cisatrade-pressNewsThe Broadside2 min read

CISA Taps CDM Telemetry to Gauge Directive Compliance

The program that used to ask agencies whether they'd deployed a capability can now measure operational performance continuously, and the data shapes when CISA issues new binding operational directives.


TL;DR

Acting Federal CISO Michael Duffy and CDM program manager Matt House detailed how the Continuous Diagnostics and Mitigation program's dashboards now supply CISA and OMB with agency-level telemetry that goes beyond yes/no checklists. Speaking at the Billington Cybersecurity Summit, Duffy framed the shift as "continuous monitoring for real", visibility into whether agencies are actually operating zero-trust capabilities, not just planning them. House separately told Inside Cybersecurity that dashboard data informs decisions about issuing binding operational directives by showing whether the data supports the need and whether agencies can execute.

The CDM program has been around since 2012, but its operational role has shifted materially in the last two years. CISA's 2023 account of using the CDM Federal Dashboard to spot other vulnerable federal systems within minutes of an agency reporting an active exploit already showed the program moving beyond static compliance. Duffy's remarks at Billington make clear that shift is now official posture: CDM telemetry is how OMB and CISA check whether agencies are doing zero trust in production.

"Those are the cross-functional capabilities that matter so much when we're implementing zero trust," Duffy said. "It is how we operate with what we have today."

What the dashboards actually show

CDM Agency Dashboards pull data from sensors and tools deployed inside each agency's environment. Those dashboards then share summarized information with CISA's CDM Federal Dashboard, which gives CISA and OMB an integrated view across the federal civilian enterprise. House told Inside Cybersecurity the dataset gets used tactically during incident response (to understand prevalence of a threat across the FCEB) and strategically to support decisions about whether to issue a binding operational directive.

"Do we see the data to support that? Do we have mechanisms to allow agencies to execute and get to a place of done that we can all agree upon using the data in the dashboard?" House said, describing the questions CISA asks before issuing a directive.

That framing is notable because it ties CDM data to the directive lifecycle rather than treating the dashboards as a separate reporting channel. The GAO reported in June 2025 that 21 of 23 agencies hadn't fully implemented network security and data protection capabilities under CDM, with several citing a lack of guidance. House's comments suggest the program's evolution toward directive-supporting telemetry is happening in parallel with uneven agency adoption, the data gets richer where agencies are fully instrumented, and thinner where they aren't.


Published ·Deep Fathom