Skip to main content
CybersecurityNetwork Security

DoD Accelerates Zero Trust Push Beyond Users, Devices

Secure government facility's network operations center with rows of computer servers and cybersecurity equipment.

The Pentagon is well down its path to implementing Zero Trust principles and architecture for information technology systems related to users and devices.

Where DoD stands on Zero Trust for users and devices

That assessment is the opening fact for a Breaking Defense webinar scheduled for August 26, 2026, which will take stock of progress and the next phase of work. The event frames current accomplishments as focused primarily on users and devices — the classic starting points for Zero Trust — and positions those gains as the foundation for broader application across the department.

Speakers will examine the status of Zero Trust implementations across the Department of Defense on the way to full compliance with DoD CIO directives and service-specific requirements over the next two years. The webinar’s agenda explicitly lists “the current state of Zero Trust across the DoD and defense industrial base” as its first topic, underscoring the department-wide scope of the effort.

Extending Zero Trust to operational technology, IoT, and weapon systems

The next step described in the webinar materials is an expansion of Zero Trust targets and goals beyond users and devices to include operational technology (OT) — such as industrial control systems — Internet of Things devices, and weapon systems. The materials state that many of the same Zero Trust principles and architecture being applied to IT will be applied to those domains.

That is a significant broadening of scope: OT and weapon systems carry different operational constraints, lifecycles, and connectivity models than enterprise IT. The webinar agenda and learning objectives commit to discussing how Zero Trust principles should be adapted for those environments, including what technical elements and capabilities must be combined to execute an implementation.

Coordinating Zero Trust across the services and the defense industrial base

Coordination is a named focus. The webinar lists “Zero Trust coordination across the services” and “the expansion of Zero Trust principles … to operational technology and weapon systems” as distinct agenda items, and it explicitly includes the defense industrial base in the overview of current state. That framing signals the department intends cross-service alignment and outreach to suppliers as part of its compliance push.

How that coordination will be operationalized — which service-specific requirements will diverge, and how the defense industrial base will align to DoD CIO directives — will be among the topics the session promises to examine.

Quantifying Zero Trust success and the DoD roadmap for 12–24 months

Measuring progress is a defined objective. The webinar will address “quantifying Zero Trust success” and provide “knowledge of the DoD’s Zero Trust roadmap for the next 12-24 months.” Those two commitments indicate an emphasis on both metrics and near-term planning: attendees are expected to learn what success looks like and what steps the department will take to achieve compliance within the stated two-year window.

The program also highlights the need to distinguish Zero Trust elements at tactical, operational, and strategic levels, and to consider how enterprise Zero Trust approaches differ from implementations at the tactical edge.

What this means for technologists, policymakers, and the defense industrial base

  • Technologists and security teams: The webinar lists as learning objectives an understanding of the “specific pain points that the various services are experiencing” and the “technical elements/capabilities that need to be combined” for Zero Trust. That signals practical, implementation-oriented discussion aimed at those responsible for designing and integrating controls.
  • Policymakers and acquisition leaders: With full compliance tied to DoD CIO directives and service-specific requirements in the next two years, policymakers and procurement officials will need to follow the roadmap and metrics the department adopts to ensure policy and contracting align with technical timelines.
  • The defense industrial base: The agenda explicitly includes the defense industrial base in assessing current Zero Trust status, indicating suppliers should expect discussion of expectations and possible requirements as Zero Trust principles extend into OT and weapon systems.

The Breaking Defense webinar is set for August 26, 2026 at 2 p.m. ET / 11 a.m. PT. Participants can earn 1 CPE credit (Field of Study: Business Management & Organization) but must respond to all three polling questions asked during the live program to receive full credit. The session promises to be a concentrated look at how the department measures success, coordinates across services, and translates enterprise Zero Trust into the realities of tactical and operational systems over the next 12–24 months.

Source: Breaking Defense — The state of DoD Zero Trust: Progress toward target level