Skip to main content
Blog

The Zero Trust Bottleneck: Why Legacy Systems Are the Hardest Pillar to Fix

The Canton Group iconmark
The Canton Group

The Zero Trust Bottleneck: Why Legacy Systems Are the Hardest Pillar to Fix

Speak with a federal CIO about how their Zero Trust rollout is going, and the answer usually depends on which system you're asking about. Ask them about identity management, and you'll likely hear they've made real progress. Ask about the application still running on infrastructure older than most of the staff maintaining it, and that's where things tend to slow down.

A mandate that isn't going anywhere

Zero Trust vs Legacy System diagram and comparison graphic

Zero Trust replaces the old "trusted network" assumption with continuous verification: no user, device, or application receives automatic trust just because it's already inside the perimeter. For the federal government, this became a requirement under OMB Memorandum M-22-09, which set a deadline of the end of Fiscal Year 2024 for agencies to hit specific zero trust goals, organized around five areas the Cybersecurity and Infrastructure Security Agency (CISA) later built into a full maturity model: identity, devices, networks, applications and workloads, and data. FY2024 has since passed, but the mandate hasn't. Follow-up Office of Management and Budget (OMB) guidance, including M-24-14 and M-25-04, has kept Zero Trust maturity a federal budget and cybersecurity priority through FY2026, with Federal Information Security Modernization Act (FISMA) reporting still tracking agency progress against those original goals.

The progress is real, just uneven

CISA's own review of agency implementation found the strongest gains in identity, device, and network pillars, where agencies could draw on existing expertise and outside support. Data and applications and workloads have proven harder, since maturing those pillars means re-engineering development processes around DevSecOps principles rather than layering on new authentication tools. That gap isn't hypothetical or dated: a Government Accountability Office (GAO) audit released July 16, 2026 (GAO-26-107693) found the Federal Aviation Administration (FAA) had fully implemented only three of seven objectives in its cybersecurity strategy, and its zero-trust migration plan addressed just three of seven NIST-recommended transition practices, with no detailed plan at all for its research and development environment. GAO's conclusion was blunt: without applying Zero Trust across every operating environment, FAA can't be confident it's managing its risk. Even a well-resourced agency stalls when legacy environments and monitoring haven't caught up.

Where the bottleneck actually lives

A GAO report from July 2025 (GAO-25-107795) lays out the scale of the underlying problem. The federal government spends more than $100 billion annually on IT, and roughly 80 percent of that keeps existing systems running, some are over 50 years old. GAO reviewed 69 legacy systems and flagged 11 across 10 agencies as most critical, including systems at Health and Human Services and Treasury. The details behind that list are reviewing too: 8 of those 11 systems run on outdated programming languages, 7 carry known cybersecurity vulnerabilities, and 4 rely on hardware their manufacturers no longer support. Of the original 10 systems GAO flagged back in 2019, only 3 had been fully modernized as of February 2025. Four more were still years out, and 1 agency had no completion date established at all.

Annual federal IT spend

$100B+

Spent by the federal government on IT every year

Source: GAO-25-107795, Jul. 2025

Share spent on upkeep

80%

Of that budget just to keep existing systems running

Source: GAO-25-107795, Jul. 2025

Oldest critical systems

50+ years

Some flagged legacy systems have been in service this long

Source: GAO-25-107795, Jul. 2025

Modernizations completed

3 of 10

Of the GAO's originally flagged critical systems are fully modernized to date

Source: GAO-25-107795, Jul. 2025

Why you can't bolt Zero Trust onto legacy infrastructure

Zero Trust assumes technical flexibility which a lot of legacy systems simply don't have. Continuous authentication and real-time monitoring depend on systems built to support modern protocols, not decades-old mainframes running COBOL or Assembly. Closing that gap usually means one of a few paths: rehosting a system onto modern infrastructure with minimal changes, refactoring its code to work within a Zero Trust model, or rearchitecting it from the ground up when the underlying platform simply can't be adapted. None of those are quick, and all of them compete for the same shrinking pool of people who still understand these older languages much less touch them safely. Skip the work entirely and the whole architecture ends up only as strong as its least-verified piece, no matter how well the newer systems around it are secured.

Modernization and security are the same project now

Too many agencies still treat Zero Trust compliance and legacy modernization as separate line items competing for the same budget. In practice, they're the same project: a modernization effort that ignores Zero Trust will need revisiting within a few years, and a Zero Trust rollout that ignores the legacy systems underneath it hits a wall the moment it reaches data and applications. The agencies making durable progress are building modernization roadmaps that bake in identity-aware architecture from the start, often using phased, automated approaches rather than waiting on one monolithic rewrite.

This is also where a partner who's done this before truly matters. Understanding Zero Trust technically is one thing. Understanding how that work happens inside a federal agency, procurement cycles, oversight, legacy dependencies included, is another. The Canton Group has spent nearly three decades helping government agencies modernize the systems everyone assumes are too old or too entangled to touch. Zero Trust doesn't change that work. It just raises the stakes for getting it right.


Have questions about where to start with Zero Trust?

If your agency is trying to figure out where Zero Trust requirements and legacy modernization overlap, we're glad to talk through what's worked for other agencies navigating the same challenge.

Talk to The Canton Group →

Similar Insights

Interested? You may also like these.

Blog

Cloud adoption can transform government service, boosting agility, security, and citizen trust. But success takes more than technology. Our latest post explores the benefits, challenges, and key considerations for agencies making the…

The Canton Group iconmark
The Canton Group
Blog

Discover how Drupal is leading the way in security, accessibility, and cloud performance in 2025. Learn about its latest advancements in cybersecurity, digital inclusivity, and scalable cloud solutions—ensuring reliability for…

The Canton Group iconmark
The Canton Group
Blog

Drupal is a powerful foundation for government websites — but platform choice is only half the story. Long‑term success depends on strong planning, governance, and ongoing support. Learn why experienced strategy and program management…

The Canton Group iconmark
The Canton Group