ON2IT - Zero Trust Innovators

Select your region

Talk to us →
← Back to blog Zero Trust

The Framework the White House Chose

September 15, 2026 · 6 minutes read · By ON2IT

When the President's highest-level private-sector advisory body convened to define the United States federal government's cybersecurity strategy, they called one practitioner to brief the committee and cited one industry framework as the implementation standard. That practitioner was John Kindervag. The organisation listed next to his name was ON2IT BV.

Official Citation

“John Kindervag, ON2IT BV, ‘NSTAC ZT Briefing,’ Briefing to the NSTAC Zero Trust – Identity Management Subcommittee. Arlington, VA, September 8, 2021.”

Cited three times as the primary industry authority for the Five-Step Process, the Zero Trust Maturity Model, and implementation best practices. NSTAC Report to the President, Final Draft, Footnotes 29, 30, 31 and 33.

In Brief

What NSTAC is

The President's National Security Telecommunications Advisory Committee (NSTAC) is the highest-level private-sector advisory body on national security and communications in the United States. Its reports go directly to the President. Its membership includes the CEOs and senior executives of the most significant technology, defence, and infrastructure companies in the country. When NSTAC speaks, it speaks with presidential authority.

What ON2IT's role was

John Kindervag, during his tenure as ON2IT's Senior Vice President of Cybersecurity Strategy, was listed as both a Subcommittee Member and a Subject-Matter Expert Briefer. He briefed the committee as "John Kindervag, ON2IT BV." The Five-Step Process for Zero Trust Implementation, the Zero Trust Maturity Model, and the Kipling Method are all cited by name as "John Kindervag, ON2IT BV," the foundational industry references the committee used to define US government policy.

What the committee validated

The NSTAC's framework for measuring federal Zero Trust progress is built directly on the ON2IT five-step methodology. The committee recommended that every federal agency report progress using quantifiable metrics mapped to these five steps. The same maturity model, Kipling Method policy framework, and DAAS protect surface model that ON2IT uses in every client engagement became the official implementation standard recommended to the US President.

Why this is still relevant

The specific policy timelines in the report have passed. The validation has not. The Five Steps, the Maturity Model, the Kipling Method, none of these have changed. What the presidential advisory committee endorsed was not a product or a vendor preference. It was a methodology. ON2IT developed and operates that methodology. That endorsement is permanent.

What the NSTAC Is, and Why Its Endorsement Matters

The President's National Security Telecommunications Advisory Committee is not a think tank, a standards body, or an industry association. It is a federal advisory committee that reports directly to the President of the United States on matters of national security telecommunications. Its mandate covers the resilience of critical infrastructure, the security of national communications, and, since 2021, the cybersecurity transformation of the entire US federal government.

In May 2021, President Biden issued Executive Order 14028: Improving the Nation's Cybersecurity, directing the federal government to advance toward Zero Trust architectures. The NSTAC was tasked with conducting a multi-phase study to advise the President on how to do it. The result was a report addressed directly to the President, laying out the framework, the implementation methodology, the maturity metrics, and the governance structures the US government should adopt to execute this transformation.

The committee is composed of the senior executives of America's most significant technology, defence, telecommunications, and infrastructure organisations. AT&T, Palo Alto Networks, Amazon Web Services, Microsoft, Raytheon, Intel, Lumen Technologies, Broadcom: the subcommittee membership reads like the board of a national security council. These are not academics writing papers. These are practitioners and executives who have implemented Zero Trust at scale and are advising the US government at the highest level.

Signal

When the presidential advisory body on national security telecommunications defines the Zero Trust framework for the US federal government, it draws on a single industry practitioner's methodology. That practitioner was John Kindervag, then of ON2IT BV, Arlington, VA, September 8, 2021.

How ON2IT's Framework Became the Federal Standard

The NSTAC report's Section 2, "Industry Standards and Best Practices for Zero Trust Implementation," is the section that defines what best practice looks like. It is the section that federal agencies are instructed to reference when designing their Zero Trust programmes. And it cites ON2IT's framework, via Kindervag's briefing, as the definitive source, not once, but three times in a single section.

Citation 1 · Five-Step Process for Zero Trust Implementation

"The Five-Step Process for Zero Trust Implementation," cited as the foundational methodology for federal Zero Trust deployment, with all five steps and their quantifiable progress metrics sourced directly from: "John Kindervag, ON2IT BV, 'NSTAC ZT Briefing,' Briefing to the NSTAC Zero Trust – Identity Management Subcommittee. Arlington, VA, September 8, 2021."

NSTAC Report, Final Draft, Footnotes 29, 30, 31

Citation 2 · Zero Trust Maturity Model

The Zero Trust Maturity Model reproduced in Appendix A of the Presidential report, a five-level framework (Initial through Optimised) mapped to all five implementation steps, is sourced from: "John Kindervag, ON2IT BV, 'NSTAC ZT Briefing,' Briefing to the NSTAC Zero Trust – Identity Management Subcommittee. Arlington, VA, September 8, 2021." This maturity model is what the committee recommended federal agencies use to measure their progress.

NSTAC Report, Final Draft, Footnote 33, Appendix A

Citation 3 · Subcommittee Membership and Briefers

John Kindervag appears in two formal tables in the report. In Table 10: Subcommittee Membership, he is listed as "Mr. John Kindervag · ON2IT BV." In Table 11: Briefers, Subject-Matter Experts, he is again listed as "Mr. John Kindervag · ON2IT BV." He is one of only two individuals who appear in both the membership and the briefers table, making him simultaneously an insider and the primary expert witness on Zero Trust practice.

NSTAC Report, Final Draft, Appendix C, Tables 10 and 11

Signal

Three formal citations. Two official tables. One organisation listed against the creator of Zero Trust, at the moment the US government defined its national cybersecurity transformation standard. That organisation was ON2IT BV.

The Framework That Was Endorsed, and That ON2IT Still Uses

The methodology the NSTAC recommended to the President is identical to the methodology ON2IT uses in every client engagement today. It has not been revised or replaced. The Five Steps, the DAAS framework, the Kipling Method, and the five-level maturity model are the same in the Presidential advisory report as they are in every ON2IT implementation guide, hospital brief, and management guide in this hub.

1

Define the Protect Surface

Identify the DAAS elements, Data, Applications, Assets, Services, to protect. Federal metric: total DAAS elements on the agency Zero Trust roadmap.

2

Map the Transaction Flows

Understand how traffic moves to and from the protect surface. Federal metric: percentage of instrumented and validated traffic flows as a function of total flows.

3

Build a Zero Trust Architecture

Design the architecture tailored to the protect surface. Each architecture is unique. Federal metric: percentage of DAAS elements that an enforcement point protects.

4

Create Zero Trust Policy

Layer 7 policy using the Kipling Method: Who, What, When, Where, Why, How. Federal metric: percentage of DAAS elements that a defined Zero Trust policy protects.

5

Monitor and Maintain the Network

Inspect and log all traffic through Layer 7. The NSTAC added a sixth principle alongside the five steps: commit to transparency and continuous improvement, publicly documenting successes and lessons learned. Federal metric: month-over-month true and false positive percentages for security incidents in Zero Trust deployments.

Architect signal

The same maturity model the US federal government uses to report Zero Trust progress to the President is the model ON2IT uses to assess client environments. The terminology is identical, Initial, Repeatable, Defined, Managed, Optimised, because the model came from the same source.

What This Means for Your Organisation

The NSTAC report's central conclusion is relevant far beyond the US federal government. The committee found that Zero Trust is not just a technical upgrade, it is a cultural and strategic transformation that must be embedded at the highest levels of an organisation and measured on a decade-long horizon.

Most importantly for any board or executive team evaluating their security strategy: the NSTAC found that the single greatest risk is not starting Zero Trust, it is starting without a coherent methodology and measuring progress with the wrong metrics.

NSTAC Key Conclusion

Without additional significant action beyond tactical checklists, organisations risk Zero Trust becoming an incomplete experiment, a collection of disjointed technical security projects measured in years, rather than the foundation of an enduring, coherent, and transformative strategy measured in decades. To realise Zero Trust as a true strategy that meaningfully transforms cybersecurity outcomes, leaders must take a series of actions to institutionalise a culture of Zero Trust. Zero Trust principles must be fully integrated into existing governance structures, policies, and programmes, not viewed as a standalone initiative.

NSTAC Report to the President, Summary of Key Conclusions (paraphrased)

The warning applies equally in the private sector. The organisations that have implemented Zero Trust as a checklist of technical projects, MFA here, network segmentation there, are not implementing Zero Trust. They are implementing components of a perimeter-hardening strategy with Zero Trust branding. The presidential advisory committee was explicit: the strategy must be measured in decades, embedded in governance, and anchored to a rigorous and consistent methodology.

That methodology, the one the committee chose, is the same methodology ON2IT has operated since 2005. Not because ON2IT lobbied for inclusion, but because when the US government's highest advisory body on national security needed to identify the industry's best practice standard, the answer was the same framework it has always been.

NSTAC on Governance

“Zero trust principles must be cemented into the core of existing and new federal governance structures, policies, and programmes. As organisations adopt new technologies, modernise systems, and adopt new security policies, Zero Trust needs to be a central tenet for managing cybersecurity risk.”

NSTAC Report to the President (paraphrased)

The Numbers That Frame the NSTAC Endorsement

Citations

ON2IT's framework cited in the Presidential advisory report as the primary industry authority for Zero Trust implementation.

2
Official tables

NSTAC tables listing ON2IT BV: Subcommittee Membership and Subject-Matter Expert Briefers.

24
Recommendations

Formal recommendations the committee made to the President, all anchored to the ON2IT five-step methodology and maturity model.

5
Implementation steps

The same five ON2IT uses in every client engagement, now the official US federal Zero Trust standard.

2005
Founding year

Year ON2IT began operating Zero Trust-based managed security, before most organisations had heard the term.

10+
Year horizon

Years the NSTAC recommended as the horizon for Zero Trust transformation: a decade-long strategy, not a technical project.

The Same Framework. The Same Standard. Available to Your Organisation.

The President's National Security Telecommunications Advisory Committee made 24 recommendations to the President of the United States on how to transform US government cybersecurity through Zero Trust. Every one of those recommendations is built on a single implementation framework, the Five-Step Process, the Maturity Model, the Kipling Method, the DAAS protect surface model, that John Kindervag developed and that ON2IT has operated since 2005.

John Kindervag has since moved on from ON2IT. The framework has not. The methodology, the tools, the operational practice, and the twenty years of implementation experience remain at ON2IT. The NSTAC report is a historical document. The endorsement it contains is not.

When the US government needed to define how to secure its most sensitive systems, military, intelligence, civilian, it chose a methodology. Your organisation can choose the same one.

Get in touch

Ask your own security partner whose methodology they run.

If the answer is vague, that is the answer. ON2IT will walk you through the same five-step framework the NSTAC cited to the President, and show you exactly how it maps to your environment.

Talk to ON2IT

Sources

  • NSTAC Report to the President: Zero Trust and Trusted Identity Management, President's National Security Telecommunications Advisory Committee, United States Government.
  • John Kindervag, ON2IT BV, listed as Subcommittee Member and Subject-Matter Expert Briefer. NSTAC Report, Appendix C, Tables 10 and 11.
  • Executive Order 14028, Improving the Nation's Cybersecurity, The White House, May 2021.

FAQ

What is the NSTAC?

The National Security Telecommunications Advisory Committee is the President's highest-level private-sector advisory body on national security and communications. Its reports go directly to the President, and its membership is drawn from the senior ranks of companies including AT&T, Palo Alto Networks, Amazon Web Services, Microsoft, and Intel.

What did the NSTAC recommend on Zero Trust?

Following Executive Order 14028, the NSTAC's report to the President made 24 recommendations for federal Zero Trust adoption, built on a five-step implementation process and a five-level maturity model, both sourced from a briefing credited to John Kindervag, ON2IT BV.

Is the framework the NSTAC cited still relevant?

Yes. The specific federal timelines in the report have passed, but what the committee endorsed was a methodology, not a product or a deadline. The five steps, the DAAS protect surface model, the Kipling Method, and the maturity model are unchanged, and ON2IT has operated them in client engagements since 2005.

Does John Kindervag still work at ON2IT?

No, Kindervag has since moved on from ON2IT. The framework he built and briefed to the NSTAC in 2021 remains: ON2IT continues to operate the same methodology, tools, and maturity model in every client engagement.

Zero TrustNSTACJohn Kindervag