Government Technology Review
Government ITLong read

Public Sector Zero Trust Security Contracts and Opportunities

Federal agencies are locked into a decade-long zero trust procurement cycle.

Features Editor · · 11 min read
Cover illustration for “Public Sector Zero Trust Security Contracts and Opportunities”
Government IT · September 2, 2026 · 11 min read · 2,488 words

The zero trust security market hit $42.28 billion in 2025, according to Fortune Business Insights, and the Government & Defense segment is projected to grow at 18.2% a year. That gap tells the whole story: commercial companies adopt zero trust because it fits their risk posture, while federal agencies adopt it because Washington put a deadline on it and attached congressional reporting to any delay. This piece traces how that mandate turned into a buying pattern, which contract vehicles carry the money, and where the real gaps sit for vendors paying attention. The most common mistake in this market is pitching zero trust as a single sale instead of a decade-long procurement relationship, and that mistake is going to keep costing people money for years.

The federal mandates that turned zero trust from a framework into a compliance requirement

Executive Order 14028, signed in 2021, is where this starts. It told every federal agency to adopt zero trust as part of a wider cybersecurity push, worded specifically enough that "we'll get to it eventually" stopped being an option. OMB Memorandum M-22-09 followed with the actual roadmap: a defined architecture target and a deadline, FY2024 initially, though that date has since stretched.

It kept stretching. M-24-14, issued in July 2024, and M-25-04, from January 2025, both tell agencies to keep maturing their zero trust architectures well past that original finish line. FISMA and Continuous Diagnostics and Mitigation reporting now track agency progress against the M-22-09 goals directly, so this gets graded every year, not checked once and filed away. A January 2025 executive order added another layer, framing zero trust around defending digital infrastructure against nation-state threats, which pushed the conversation from IT hygiene into something closer to national security politics.

DoD runs its own, tougher track. The Department's 2022 Zero Trust Strategy lays out seven pillars and 45 mapped capabilities, tied to a two-phase deadline: Target Level by FY2027, Advanced Level by FY2032. A Portfolio Management Office stood up in January 2022 to run the effort, and more than 40 DoD components have already filed implementation plans that get reviewed every quarter and reported to Congress. NSA's January 2026 Zero Trust Implementation Guidelines push the mandate further, extending it to the Defense Industrial Base and its contractors.

Here's the part vendors keep getting wrong: this isn't a sale with an end date. Compliance is a moving target through at least FY2032, which means agencies stay in procurement mode for the better part of a decade. Show up once, close a deal, and vanish, and the follow-on work goes to whoever stuck around and kept reading the memos instead.

Diagram: DoD Zero Trust Compliance Timeline: Target to Advanced. Visualizes: Show the DoD zero trust mandate as a linear timeline anchored to real milestones and deadlines.

How DoD's zero trust spending is structured and what the FY25 budget reveals about priorities

The Pentagon asked for $14.5 billion in cyber spending for FY25, with $977 million tagged specifically for zero trust. Treat that number as a floor, not a ceiling. DoD splits implementation into three lanes: assessing existing environments, using cloud services, and deploying purpose-built on-premises systems. Zero trust dollars buried inside broader IT modernization or cloud contracts never show up under that line item, so the real spend runs higher than the memo suggests.

The cloud lane is where the near-term action sits, and the Joint Warfighting Cloud Capability contract is the main delivery mechanism for it across DoD components (more on that below). Pitch a generic "zero trust solution" without naming which of the three lanes it fits, and a task order officer working through a stack of proposals against a specific budget line just moves on to the next one. Name the lane directly. Say "this is an on-premises deployment capability" or "this is a cloud services capability," and the conversation moves forward instead of stalling. Vagueness reads as a vendor who skipped the homework, and in this market that's often disqualifying before the pricing page even opens.

The contract vehicles that govern how agencies actually buy zero trust solutions

Zero trust architecture gets bought piecemeal, through vehicles originally built for broader IT and cloud services. Knowing the vehicle matters as much as knowing the technology, and this is the section most vendors skip because it feels like paperwork instead of strategy. That's backwards, because the paperwork is the strategy.

For civilian agencies, GSA's Enterprise Infrastructure Solutions contract is the main channel for ZTA components. GSA updated its ZTA Technology Book in March 2025, mapping NIST framework pieces to the solutions actually sold on EIS, and that book works as a practical reference for structuring an offering around what agencies can actually buy. The GSA Multiple Award Schedule is the broader on-ramp: pre-negotiated pricing and terms cut the friction of a full and open competition, and landing a MAS contract is often the first real step into this market. VirnetX picked one up in October 2025, a recent, concrete example of how a cybersecurity vendor gains that access.

On the defense side, JWCC is the vehicle that matters right now. It carries a $9 billion ceiling, current awardees are Amazon Web Services, Google, Microsoft, and Oracle, and roughly $3 billion in task orders have gone out since the original November 2021 award. The Army made JWCC use mandatory for new cloud buys, marking the vehicle's shift from optional tool to baseline requirement inside DoD.

Behind it sits JWCC Next: a solicitation expected in the second quarter of FY2026, awards by early 2027, and an expected expansion to more hyperscale and non-hyperscale cloud providers, with zero trust built into the requirement from day one. For any vendor building cloud-adjacent zero trust capability, JWCC Next is probably the single biggest opportunity on the horizon. Waiting for the solicitation to drop before positioning is a bad bet against everyone who's already aligning schedule language to it now. GSA's ZTA buyer's guides map framework requirements to available contract vehicles, so matching that language before an RFP lands beats scrambling to match it after the fact.

Diagram: Federal Zero Trust Contract Vehicle Map by Buyer Type. Visualizes: Show the three primary procurement lanes as a ranked or tiered structure: (1) Civilian agencies — GSA EIS (ZTA Technology Book updated March 2025) and GSA Multiple Award…

What recent contract awards reveal about how agencies are scoping and funding zero trust work

Recent awards show the shape of this market better than any spending projection can. GDIT won a $120 million contract with the U.S. Air Force in January 2026 to build an AI-enabled, data-centric zero trust platform serving more than 1 million users across 187 Air Force bases, awarded under the Next Generation Gateway program at Hanscom AFB. GDIT built it around its own Everest Zero Trust Digital Accelerator, which reflects how the largest integrators tend to package this work: as a platform wrapped around existing capability, tailored to whatever the award requires.

The bigger example follows the same pattern. GDIT's $1.5 billion award from U.S. Strategic Command in September 2025 folded zero trust platforms into a broader enterprise IT modernization contract. Zero trust, increasingly, rides inside something larger rather than standing as its own line item, and that changes the pitch.

Move down market and the picture shifts. ASRC Federal won a $16.65 million contract with USCIS in November 2024, scoped specifically to zero trust implementation work for the agency. That's a mid-market civilian agency award built around a maturity-model milestone rather than an open-ended modernization effort. Smaller, specialized vendors get into defense work through narrow, capability-specific awards, not massive omnibus contracts.

The tiering here is fairly clean, and vendors who misjudge which tier they belong in waste a year chasing the wrong bid. Large integrators like GDIT capture the billion-dollar modernization work, mid-tier contractors with ZTMM alignment win civilian agency awards in the ASRC/USCIS range, and specialized vendors get in through narrow DoD components with a well-defined capability, nothing more. Anyone without prime contractor status should figure out which tier actually fits and go find a teaming partner instead of burning a proposal cycle competing for the biggest prize on the board.

The CISA Zero Trust Maturity Model as the shared compliance language across civilian agencies

CISA's Zero Trust Maturity Model organizes the civilian effort around five pillars: Identity, Devices, Networks, Applications and Workloads, and Data, along with cross-cutting capabilities layered across all of them. Each pillar climbs through defined maturity stages, and getting from the bottom to the top of even one pillar is a multi-year program. Nobody finishes this in a quarter, and anyone who tells an agency otherwise is either new to the space or hoping the agency doesn't ask follow-up questions.

The Federal Zero Trust Data Security Guide, revised in May 2025, was written by 70 people from more than 30 federal agencies, and that breadth of authorship carries real weight on its own. The ASRC/USCIS contract mentioned above named the maturity model directly, with its scope calling out "achieving and maintaining maturity across the five pillars." The maturity model shows up verbatim in statements of work now, which means a vendor who maps proposal language to a specific pillar and a specific maturity stage has a real edge over anyone still pitching zero trust as a concept rather than a checklist.

DoD runs a parallel but separate framework, its seven pillars and 45 capabilities, and the two models don't map onto each other cleanly. A vendor working both civilian and defense contracts needs fluency in both vocabularies; use DoD's framework language in a civilian proposal, or the reverse, and the mismatch is immediately obvious to whoever's grading the submission.

Where implementation is breaking down and what that means for vendors positioning their solutions

Federal assessments of civilian agency progress offer the clearest window into where agencies are actually struggling, since they reflect on-the-ground implementation experience rather than vendor claims or marketing surveys. The Data pillar is widely identified as a significant challenge area, where agencies tend to lag behind more mature pillars like identity and network segmentation. There are simply fewer commercial products built for this pillar than for identity or network segmentation, where the market has been building tools for years.

That's the section every vendor should read twice, because it's an admission from the government itself about where the shelf is bare. That gap is a direct signal for data-centric vendors working in a lane far less crowded than the one everyone's piling into for identity management. Separately, agencies moving from legacy, on-premises architecture into hybrid or cloud-native environments face real transition complexity. An agency running twenty-year-old infrastructure needs a transition path more than a clean cloud-first purchase order, and that need already shows up in procurement language.

That's a practical filter for where to put resources. Agencies with Data pillar pain are more likely to issue RFPs asking specifically for classification, tagging, and governance capability. A vendor who can show maturity-stage progress in that pillar, while also supporting a legacy-to-cloud migration path instead of assuming a clean-slate environment, is answering a documented gap instead of adding another name to the identity and access management pile. That's the bet worth making, rather than chasing identity work that a dozen other vendors are already fighting over.

How state, local, and education agencies are entering the zero trust market and where their spending differs from federal

SLED agencies (state, local, and education) don't fall under EO 14028 or OMB M-22-09; nothing forces them to adopt zero trust the way it forces a federal agency. Plenty are doing it anyway, pushed along by state-level cybersecurity executive orders, CISA advisories, and conditions attached to federal grant money that make zero trust adoption a prerequisite for the check.

GSA MAS contracts extend to state and local governments in many cases, so a vendor already holding a MAS schedule can reach SLED buyers without chasing a separate procurement vehicle in every statehouse. The funding itself looks different too, since SLED zero trust spending tends to trace back to federal grant programs and state budget cycles, rather than the annual appropriations tied to DoD directives or OMB memos. Individual SLED contracts run smaller, closer in scale to ASRC/USCIS's $16.65 million than to GDIT's $1.5 billion Strategic Command deal, but there are far more of them, scattered across school districts and county governments that never show up in a federal spending report.

SLED buyers also tend to sit lower on the ZTMM maturity scale than federal agencies, most of which already have existing security infrastructure to integrate against. That gap shows up as a heavier consulting and implementation services component in SLED contracts, since the work involves building the foundation the tool sits on, not just deploying the tool itself. For a vendor without a deep federal contracting bench, SLED offers a lower-barrier entry point into public sector zero trust work, and past performance built there travels well into a future federal proposal.

What vendors and contractors need to do now to position for the contracts ahead

Start with the vehicles: EIS and MAS for civilian agencies, JWCC for DoD cloud work today, JWCC Next for the next major DoD opportunity, with that solicitation expected in Q2 FY2026 and awards landing by early 2027. Getting onto the right schedule before the RFP drops matters more than a sharp pitch delivered after the fact. By the time the RFP goes public, the vendors already on schedule have a head start nobody else can buy back.

Speak both frameworks fluently: CISA's ZTMM 2.0 for civilian work, DoD's seven-pillar, 45-capability model for defense work. Proposal language naming a specific pillar and a specific maturity stage beats generic zero trust positioning, because that's the exact language agencies use to grade both their own progress and whatever gets pitched to them.

Target the Data pillar specifically, since CISA's own implementation report names it the most underserved, with fewer commercial products than identity or network segmentation. A vendor with real data classification, tagging, and governance capability has room to lead in a field that isn't nearly as crowded, instead of fighting for scraps in identity management.

Take the teaming path seriously instead of assuming prime contractor status is the only door in. GDIT's $1.5 billion and $120 million awards show large integrators building zero trust platforms out of several vendors' capabilities, so a specialized vendor often reaches a big contract faster as a subcontractor than by trying to prime it alone. Build a SLED pipeline alongside that federal push, since state and local grant-funded demand is real, less competed, and generates past performance that strengthens a future federal bid. Keep the calendar in view too: DoD's Target Level deadline hits in FY2027, Advanced Level in FY2032, and FY2027 is close enough that agencies are already in active award mode, not planning mode.

None of this holds still long enough to write once and forget. Contract vehicle updates, revised maturity guides, new executive orders: the language keeps shifting, and proposal and marketing content needs to track it in something close to real time rather than catching up a quarter late. In a market where the deadline is FY2032 but the paperwork changes every few months, that pace can be the difference between writing to the RFP and writing the sentence the RFP eventually quotes back.

Filed underGovernment IT

More in Government IT