Zero trust did not expire
Newer AI and logging memoranda get the headlines, but M-22-09 and NIST SP 800-207 still structure how agencies talk about identity, devices, networks, applications, and data. Most federal cyber volumes still live or die on those pillars.
Where we see primes need help
- Enterprise IAM and privileged access (PAM) that can survive an evaluator's scenario questions
- Device posture for endpoints and virtual desktops (AVD / Horizon)
- Micro-segmentation and TIC 3.0-aligned patterns
- Cloud security across Azure, GCP, and AWS without inventing a fifth identity plane
Package patterns
Endpoint and Virtual Desktop Security Modernization covers the device pillar. Zero trust, identity, and privileged access work often sits as an advisory retainer or firm-fixed-price architecture package when the solicitation names a cleared senior architect.
The Legate posture
Three senior principals. No junior bench. If the requirement is larger than that, we can bring in cleared seniors we have worked with before—but we will not invent a staffing mill on paper.
