaching close for new Rev. 5 applications make readiness sprints time-boxed work.

Zero trust · 2026-04-28

Zero trust after M-22-09: identity, devices, and TIC 3.0 still decide outcomes

Zero trust strategy remains the backbone for IAM/PAM, device posture, segmentation, and secure access—especially when AI and logging mandates accelerate.