The NSA published Zero Trust Implementation Guidelines Phase One and Phase Two, expanding its series beyond earlier Primer and Discovery Phase materials to provide more actionable, task-based direction aligned to the DoD target-level maturity model. Phase One outlines 36 activities intended to establish conditions for 30 zero trust capabilities, while Phase Two defines 41 activities to begin integrating core zero trust solutions and enable 34 additional capabilities, with a modular approach intended to let organizations tailor adoption based on maturity and constraints.
Separately, the General Services Administration (GSA) is tightening federal supply-chain cybersecurity expectations by issuing an IT security procedural guide (CIO-IT Security-21-112 Rev. 1) that imposes CMMC-like requirements on certain new contracts involving CUI, including implementation of NIST SP 800-171 and selected 800-172 controls. The guide identifies eight blocking requirements (including MFA, encryption of CUI in transit and at rest, vulnerability scanning/remediation, and removal of end-of-life components) and requires independent assessments via FedRAMP third-party organizations or GSA-approved assessors, though GSA has not published assessor approval criteria—creating potential uncertainty for contractors; a separate GSA acquisition discussion on AI purchasing emphasizes flexibility, cost savings, and responsible use but does not materially add to the zero trust or contractor-control policy details.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The NSA published Phase One and Phase Two of its Zero Trust Implementation Guidelines, expanding its broader zero trust guidance series with phased activities and capabilities for enterprise adoption. The guidance was described as modular and aligned with Department of Defense and federal zero trust maturity frameworks.
On 2026-01-05, GSA's Office of the Chief Information Security Officer issued an IT security procedural guide for certain federal contractors handling Controlled Unclassified Information. The guide requires implementation of NIST SP 800-171 and selected NIST SP 800-172 controls, along with independent assessments and mandatory security measures for new contracts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.