Rethink Zero Trust: Prepare for DoW Strategy 2.0

10:05:2026

Rethink Zero Trust: Prepare for DoW Strategy 2.0

The Department of War (DoW) is preparing Zero Trust Strategy 2.0. This update to the 2022 framework extends coverage beyond information technology (IT) to operational technology (OT), weapons platforms, and defense-critical infrastructure. 

Their strategy reflects a shift in which identity is a continuous signal, trust is never assumed, and every access decision is evaluated against real-time context. Read on for details on how the framework is evolving and what it means for implementation.

Key Changes in Zero Trust Model 2.0

Continuous Identity Verification

The National Security Agency (NSA) released Phase One and Phase Two of its Zero Trust Implementation Guidelines in January 2026. Together, they define 77 activities that support 64 zero‑trust capabilities, organized to move organizations from discovery to the DoW’s target‑level maturity. The guidance emphasizes continuous evaluation after authentication rather than treating login as a one‑time gate. 

Many cyberattacks now succeed after credentials are compromised, making point‑in‑time verification insufficient. The NSA directs agencies to continuously monitor sessions; for instance, they’re required to evaluate user activity, requested privileges, and accessed resources. And they’re systems need to trigger step‑up authentication or session termination when the risk context changes.

Adaptive Micro‑Segmentation

In the current zero‑trust framework, micro-segmentation functions as an adaptive control rather than a static network boundary. The April 2026 interagency guidance on Zero Trust for OT (issued by the Cybersecurity and Infrastructure Security Agency (CISA), the Department of War, Department of Energy, FBI, and the Department of State) identifies micro‑segmentation as a core mechanism for limiting lateral movement within OT environments. 

Agent‑based and agentless enforcement approaches allow segmentation across IT, OT, IoT, and legacy systems. When an adversary gains a foothold, properly configured segmentation contains the blast radius. The guidance recommends audit‑only policies for monitored boundaries and block policies for critical zones, applied progressively as operators validate traffic patterns against mission requirements.

Post‑Quantum Cryptography Migration

The National Institute of Standards and Technology (NIST) finalized its first three post‑quantum cryptographic (PQC) algorithms in August 2024. A draft executive order under review in May 2026 would require federal agencies to migrate digital signatures for high‑impact systems to PQC standards by December 2031 and to adopt PQC for key establishment by December 2030, with covered contractors subject to the same deadlines. 

CISA published a list of PQC‑capable product categories in January 2026 to support federal acquisition planning. The migration requires cryptographic inventory, systems‑level assessment, and integration with zero‑trust identity and network controls. NIST plans to deprecate quantum‑vulnerable algorithms from its standards by 2035, though high‑risk systems will transition earlier.

AI‑Driven Behavioral Analytics

The Pentagon issued a request for information (RFI) in January 2026 seeking industry input on using AI and machine learning to scale zero‑trust assessments. The RFI explored how automated tools could support purple team assessments, identify attack paths, and analyze detection effectiveness across the department’s IT environments. 

Concurrently, the NSA guidelines direct agencies to baseline normal activity and detect anomalies such as privilege escalation, unusual data access, and lateral movement. This moves beyond static indicators like login location or device type. Behavioral analytics provide the continuous validation that rule‑based detection cannot sustain across dynamic operational environments.

Risk‑Based Access Control

Risk-based access control evaluates each request against real-time signals: device posture, user behavior, geolocation, and the sensitivity of the requested resource. When risk exceeds a defined threshold, enforcement adjusts proportionally (from step-up authentication to session termination).

The interagency OT guidance applies this principle to industrial control systems, recommending that access decisions account for operational context and the potential physical consequences of a compromise. Access is continuously evaluated rather than permanently granted, reflecting the principle that identity misuse by authenticated users is a primary threat vector in current operational environments.

Implementing Zero Trust 2.0

Below, we outline what the implementation requires in practice.

Prioritize High‑Impact Systems

The NSA’s phased guidelines begin with a Discovery Phase that establishes visibility into data, applications, assets, and access activity before deploying any controls. Phase One then defines 36 activities that build a secure baseline across 30 capabilities. Implementation sequencing should direct resources toward systems where compromise carries the greatest operational consequence. 

Modernize Identity Infrastructure

The Federal Identity Lifecycle Management Playbook, updated in March 2026, guides agencies in shifting from managing authenticators to managing the continuous lifecycle of digital identities. Modern identity infrastructure encompasses all identity types: human users, devices, APIs, and automated agents. Phishing‑resistant multi‑factor authentication and automated provisioning and deprovisioning are baseline controls. The playbook recommends that agencies designate authoritative sources of truth for identity attributes and implement identity governance tools to centralize user data across the enterprise.

Extend Zero Trust to the Tactical Edge

Zero-trust enforcement in environments with intermittent or absent connectivity requires a distinct approach. Forward‑deployed policy decision points and enforcement points must operate autonomously, enforcing access using cached and encrypted policy when links to enterprise control planes are unavailable. 

This model accommodates headless systems and enables rapid onboarding of coalition partners without reach‑back to centralized identity infrastructure. Operational requirements include policy continuity during extended SATCOM disruption and consistent enforcement across classification boundaries.

Integrate Continuous Monitoring and Threat Detection

Zero Trust depends on continuous monitoring to detect malicious activity that occurs after access is granted. The NSA guidelines structure implementation across seven pillars, each contributing to the framework’s detection and response capabilities:

SealingTech's AegisEdge MicroServers

Security information and event management (SIEM) platforms correlate activity from identity systems, devices, networks, and applications into a unified risk view. The objective is detection of identity misuse after authentication through continuous telemetry rather than periodic review.

Advance Your Zero Trust Architecture

Rethink Zero Trust: Prepare for DoW Strategy 2.0

SealingTech’s AegisEdge MicroServers

SealingTech delivers defensive cyber solutions purpose‑built for zero‑trust enforcement at the tactical edge. AegisEdge MicroServers provide compact, TAA‑compliant compute for OT and ICS environments. Zepharis™ AI, designed for edge operations, runs fully offline. It enables behavioral analytics and threat detection in air‑gapped environments. 

Backed by a veteran‑founded team with over a decade of service to the Department of War, SealingTech addresses the operational realities of zero‑trust implementation in contested environments. Contact our team to learn more.

Related Articles

CIRCIA’s Coming: Is Your Business Ready for Mandatory Cyber Reporting?

In March 2022, the Cyber Incident Reporting for Critical Infrastructure Act(opens in new tab) (CIRCIA) was signed into law, creating the federal government’s first comprehensive, cross-sector framework for mandatory cyber…

Learn More

Understanding Zero Trust Network Access (ZTNA)

Zero Trust Network Access replaces implicit network trust with continuous, identity-based verification of every access request. Rather than placing a user on the network, it grants application-level access after confirming…

Learn More

National Infrastructure Priority Status: Benefit, Impact, and Why It Matters

The United States is in the midst of a generational investment in the nation’s infrastructure. This modernization effort (spanning energy, transportation, water, and digital systems) arrives alongside an era of…

Learn More

Could your news use a jolt?

Find out what’s happening across the cyber landscape every month with The Lightning Report. 

Be privy to the latest trends and evolutions, along with strategies to safeguard your government agency or enterprise from cyber threats. Subscribe now.