Zero Trust Procurement Criteria for Public Sector Vendors
Government vendors now need to map products to NIST's five zero trust pillars to win contracts.

Selling into government right now means proving, in writing, that your product understands zero trust the way NIST, OMB, and increasingly the DoD define it. This is a scoring rubric with pillars, maturity stages, and legal teeth attached. This piece walks through that rubric the way an evaluator actually reads it, pillar by pillar, so you can see where the easy points are and where most vendors still trip.
Quick framing before we get into the weeds: zero trust, as a philosophy, just means nobody gets trusted by default because they're sitting inside the network perimeter. Every request gets checked, every time. NIST wrote this down formally in Special Publication 800-207 back in 2020, and that document is still the technical bible agencies work from. Executive Order 14028, signed in May 2021, told every federal civilian agency to write a zero trust adoption plan. OMB Memo M-22-09, issued in January 2022, turned that instruction into deadlines with teeth, including an FY 2024 target for a specific set of cybersecurity objectives. Then in June 2025, EO 14306 landed under the current administration and, notably, didn't walk any of it back. It added language about quantum threats and AI, and told agencies to bake secure-by-design thinking into procurement decisions from the start. Translation for vendors: compliance with 800-207 is baked into FAR and DFARS now, and if you can't demonstrate it, you either get an ATO waiver or you don't get the contract. This is a legal exposure question that belongs on your capability slide alongside the technical pitch.
The evaluative framework agencies use: CISA's Zero Trust Maturity Model
CISA published version 2.0 of its Zero Trust Maturity Model in April 2023, and this is the actual rubric evaluators use when they read your proposal. Five pillars: Identity, Devices, Networks, Applications and Workloads, and Data. Three things that cut across all five: Visibility and Analytics, Automation and Orchestration, and Governance. Every agency gets scored on where it sits across those pillars, and every vendor's product gets mapped against the same grid.
There are four maturity stages: Traditional, Initial, Advanced, and Optimal. That "Initial" stage didn't exist in version 1; CISA added it after getting 378 public comments telling them the jump from Traditional straight to Advanced was too big a leap for most agencies to make in one move. CISA Director Jen Easterly said as much publicly, that a lot of organizations were stuck on old perimeter-based defenses and needed a rung on the ladder they could actually reach. So now there's one.
Here's the part vendors miss constantly: GSA's own Zero Trust Architecture Tech Book says flatly that zero trust isn't a product. It's a strategy that gets implemented through the services an agency buys, mostly through GSA's Enterprise Infrastructure Solutions (EIS) contract vehicle, which covers SD-WAN, managed security, managed network, managed mobility, and cloud services across IaaS, PaaS, and SaaS. If your proposal pitches "our zero trust solution" without saying which pillar it touches and which maturity stage it moves an agency toward, an evaluator working from this model has nowhere to put you. You become invisible on the scoring sheet, which is arguably worse than being wrong.
What the Identity and Devices pillars specifically require vendors to prove
Identity and Devices are the two pillars where the vendor market has actually grown up. Evaluators here are asking you to show your work, not just confirm you can do the thing.
On Identity, M-22-09 sets three concrete bars. Phishing-resistant multi-factor authentication, enforced at the application layer, not just at the network gate. Single sign-on across every application an employee touches, cloud-based ones included. And updated password policies that drop the old habits: no more mandatory rotation schedules, no more special-character rules nobody could remember anyway, and passwords get checked against known-breach lists. If you're selling an identity product, the evaluator wants session-level enforcement evidence, not a diagram claiming it happens somewhere upstream. Prior authentication doesn't count as ongoing trust; that's the whole point of zero trust, so a product that assumes it does is failing the philosophy it claims to implement.
Devices works similarly but with an inventory twist. Agencies have to maintain a complete list of every device authorized for government use, and prove they can prevent, detect, and respond to incidents on each one. If you sell endpoint management or device tools, you need to support that inventory and response loop, not just get devices talking to the network. There's also a hard date buried in EO 14306: January 4, 2027, is when every IoT device sold to the federal government has to carry the US Cyber Trust Mark, built on NIST SP 800-213. Miss that mark and you lose eligibility for IoT sales to the government, full stop. Mark your calendar, or better yet, mark your compliance roadmap.
Networks, Applications, and Data: the three pillars where most vendors still have gaps
This is where the market thins out, and honestly, where the interesting work still is.
Networks: M-22-09 requires encryption on all DNS requests and HTTP traffic inside agency environments. Micro-segmentation, breaking the network into isolated zones instead of one big trusted perimeter, is a core design principle in NIST 800-207, not an add-on feature. Vendors selling infrastructure need to show segmentation capability directly; vendors selling managed services need to show they can operationally support isolating a segment when something goes wrong in it.
Applications and Workloads treats every application as if it's sitting on the open internet, no exceptions for "it's behind our firewall so it's fine." Agencies have to run routine, serious testing on their applications and accept vulnerability reports from outside researchers. As of the fourth quarter of FY2024, 51 agencies had signed on to CISA's Vulnerability Disclosure Program platform. If your product plugs into or eases that VDP onboarding process, that's a visible, scorable advantage, and most vendors aren't even mentioning it.
Data is the one CISA itself calls out as the biggest opportunity, because it's the pillar where agency maturity lags furthest behind. Identity, credential, and access management gaps, plus weak data tagging and classification, keep showing up in 2025 market analysis as the persistent blockers to real zero trust progress. If you've got a data classification or ICAM product, this is where you lead your pitch, not bury it on page nine. It's underserved, agencies know it's underserved, and evaluators are actively looking for anyone who can close that gap.
One more thing worth saying plainly: those three cross-cutting capabilities, Visibility and Analytics, Automation and Orchestration, and Governance, run through all five pillars. A vendor who nails Data but says nothing about how their product feeds visibility or governance reporting is going to score lower on a holistic review than one who connects the dots. Evaluators aren't grading pillars in isolation; they're grading the whole grid.
The DoD's stricter standard and what it means for defense vendors specifically
If you thought civilian agency requirements were granular, the Pentagon's version makes M-22-09 look like a suggestion box. The DoD Zero Trust Strategy and Capability Execution Roadmap breaks the work into 152 discrete activities spread across seven interdependent pillars. Of those, 91 activities make up the Target Level, due by FY 2027. The remaining 61 make up the Advanced Level, due by FY 2032.
As of late 2024, only 14% of those 152 activities had actually been completed across the board. Sit with that number for a second: FY 2027 isn't far off, and the gap between where things stand and where they need to be is wide enough that any vendor who can genuinely accelerate progress on those 91 Target Level activities has a real, sellable value proposition, not just a talking point.
The consequences of missing the deadline aren't soft. Organizations without Target Level certification by September 30, 2027, become ineligible for new DoD contract awards. Existing contracts don't get a pass either; you can't exercise an option period or extend performance without certification in hand. And the pressure is already flowing downhill: prime contractors are screening subcontractors for zero trust compliance before they even commit to a bid, which means non-compliant subs are getting cut before the solicitation is ever posted. Nobody wants to be the weak link that sinks a prime's bid.
Layer CMMC 2.0 on top of this and things get busier. Defense contractors handling Controlled Unclassified Information have to hit 110 controls under NIST SP 800-171 to reach CMMC 2.0 Level 2. CMMC never actually says the words "zero trust," but a working zero trust architecture makes hitting those 110 controls dramatically easier, since the two frameworks are pulling in the same direction. The enforcement timeline is rolling out in stages: self-assessed Level 1 and 2 status becomes required in solicitations starting November 2025, with C3PAO-assessed Level 2 mandatory by November 2026, and DIBCAC-assessed Level 3 required by November 2027. Vendors who treat CMMC and zero trust as two separate compliance projects are doing twice the work for half the argument. Combine them, and you've got a pitch that writes itself.
How False Claims Act enforcement turned compliance certifications into legal instruments
Here's where this stops being a technical exercise and starts being a legal one. When a vendor certifies cybersecurity compliance on a federal contract and that certification turns out to be false, or just unsupported, the False Claims Act kicks in. That means civil fraud liability: treble damages, plus penalties calculated per claim, not per contract.
The Department of Justice moved fast on this in 2025. They settled cybersecurity fraud cases at a noticeably higher rate than before, including the first FCA enforcement action brought against a subcontractor rather than a prime, and a separate case where an acquiring company got held liable for cybersecurity violations the acquired company committed before the deal closed. Read that twice. It means due diligence on zero trust compliance is now something your M&A lawyers need to care about, alongside your contracts department. Buying a company with sloppy compliance records carries inherited legal exposure, well beyond an operational headache.
The clearest illustration: Health Net Federal Services, along with parent company Centene Corporation, agreed to pay roughly $11.25 million in a settlement announced by DOJ on February 18, 2025, resolving claims that HNFS had falsely certified compliance with federal cybersecurity contract requirements. Eleven million dollars is a real number, and it's the kind of number that gets a general counsel's attention.
CMMC 2.0 makes this worse in a subtle way, through its annual affirmation requirement. Vendors have to re-certify their compliance status every year, which means every single affirmation is a fresh moment of FCA exposure if your controls have quietly drifted, or worse, were never fully implemented the way you claimed. So the compliance documentation you write to win the contract needs to hold up under audit at any point during the contract's life, not just at signing. Treat it as a legal record, because that's exactly what it becomes the moment DOJ comes asking.
What evaluators actually look for in vendor proposals and technical documentation
So what does all this add up to when you're actually sitting down to write a proposal? A few concrete habits separate vendors who score well from vendors who don't.
Map your language directly to CISA's ZTMM pillars and maturity stages. Evaluators are literally working from that model with that vocabulary, so a proposal that mirrors it is easier to score, plain and simple. Show your current maturity stage honestly, and show a credible path to the next one; agencies get measured on their progression, and a vendor who can move that needle scores better than one who claims a compliance level they can't actually evidence. For Identity and Devices, bring implementation evidence, not architecture diagrams: MFA enforcement logs, your device inventory methodology, proof your product ties into incident response. For Data and ICAM, where agency maturity is weakest, lead with your capability instead of hiding it in an appendix; that's the underserved lane and evaluators know it.
DoD vendors need to get even more specific: map your deliverables to the 91 Target Level activities by name, and state plainly which of the 152 total activities your product closes and at what maturity level. "Supports zero trust" reads as filler, not a scorable sentence, and evaluators skip past filler fast. Have your compliance documentation ready at every tier of the supply chain, not just as a prime, since subcontractor screening keeps tightening. And keep your certifications, evidence, and audit trail current on a rolling basis, not something you assemble in a panic when an FCA letter shows up.
Last thing worth saying: if you're not on GSA's EIS contract vehicle or something comparable, you're starting from a structural disadvantage no matter how good your technology is. Your engineering team isn't the problem. The door is just somewhere else.


