cisatrade-pressNewsThe Broadside2 min read

Venable urges CISA to rebuild CDM acquisition model

The useful part is the procurement diagnosis: duplicative agency tool buys are a poor delivery vehicle for federal Zero Trust.


TL;DR

Inside Cybersecurity reports that Venable’s Center for Cybersecurity Policy and Law and the Institute for Critical Infrastructure Technology published a July 2 plan to modernize CISA’s Continuous Diagnostics and Mitigation program. The report urges CISA and OMB to reshape CDM buying, funding and dashboards around Zero Trust, enterprise risk management and Federal Civilian Executive Branch visibility. For agencies, the pressure point is familiar: CDM can see more than it can standardize.

Venable’s Center for Cybersecurity Policy and Law and the Institute for Critical Infrastructure Technology are pressing CISA to treat Continuous Diagnostics and Mitigation as the federal civilian government’s central operating layer for Zero Trust, continuous visibility, enterprise risk management and coordinated defense. The report’s real diagnosis is procurement architecture. A program built around fragmented buying, administrative overhead and siloed implementations will struggle to deliver enterprise security outcomes, no matter how good the dashboards become.

CDM has always had that dual identity. CISA describes the program as providing tools, integration services and dashboards that reduce agency threat surface, increase federal cybersecurity visibility, improve response and streamline Federal Information Security Modernization Act reporting. The program dates to 2012, and CISA has separately said its agency and federal dashboards give operators host-level visibility for coordinated response across the Federal Civilian Executive Branch, https://www.cisa.gov/continuous-diagnostics-and-mitigation-cdm and https://www.cisa.gov/news-events/news/evolving-cdm-transform-government-cybersecurity-operations-and-enable-cisas-approach-interactive.

The Venable report, as described by Inside Cybersecurity, argues that the buying model has not kept up with the mission. It calls for OMB mechanisms to flag duplicative cybersecurity purchases, shelfware and redundant capabilities, and for licensing paths based on aggregated demand and standardized contract terms. It also wants better visibility into capability coverage, gaps, procurement barriers and deployment barriers, with the federal CIO and CISA using that data for software inventory, tool rationalization and enterprise consolidation.

The dashboard recommendation is the other half of the same point. The report says CDM agency dashboards should move beyond FISMA reporting and become a federated operational platform that aggregates telemetry, analytics and workflow data from agency tools. That lines up with GAO’s June 2025 finding that CDM had met two goals but only partially met visibility and FISMA-reporting goals, while 21 of 23 agencies said they had not fully implemented network security and data protection capabilities, https://www.gao.gov/products/gao-25-107470.

For practitioners, the report does not change Monday’s control implementation work. It does describe the shape of the fight: fewer bespoke agency purchases, more shared licensing and a CDM dashboard that functions as operational infrastructure instead of a reporting sink. That is a procurement reform story wearing a Zero Trust label, which is probably why it matters.


Published ·Deep Fathom