Zero trust · 2026-04-28

Zero trust after M-22-09: identity, devices, and TIC 3.0 still decide outcomes

Zero trust strategy remains the backbone for IAM/PAM, device posture, segmentation, and secure access—especially when AI and logging mandates accelerate.

Zero trust did not expire

Newer AI and logging memoranda get the headlines, but M-22-09 and NIST SP 800-207 still structure how agencies talk about identity, devices, networks, applications, and data. Most federal cyber volumes still live or die on those pillars.

Where we see primes need help

  • Enterprise IAM and privileged access (PAM) that can survive an evaluator's scenario questions
  • Device posture for endpoints and virtual desktops (AVD / Horizon)
  • Micro-segmentation and TIC 3.0-aligned patterns
  • Cloud security across Azure, GCP, and AWS without inventing a fifth identity plane

Package patterns

Endpoint and Virtual Desktop Security Modernization covers the device pillar. Zero trust, identity, and privileged access work often sits as an advisory retainer or firm-fixed-price architecture package when the solicitation names a cleared senior architect.

The Legate posture

Three senior principals. No junior bench. If the requirement is larger than that, we can bring in cleared seniors we have worked with before—but we will not invent a staffing mill on paper.

Related work package

Need this mapped into a scoped subcontract?

We usually price by work package after a short no-cost scoping call.

Experience described reflects work performed by Legate Solutions principals while employed by other organizations. It is provided to show individual qualifications and is not represented as corporate past performance of Legate Solutions LLC or as an endorsement by any agency named. Corporate past performance and references are available where applicable; where no relevant corporate record exists, Legate requests evaluation consistent with FAR 15.305(a)(2)(iv).