bodtrade-pressNewsThe Broadside3 min read

Wyden Urges Mandatory Federal VPN Purge Within Two Years

The request for a binding operational directive and procurement attestation rules signals Congress is losing patience with CISA's vulnerability-by-vulnerability approach to federal edge-device security.


TL;DR

Sen. Ron Wyden (D-Ore.) sent a letter Monday to CISA, OMB, and NIST calling for agencies to replace all legacy, public-facing VPN remote-access systems with zero-trust architecture within two years. He asked CISA to issue a binding operational directive mandating the transition, NIST to publish zero-trust implementation standards, and OMB (coordinating with the Defense Department) to update procurement rules so agencies and defense contractors can't buy VPN or edge-device solutions unless the vendor attests to NIST zero-trust compliance. Wyden framed the ask as breaking a "whack-a-mole" cycle where CISA issues emergency directives to patch individual VPN appliance vulnerabilities without addressing the architectural exposure itself.

Wyden Urges Mandatory Federal VPN Purge Within Two Years
Editorial illustration · drawn by The Broadside

Wyden's letter, first reported by CyberScoop, frames the current federal approach as an "endless game of 'whack-a-mole'", CISA issuing emergency directives and accelerated patch mandates each time a new vulnerability surfaces in a VPN appliance from Cisco, Fortinet, Ivanti, or Check Point. Wyden referenced the ArcaneDoor attacks on Cisco firewalls, the FortiBleed credential exposures, and exploited vulnerabilities across Ivanti and Check Point appliances. His argument: the vulnerabilities aren't one-off bugs. They're inherent to the architecture of leaving an encrypted tunnel entrance exposed on the public internet.

How this differs from CISA's existing edge-device directives

CISA has already acted on edge-device risk through two binding operational directives. BOD 23-02 (June 2023) required agencies to remove specific networked management interfaces on routers, switches, firewalls, VPN concentrators, and similar devices from the public internet (or implement zero-trust access controls) within 14 days of discovery. BOD 26-02 (February 2026) required agencies to inventory unsupported edge devices within three months and replace those appearing on a CISA-maintained list within one year.

Both directives narrowed in on specific device categories or support-status problems. Wyden's request is structurally different: it seeks a preventive architecture mandate declaring the entire class of public-facing legacy VPN remote-access systems obsolete for federal use, with a hard two-year sunset. It's the difference between telling agencies to lock the doors on a building with known weak points and telling them to stop using the building.

What the procurement change would mean

The procurement request is the sharpest edge of the letter. Wyden wants OMB, coordinating with CISA and the Defense Department, to update federal acquisition rules so agencies and defense contractors cannot purchase "network edge, VPN, or other remote-access solutions" unless the vendor attests to NIST zero-trust compliance.

That would function as a market gate. VPN vendors whose products depend on public-facing concentrator architecture would need to either retool or lose access to federal buyers. It also extends the obligation beyond FCEB agencies to defense contractors through DoD procurement channels, a broader reach than CISA's BODs, which bind only federal civilian agencies.

For agencies and contractors still running legacy VPNs, the practical deadline is the two-year BOD clock Wyden wants CISA to set. If the directive issues, federal cybersecurity teams face a mid-2028 deadline to architect, procure, and deploy zero-trust remote-access, not merely patch what they already have.

The open question

The letter is a request. CISA, OMB, and NIST aren't obligated to act on it, and none has signaled whether they will. Agencies have generally complied with CISA's prior edge-device directives even though CISA lacks direct enforcement authority, but a two-year architecture mandate is a heavier lift than a 14-day interface lockdown.

Wyden's letter doesn't specify an enforcement mechanism for agencies that miss the deadline, and the existing model (what CISA's Nick Andersen described in February as "not about forcing agencies to comply so much as working with them to find a resolution") hasn't been tested against a requirement this broad. Whether the collaborative compliance model scales to a preventive architecture mandate covering every public-facing remote-access system across the FCEB is the question the letter leaves unanswered.


Published ·Updated ·Deep Fathom