CISA has expanded the Continuous Diagnostics and Mitigation (CDM) program to include Operational Technology (OT) and Internet of Things (IoT) assets. This marks a significant shift in federal cybersecurity, acknowledging that your network perimeter dissolved long before you finished mapping it.
This expansion impacts 92 federal agencies managing 3 million endpoints, with implications for every defense contractor and public-sector team grappling with asset visibility. Here's what changed, what it means, and how to prepare.
What Changed
In early 2024, CISA announced that the next CDM phase will incorporate OT and IoT assets. This is a mandatory expansion of the federal government's largest continuous monitoring program, driven by three key factors:
1. CDM's initial success revealed gaps. As agencies built dashboards for traditional IT assets, they discovered orphaned devices and unmanaged endpoints that didn't fit existing categories. These represent exploitable attack surfaces that adversaries are eager to target.
2. Threat actors shifted focus to critical infrastructure. The FBI warned in January about cyberattacks targeting U.S. critical infrastructure. Industrial control systems and connected medical devices are now at the intersection of national security and operational continuity.
3. Policy caught up to reality. The OMB's December 2023 FISMA reporting memo requires agencies to submit metrics by October 31, 2024, with a focus on zero trust architecture that includes all networked assets.
Key Findings
1. Non-traditional assets don't behave like IT endpoints. OT and IoT devices often run custom operating systems and lack support for traditional management tools. You can't manage what you can't instrument, and most OT/IoT can't be instrumented without disrupting operations.
2. Volume and longevity compound the challenge. Federal networks contain decades-old equipment designed for long lifespans. These assets outnumber IT endpoints and change infrequently, often remaining unaccounted for as cyber assets.
3. Data quality determines success. Expanding CDM's scope increases the volume of asset data agencies must track. Poor data quality can undermine zero trust architectures. Accurate asset inventories are essential for effective security policies.
4. Internet exposure creates immediate risk. Identifying high-risk OT/IoT assets with internet connectivity is a priority. Legacy systems weren't designed for hostile environments, and exposed systems represent significant vulnerabilities.
5. Accountability gaps persist across asset classes. Many organizations can't answer basic questions about non-traditional assets, hindering remediation and segmentation strategies.
What This Means for Your Team
If you're a defense contractor subject to CMMC or DFARS 252.204-7012, you're already required to maintain accurate asset inventories under NIST SP 800-171 control 3.4.1. The CDM expansion means federal assessors will scrutinize how you define "system components" and whether you exclude hard-to-manage OT/IoT assets.
For FedRAMP cloud service providers, the shared responsibility model now includes visibility into customer-deployed IoT devices. Your Customer Responsibility Matrix must address how customers will secure non-traditional endpoints.
Public-sector teams should anticipate similar expansions in StateRAMP requirements and state-level monitoring mandates. The federal CDM evolution sets a compliance baseline that state programs typically adopt within 18-24 months.
Action Items by Priority
Immediate (next 30 days):
Conduct a passive network discovery sweep to identify unmanaged OT/IoT assets. Use network traffic analysis to avoid disrupting operations. Document findings even if you can't immediately classify or secure them.
Inventory your current asset management tools and identify gaps in OT/IoT coverage. Evaluate platforms that provide unified visibility across IT, IoT, and OT.
Short-term (90 days):
Develop a risk-scoring framework considering asset type, network exposure, data sensitivity, and criticality. Prioritize assets based on this framework.
Implement network segmentation to isolate high-risk OT/IoT assets from IT networks. Create separate VLANs or zones for different systems to limit lateral movement.
Review your zero trust architecture plans to ensure they include non-traditional assets. Extend your strategy to include device identity and micro-segmentation for unmanaged assets.
Ongoing:
Assign responsibility for OT/IoT security to specific teams or individuals. Security gaps often persist between organizational boundaries.
Create a replacement roadmap for internet-exposed legacy systems that can't be secured. Plan for their replacement to mitigate perpetual risk.
Incorporate data quality checks into your asset inventory processes. Require metadata for each asset, including owner, function, network location, and last verification date.



