From TIC 2.0 to Zero Trust: A Practical Roadmap to Modern SASE

The federal workforce has changed permanently. Hybrid work environments, cloud-based applications, and increasingly sophisticated threats mean that perimeter-based security simply cannot keep up. For federal agencies navigating this shift, Zero Trust Architecture is not a buzzword; it is a mandate.

The Cybersecurity and Infrastructure Security Agency's Trusted Internet Connections (TIC) 3.0 guidance, most recently expanded in its June 2026 publication on using Secure Access Service Edge (SASE) in a modern TIC 3.0 solution, lays out why legacy perimeter architectures no longer serve agency missions and what a modern replacement looks like. At Celestial Innovations Group, we help agencies put that guidance into practice.

We start with an agency's mission, existing infrastructure, and risk tolerance, then design a Zero Trust and SASE architecture around the capabilities that fit best, whether that means extending an agency's current toolset or introducing new ones.

Why Legacy Perimeter Architectures Fall Short

Most legacy agency architectures were built around the TIC 2.0 model, in which all inbound and outbound traffic is routed through TIC access points, whether agency-managed TIC Access Providers or vendor-managed Managed Trusted Internet Protocol Services (MTIPS). This model made sense when applications lived on premises, but it struggles under today's distributed, cloud-first workforce. CISA identifies three recurring challenges:

  • Poor performance: MTIPS backhaul increases contention and latency for remote and branch users

  • Legacy infrastructure: older and IoT systems often cannot integrate with modern security and Zero Trust controls

  • Legacy identity: on-premises identity solutions frequently lack phishing-resistant authentication, such as PIV or WebAuthn, and complicate cloud integration

How SASE Advances TIC 3.0 and Zero Trust

OMB Memorandum M-19-26 gave agencies flexibility to move away from routing all traffic through TIC access points, provided they maintain equivalent situational awareness for CISA. CISA's TIC 3.0 guidance formalized that flexibility, and its recent SASE guidance describes how a SASE framework can replace MTIPS while improving performance, visibility, and cost. A SASE framework combines networking and security capabilities into a unified edge, typically built from five core categories:

  • Zero Trust Network Access (ZTNA), which replaces legacy VPNs with granular, context-aware access to internal applications

  • Secure Web Gateway (SWG), which filters and monitors traffic to the open internet

  • Cloud Access Security Broker (CASB), which extends policy and visibility to SaaS and cloud application use

  • Next Generation Firewall (NGFW), which enforces application, user, and content aware policy at the network layer

  • Software-Defined Wide Area Networking (SD-WAN), which optimizes connectivity through dynamic, policy-driven routing

CIG's Approach to Zero Trust Modernization

Deploying Zero Trust in a federal environment is not a plug-and-play exercise. Agencies must navigate compliance requirements, legacy infrastructure, clearance considerations, and the need for minimal disruption to mission-critical operations. CIG maps each of the TIC 3.0 security capability groups, covering identity, network, data, and endpoint protection, to the combination of technologies that best fits an agency's environment. In practice, that means our teams are equally comfortable designing around a consolidated SASE platform or integrating best-of-breed tools an agency already owns.

Our teams work with agencies from initial architecture assessment through implementation and ongoing management: evaluating the current TIC 2.0 or MTIPS footprint, mapping mission and risk requirements, designing the security patterns CISA outlines for agency-to-campus, agency-to-web, and agency-to-cloud traffic, and planning a phased transition that accounts for legacy VPNs, operational technology environments, and devices that cannot support modern agents.

Maintaining Required Visibility with CISA

Replacing MTIPS does not remove an agency's obligation to share telemetry with CISA. In legacy architectures, that telemetry came from sensors at MTIPS or TIC access points. In a modernized architecture, agencies can meet the same requirement by routing relevant telemetry to CISA's Comprehensive Log Aggregation Warehouse (CLAW) and by integrating CISA's Protective DNS service through their chosen security edge. CIG builds this telemetry planning into every modernization engagement, so agencies stay compliant as they transition.

The Growing Role of AI in Zero Trust

CISA notes that full decryption and inspection of encrypted traffic is no longer universally recommended, given the complexity and latency it adds. Increasingly, agencies are turning to machine learning and other AI-driven methods to analyze encrypted traffic for anomalies and threats without full decryption. This is an area to watch across the SASE market broadly, and CIG evaluates each platform's AI and analytics capabilities as part of our assessment process for every agency engagement.

Aligned with Federal Zero Trust Guidance

A well-implemented SASE and Zero Trust architecture, supported by a knowledgeable systems integrator, gives agencies a direct path to compliance with the federal mandates shaping this space, including Executive Order 14028, OMB M-22-09's Federal Zero Trust Strategy, CISA's Zero Trust Maturity Model 2.0, and NIST Special Publication 800-207. Whether your agency is just beginning to evaluate its options or looking to accelerate an existing modernization effort, CIG's team is positioned to support your mission with the tools and architecture that make sense for your environment.

Reach out to learn more about what a Zero Trust and SASE modernization roadmap could look like for your agency.

Next
Next

CIG Gives Back: Investing in the DMV Community