- CISA's Zero Trust Maturity Model requires phishing-resistant MFA to reach its Advanced stage, and OMB M-26-14, issued May 2026, ties agencies' logging maturity directly to their Zero Trust posture.
- Most federal Zero Trust investment goes into the network perimeter and the login event; almost none of it continuously verifies that the authenticated person is still physically present afterward.
- CAC and PIV cards are genuinely phishing-resistant at login, but nothing about the card verifies anyone is still at the terminal once it is out of the reader.
- Continuous, presence-aware authentication closes that specific gap and produces the per-session identity attribution OMB M-26-14's logging requirements call for, without requiring a rip-and-replace of existing CAC or PIV infrastructure.
CISA's Zero Trust Maturity Model names phishing-resistant MFA as a defining requirement of its Advanced stage, and federal agencies and contractors have spent years building toward it. What almost none of that investment addresses is what happens after the authenticated moment: a shared workstation at an agency site, left unlocked while the authorized user steps away.
This piece covers what CISA and OMB actually require right now, why CAC and PIV do not fully close the gap on their own, and what does.
What CISA and OMB Actually Require Right Now
Two live, current mandates set the bar: CISA's Zero Trust Maturity Model requires phishing-resistant MFA at its Advanced stage, and OMB M-26-14 requires agencies to reach Advanced logging maturity within 320 days of CISA's Logging Reference Architecture release.
CISA's model has four stages, Traditional, Initial, Advanced, and Optimal; there is no officially numbered "Level 3." Phishing-resistant MFA is a defining requirement of the Advanced stage. OMB M-26-14, issued May 22, 2026, rescinds the prior M-21-31 and ties an agency's logging maturity directly to its Zero Trust posture.
Both mandates build on earlier ones still in force: Executive Order 14028 and its implementing memo OMB M-22-09 name FIDO2/WebAuthn and PIV specifically as approved phishing-resistant authentication methods, and remain in effect as of this writing.
The Gap Zero Trust Mandates Do Not Close
Federal Zero Trust deployments concentrate heavily on network segmentation, ZTNA, and single sign-on at the perimeter and the login event, leaving the workstation itself, especially a shared one, without continuous verification afterward.
This falls hardest on federal contractors, who often work across multiple agency sites, courthouses, defense facilities, hospital systems, on shared workstations with no continuous confirmation that the authenticated user is still the person at the terminal. A contractor employee must satisfy this across several agency sites and compliance regimes at once, frequently without control over the agency's own infrastructure choices.
Why CAC and PIV Cards Do Not Fully Close the Gap
CAC login is a genuinely phishing-resistant, card-plus-PIN PKI challenge-response, but it verifies identity at the moment of login, not for the duration of the session that follows.
Mechanically, CAC login is Cryptographic Logon: the card's private key never leaves the chip, and the domain controller verifies the signed challenge against the certificate chain, which is why OMB M-22-09 names PIV and CAC alongside FIDO2/WebAuthn as approved phishing-resistant methods. Nothing about that mechanism verifies the person is still at the terminal once the card is out of the reader, which is the specific, post-login gap.
CAC remains the Department of War's primary credential, and a December 2025 CIO memo formally approves specific non-CAC login options only for narrow edge cases, new recruits pre-issuance, low-risk training environments for contractors without a CAC, reported as more than 20 approved use cases. The department is not moving away from CAC as the primary credential; the memo does not mandate phishing-resistant authenticators department-wide, though a separate congressional requirement calls for a phishing-resistant strategy briefing and the retirement of legacy phishable authenticators by the end of FY2027.
How Continuous Session Protection Closes the Gap Without Replacing CAC or PIV
Continuous, presence-aware authentication adds session-level verification on top of, not instead of, existing login-event controls, and produces the identity-attributed audit trail OMB M-26-14's logging mandate calls for.
Biometric plus XiFi Card authentication removes the password or phishable prompt from the workstation entirely, closing the exact gap most Zero Trust perimeter tooling leaves open: authenticated at login, unverified after. Continuous Session Protection ties the session to physical presence and locks it automatically when the user steps away, and because it is workstation-based, authentication is identical regardless of which agency site a contractor is working from, as long as the workstation meets hardware requirements and is enrolled.
Per-session identity attribution, verified user identity plus timestamps, supports the identity-attribution half of OMB M-26-14's logging-maturity requirement. Proximia integrates with existing Active Directory or Entra ID, with SAML-based application support confirmed live today, so there is no rip-and-replace of existing infrastructure, CAC and PIV included.
What This Means for Agencies and Contractors Now
With OMB M-26-14's logging deadline running from CISA's Logging Reference Architecture release, closing the session-persistence gap is current-cycle compliance work, not a future roadmap item.
Proximia supports the identity and authentication-layer requirements within a broader Authority to Operate package; it is not itself an ATO and should not be positioned as one. No named federal agency or contractor customer deployment exists yet; the current commercial motivation is an active outreach effort against major federal systems integrators, reflecting real, ongoing interest in closing this specific gap rather than an established federal track record to point to.
Ready to Close the Gap?
See how Proximia supports CISA's phishing-resistant MFA requirement and OMB M-26-14's logging maturity goals without replacing your CAC or PIV infrastructure. Schedule a demo at proximia.com/contact.
Frequently Asked Questions
Does this replace CAC or PIV cards?
No. It works alongside your existing CAC or PIV infrastructure, adding session-level verification after the login event those credentials already secure.
Does Proximia get us to an ATO?
It supports the identity and authentication-layer requirements within a broader ATO package; it is not itself an ATO.
Is Proximia FedRAMP certified?
FedRAMP is not a current certification. Proximia works with FedRAMP-accredited advisory partners and can pursue authorization if a specific procurement requires it.
Can this work across multiple agency sites for contractor staff?
Yes. Authentication is workstation-based, so it is identical regardless of physical location, as long as the workstation meets hardware requirements and is enrolled.
Does Proximia support SAML or OIDC-based applications for federal use?
Yes. Entra ID and Active Directory integration with SAML-based application support is confirmed live today, with OIDC-based application support also available through the same integration.




