CISA, partners reject copy-paste zero trust for OT
The April joint guide is the first federal break from copy-paste IT controls, but it leaves compliance deadlines and auditing unspecified.
TL;DR
In April, CISA and four federal partners released Adapting Zero Trust Principles to Operational Technology, the first interagency zero-trust guide that treats OT as distinct from IT rather than an extension of the enterprise playbook. It puts asset visibility and network segmentation ahead of direct IT control translation, with secure communications and stronger identity controls in support. What's absent is any compliance deadline or audit mechanism, let alone an acquisition rule tying contractors to the standard.
In April, the Cybersecurity and Infrastructure Security Agency joined the Defense Department, the Energy Department, the FBI, and the State Department to publish Adapting Zero Trust Principles to Operational Technology. It's the first interagency zero-trust guidance that treats OT as its own problem rather than an extension of the enterprise IT playbook. That distinction is the whole point. In a compromised office network you can pull a machine offline and investigate. In a water plant or power substation, taking the controller offline can be a bigger operational and safety risk than leaving a degraded system running.
The guidance calls for comprehensive asset visibility, layered controls, network segmentation, secure communications, vulnerability management, and strong identity and access management, all while preserving availability and safety. None of that is new to OT practitioners; the framing is. CISA says threat actors like Volt Typhoon have used OT to compromise environments and hold access (CISA release), and zero trust is how operators keep visibility and control over physical processes once an adversary is already inside. A September Federal News Network commentary that tied these points to the Minnesota water-system attacks comes from a Fortinet Federal engineering director, so its "design for disruption" language is vendor commentary. The underlying guide is primary CISA.
The load-bearing requirement is inventory. You can't segment or recover what you can't see, and OT visibility is hard because devices live for decades, speak specialized protocols, sit behind air gaps, and react badly to aggressive scanning. CISA's separate August 2025 asset inventory guidance (cisa.gov) tells owners to build a taxonomy that classifies assets by function and criticality first. Monday's work is passive discovery and operator coordination, not a tool deployment.
One thing the guidance doesn't do is impose a deadline. There's no compliance date or audit mechanism, and no acquisition rule tying a contractor's OT security posture to a contract requirement. Agencies and suppliers get principles and a mandate to treat OT as distinct, but the enforcement architecture is still unspecified. That's the gap to watch: the guide settles the conceptual question and leaves the compliance question open.
Published ·Deep Fathom