Session Presentation
Zero Trust in 2026: 6 Key Takeaways for Federal Cloud Providers and Contractors



Session speakers: Jason Macallister and Nikolas Theiss
Zero trust has moved from an aspirational framework to a practical expectation across the federal landscape.
InZero Trust in 2026, Jason Macallister and Nikolas Theiss explained how federal zero trust mandates are reshaping agency expectations and influencing the commercial cloud services those agencies rely on.
Their RAMPCon session made the case that perimeter-based security no longer matches today’s threat environment. As identity-driven attacks grow faster and more sophisticated, organizations need to strengthen how they verify access, enforce policy, and limit attacker movement across the enterprise.
“Zero trust is not a product you buy. It is a discipline you build into how access, policy, and security operate every day.”
1. Zero trust may not be stated as a requirement everywhere, but the expectation is already there
Federal zero trust architecture mandates do not always apply explicitly to federal contractors or authorized commercial cloud service providers. Even so, underlying zero trust aligned controls requirements already show up across frameworks such as FedRAMP Rev. 5, the DoD CC SRG, NIST 800-171 Rev. 3, and FedRAMP CR26. Organizations that interpret and implement those requirements through a zero trust lens can strengthen agency confidence and improve their security posture at the same time.
2. The threat environment makes zero trust urgent
This is not just a policy trend. It is a response to how attacks now happen. The session highlighted a threat landscape shaped by machine-speed attacks, identity compromise, and rapid lateral movement. Even if an organization believes the mandate does not directly apply, the threat does. That alone should be enough to push zero trust higher on the priority list.
3. Identity is the new perimeter
The network boundary no longer defines security in the way it once did. Identity does. Jason and Nikolas emphasized that phishing-resistant multi-factor authentication and least privilege are the starting point, not the finish line. Mature zero trust programs move beyond static access rules toward context-based decisions and then to dynamic, risk-adaptive policy enforcement that responds to changing conditions across the enterprise.
4. Many organizations already have core zero trust pieces in place
For federally aligned programs, the issue is often not starting from scratch. Many environments already have several core capabilities in place, including centralized identity providers, MFA, EDR, SIEM, FIPS encryption, and boundary protection. The real gap is integration. Tools that exist in isolation do not create zero trust maturity on their own. Organizations need consistent policy enforcement and tighter coordination across the pillars.
5. Zero trust helps contain the damage when attacks succeed
One of the strongest business cases from the session was that zero trust can reduce the cost of a breach. The speakers pointed to IBM research showing that organizations with varying degrees of zero trust maturity reduced average breach costs by $1.76 million compared with those without zero trust deployment. That does not mean zero trust prevents every attack. It means it helps contain impact when attacks happen.
6. Zero trust is an operating model, not a tool checklist
The session closed on a point that many organizations still get wrong: zero trust is not a product purchase. Buying tools that map to zero trust capabilities is not the same as building a zero-trust architecture. The better approach is to follow the NIST 800-207 migration path, measure effectiveness through practical outcomes, and demonstrate capabilities through policy enforcement, access controls, and security results rather than tool counts.
Why this matters now
Federal agencies are pushing toward stronger zero trust maturity because the old model of implicit trust no longer holds. That shift affects more than government networks. It affects the suppliers, platforms, and service providers that support federal missions and handle sensitive workloads.
For many organizations, the opportunity is not to rip and replace what they already have. It is to connect the capabilities they have already built, enforce policy more consistently, and move toward access decisions that reflect real risk in real time. That is how zero trust becomes practical instead of performative.
Closing thoughts
The clearest takeaway from this session was that zero trust maturity starts with discipline, not procurement. Organizations need to understand where identity risk sits today, where policy enforcement breaks down, and where existing tools are not working together the way they should. From there, the path forward becomes more manageable and far more defensible.
If you want to dive deeper into zero trust architecture or get help with a current or upcoming project, get in touch with the Coalfire team. We can help with zero trust planning, architecture, implementation, evaluation, and security testing, whether you are working across the enterprise or within a specific federal program or enclave.