Government IT Officers evaluating ZTNA face a different challenge than the CISOs and Authorizing Officials they support. The IT Officer's role spans procurement execution, vendor management, deployment coordination, and day-to-day implementation oversight - and the vendor that scores best on a strategic evaluation is not always the one that produces a successful deployment in operational reality.
This guide covers the five federal use cases that ZTNA actually serves, the questions that belong in an RFP, and the implementation realities worth anticipating before award.
Five federal use cases
Distributed DoD workforce. A component with 5,000–50,000 personnel across installations, telework locations, and field operations, running a VPN concentrator approaching end-of-life. The requirements are PIV/CAC authentication, derived credentials for mobile, DoD ICAM integration, and application-specific rather than network-level access - with a migration that doesn't disrupt the 40–60% of personnel working remotely on any given day. Deployment typically phases over 12–18 months: administrators first, then contractors, then production populations in tranches, with the VPN running throughout and decommissioned only at the end.
DIB contractor CUI handling. A contractor with 500–10,000 employees handling Controlled Unclassified Information under CMMC Level 2 or 3, where assessors typically find VPN plus procedural controls inadequate. Requirements center on identity-attributed access to CUI environments, session recording for privileged operations, and segmentation preventing movement from non-CUI to CUI systems. Deployment runs 9–15 months - shorter than a DoD component because the scope is narrower - and produces assessment artifacts continuously rather than through point-in-time evidence collection.
Cross-classification operations. A component operating across Unclassified, CUI, Secret, and sometimes Top Secret, currently maintaining separate access infrastructure per level with different credentials, devices, and procedures. Requirements include classification-aware access decisions, structural separation preventing cross-contamination, and audit evidence supporting multi-classification continuous monitoring. Many ZTNA platforms cannot serve this case at all, because their foundations assume single-classification deployment.
IT-OT integration at military installations. A post, base, yard, or industrial facility running building automation, energy management, water treatment, gate access control, and industrial control systems alongside IT. The boundary has historically been a data diode or air gap with manual file transfer for firmware updates and vendor maintenance. What's needed is remote vendor maintenance without physical presence, content inspection on files crossing the boundary, identity-attributed audit for OT operations, and alignment with NIST SP 800-82. Deployment establishes outbound-only connectivity over TLS 443 from the OT enclave, then content inspection workflows, then vendor access with session recording.
Coalition and allied partner access. A component or combatant command providing mission system access to FVEY, NATO, or ad-hoc coalition partners whose personnel hold clearances from their own governments and use their own devices. Requirements include federation with partner identity providers, attribute-based access on coalition role rather than DoD employment, releasability handling, and operational tempo supporting rapidly formed coalitions. Federation replaces the ad-hoc VPN configurations and manual credential issuance that don't scale.
What belongs in the RFP
Six questions produce comparable responses across vendors and surface the architectural evidence that distinguishes platforms built for federal requirements from platforms extended toward them.
Architectural foundation. Does the solution use outbound-only Reverse Access eliminating inbound listeners, or traditional inbound-listener architecture? Ask for diagrams showing connection flow direction.
Federal identity integration. Does it natively integrate with PIV/CAC, DoD ICAM, and federal SSO? Which providers have certified deployments, and what is the derived credential approach for mobile?
Multi-classification support. What are the deployment patterns for IL2, IL4, IL5, and IL6, and what is the current authorization status at each Impact Level?
IT-OT capability. Does IT-OT integration operate as platform functionality, or does it require a separate product and a second procurement?
Audit evidence. What is produced automatically - identity attribution at source, session recording, continuous monitoring evidence? Ask for samples.
Deployment and day-2 support. What is the phased methodology, the resource commitment expected from the customer team, the operational handoff pattern, and the support structure for federal customers - US-based operations, cleared staff for higher classifications, federal-specific escalation?
Responses that avoid specifics, redirect to marketing material, or claim capability without architectural evidence indicate poor federal fit.
Implementation realities
Timeline. Federal deployment runs 12–30 months from award to full operational capability - smaller components and DIB contractors at the shorter end, large multi-classification environments at the longer. Vendors promising six months for a federal customer are underestimating the complexity.
Resources. Expect the IT Officer at 25–50% over the deployment period, security team at 10–20% for ATO support, identity infrastructure team at 10–20% for federation work, and operational team at variable levels during migration. Total commitment typically lands between 1.5 and 3.0 FTE-equivalent. Vendors offering "minimal customer involvement" tend to produce deployments that are technically operational and operationally fragile.
Migration. Moving off existing infrastructure usually takes longer than standing up the new platform. Current VPN and jump server patterns serve real requirements, so phased migration preserves continuity while rip-and-replace produces predictable disruption.
Authorization. ATO activities run in parallel with technical deployment but on different timelines and with different stakeholders. Engaging the Authorizing Official in the first months rather than at the end produces faster acceptance - and prevents architectural decisions that complicate authorization later.
Adoption. After the initial transition friction, federal user satisfaction with ZTNA typically exceeds satisfaction with the VPN it replaced: single sign-on once per day instead of per-session reconnection, better performance away from headquarters, fewer access failures. The transition period needs change management; the steady state is generally positive.
How truePass fits
Reverse Access™ foundation. No inbound listeners on protected networks. The property satisfies FedRAMP SC-7 boundary protection and DoD Zero Trust Strategy pillar 3 structurally, through design rather than through configuration of compensating controls. Remote users connect through gateways that broker traffic; the systems behind them have no internet-facing attack surface.
Federal identity as a foundation, not an extension. PIV/CAC, DoD ICAM federation, derived credentials for mobile, and clean federation with partner identity providers for coalition access. CMMC AC family controls are satisfied architecturally rather than procedurally.
Gravity for IT-OT. Three integrated layers - Reverse Access™ for boundary protection, SMB proxy with Content Disarm & Reconstruction for content inspection, and Zero Trust application access for authenticated vendor sessions. IT-OT operates as platform functionality, so a military installation doesn't need a second procurement to cover it.
Frequently asked questions
How long does deployment take from award?
Typically 12–30 months to full operational capability. Smaller components and DIB contractors usually complete in 12–18; larger components with multi-classification requirements and complex authorization paths run 18–30.
What happens to the existing VPN?
It runs in parallel throughout. Users migrate in phased tranches by operational priority and risk, and the VPN is decommissioned only after the last population moves - a parallel period of roughly 6–18 months.
Which CMMC controls does ZTNA help satisfy?
Controls across the AC, AU, IA, SC, and SI families. Architecturally foundational platforms typically satisfy 30–50 individual controls through the deployment itself rather than through compensating procedural controls.
Does helpdesk burden go up or down?
Access-related tickets typically drop substantially once ZTNA replaces VPN, as VPN-specific failure modes disappear - connection failures, certificate issues, token problems, timeout disconnections. Expect a temporary increase during the 3–6 month migration window.
Next steps
Map your organization to the use cases - most federal organizations face several simultaneously, and the priority order shapes vendor selection. Draft the RFP around the six questions. Request architecture briefings where vendor architects address your specific cases, with diagrams and control mapping as standard deliverables. Run a proof of concept in a representative environment with two to four candidates over two to three months. And engage your Authorizing Official from the start of vendor selection rather than after award.
