2026 Top 10 Trends and Priorities for Government - Federal

Tailored Industry Research to Empower IT Leadership

Preview Another Industry

Industry-Centric Innovation and Transformation

View Our Research and Analyst Services

Stay ahead of cyber and post-quantum threats

The Challenge

Cyber incidents threaten mission continuity.

Federal agencies face relentless ransomware, credential theft, supply-chain, and AI-enabled attacks that prevention alone can't stop, so the real test is staying operational through a breach, not preventing every one. Compounding this, adversaries are already harvesting encrypted data to decrypt once quantum matures, making cyber resilience and quantum readiness two fronts of the same challenge.

Why It Matters

Resilience and quantum-readiness both sustain public trust.

Resilience is now codified direction, not best practice. Executive Order 14144 and the June 2025 cyber EO (EO 14306) demand continuous monitoring and rapid recovery against state threats. In parallel, NIST finalized post-quantum standards in 2024 and the National Security Agency's Commercial National Security Algorithm Suite (CNSA) 2.0 requires new National Security System acquisitions to support post-quantum cryptography (PQC) from 2027, with full migration by 2035 ("Announcing the Commercial National Security Algorithm Suite 2.0," NSA, 2025); because crypto transitions take years while "harvest now, decrypt later" exposure accrues today, both fronts demand action now.

The Solution

Modernize detection, response, and recovery.

Build out endpoint detection and response and a security operations center through the Cybersecurity and Infrastructure Security Agency's Continuous Diagnostics and Mitigation program, and meet Federal Information Security Modernization Act (FISMA) timelines for reporting incidents to CISA. Regularly test ransomware recovery against NIST SP 800-34, starting with the highest-value systems.

Reduce human-centered risk.

Enforce phishing-resistant multifactor authentication (MFA), personal identity verification/common access card (PIV/CAC) and FIDO2, and role-based security awareness training across the workforce.

Build quantum readiness.

Inventory cryptography starting with high-value assets using CISA and NIST post-quantum guidance, then migrate to NIST-standardized algorithms (ML-KEM, ML-DSA, SLH-DSA), sequenced to CNSA 2.0 (2027) and the National Security Memorandum 10 (NSM-10) 2035 migration deadline.

Back to Top

Deliver AI the public can trust

The Challenge

AI demand is outpacing governance.

Agencies are pushed to adopt AI for productivity and better services, but without guardrails that adoption creates security, fairness, and transparency risk. The constraint is no longer access to AI; it is the governance and discipline to deploy it responsibly at scale.

Why It Matters

Responsible adoption protects trust and effectiveness.

AI can sharpen service delivery and stretch scarce resources, but only with governance that protects trust, security, and accountability. Federal AI governance now has hard deadlines; the Office of Management and Budget (OMB) Memorandum M-25-21 (OMB, 2025) mandates chief AI officers, AI strategies, and risk practices for high-impact AI, so agencies that operationalize governance now will scale faster than those still standing it up.

The Solution

Prioritize high-value use cases.

Maintain the agency's public AI use case inventory and target mission uses with the highest ROI, with the chief AI officer steering selection.

Establish responsible AI guardrails.

Stand up an AI governance board and apply minimum risk practices for high-impact AI per OMB M-25-21, aligned to NIST's AI Risk Management Framework.

Prepare the workforce.

Train staff on safe AI use and acquire responsibly through General Services Administration (GSA) vehicles and OMB M-25-22 acquisition guidance.

Back to Top

Modernize mission-critical systems

The Challenge

Technical debt limits operational agility.

Aging systems and fragmented infrastructure make secure, reliable service delivery slower and costlier. Legacy is not just an IT expense, it is the ceiling on every modernization ambition, so it has to be tackled deliberately rather than deferred.

Why It Matters

Modern platforms enable better delivery.

Legacy systems drive cost, risk, and complexity, and block cloud, AI, and modern services. Modernization is the gating dependency for AI, zero trust, and shared services, and every deferred quarter compounds technical debt, where infrastructure modernization now ranks among federal CIOs' top priorities ("Federal CIO Forecast 2026," MeriTalk, 2025). Tackling the highest-risk systems first protects capacity for every other priority.

The Solution

Prioritize high-risk legacy systems.

Rank systems in the Federal Information Security Modernization Act (FISMA) inventory by mission criticality, security exposure, and technical debt, and pursue Technology Modernization Fund (TMF) support for the costliest.

Modernize without disruption.

Move in stages instead of all at once, shifting systems to Federal Risk and Authorization Management Program (FedRAMP), the authorized cloud allowing you to rebuild piece by piece, so mission-critical services never go down.

Align platforms to future needs.

Standardize on shared services and FedRAMP platforms that support AI, data sharing, and digital services rather than new silos.

Back to Top

Prove the value of every IT dollar

The Challenge

Cost pressure demands clearer accountability.

CIOs must cut costs while sustaining mission delivery, security, and modernization, yet overlapping applications, duplicative capabilities, and aging contracts drain resources when portfolio visibility is weak. In a flat budget, the advantage goes to those who can both prove where IT spend creates mission value and rationalize the portfolio to self-fund modernization.

Why It Matters

Spend discipline protects modernization capacity.

Doing more with less means steering scarce funding to what matters most, backed by cost transparency that defends investments. With 80% of federal CIOs under explicit savings mandates ("Federal CIO Forecast 2026," MeriTalk, 2025), those who can quantify IT cost-to-value keep their funding, while others face blunt cuts. Portfolio and vendor rationalization is the funding engine; cutting duplication and tracing decisions to federal mandates, FedRAMP, category management, and IT spend transparency, frees money to redirect toward modernization and security.

The Solution

Increase cost visibility and prioritize by value.

Apply the Technology Business Management (TBM) taxonomy and report through Capital Planning and Investment Control (CPIC) and the Federal IT Dashboard to expose duplication, and evaluate initiatives under Office of Management and Budget (OMB) Circular A-130 and the Federal Information Technology Acquisition Reform Act (FITARA) on risk, service impact, and total cost of ownership.

Rationalize applications and platforms.

Run FITARA-driven application rationalization using TBM/CPIC data, and consolidate via shared services; Quality Service Management Offices (QSMOs) and the Data Center Optimization Initiative (DCOI).

Strengthen vendor and contract management.

Consolidate spend through category management and General Services Administration (GSA) Best-in-Class vehicles with clear performance metrics.

Back to Top

Manage data as a strategic asset

The Challenge

Foundations and decisions both depend on trusted data.

Agencies cannot scale analytics, automation, AI, or digital services on siloed, poorly governed data. Even where data exists, they struggle to turn it into timely, measurable decisions. The gap is rarely closed with more data or dashboards; rather, it is the governance, architecture, and habits that make data usable and make leaders actually decide with it.

Why It Matters

Trustworthy data turns ambition into outcomes.

Strong foundations are the prerequisite for the AI ambitions in OMB Memorandum M-25-21. Agencies can't scale high-impact AI on siloed data. Once the foundation holds, data-driven decision-making lets agencies spot risks earlier, target resources, and measure outcomes; these problems recur across regulated industries, so proven patterns (data products, embedded analytics, self-service governance) can be adapted, and the Evidence Act and OMB performance mandates make it a compliance obligation, not just upside.

The Solution

Improve data quality and governance.

Empower the agency chief data officer and the data governance body to set ownership, standards, and stewardship for priority domains.

Integrate data across silos.

Modernize data architecture and interoperability under the Federal Data Strategy, on FedRAMP cloud platforms built for analytics and AI.

Turn data into decisions.

Tie analytics to Evidence Act learning agendas and Government Performance and Results Act (GPRA) goals, and embed data-driven reviews (GPRA Modernization Act), dashboards, and performance.gov metrics into operations to shift from retrospective reporting to proactive decisions.

Back to Top

Advance zero trust maturity across the federal enterprise

The Challenge

Perimeter-based security no longer fits.

With distributed users, cloud, contractors, and shared platforms, the network edge is gone, and implicit trust is a liability. Identity is the new perimeter, so security must verify continuously, and that same backbone can enable collaboration, not just lock it down.

Why It Matters

Continuous verification reduces exposure.

Zero trust replaces implicit trust with continuous verification across users, devices, networks, and data, limiting lateral movement and securing modernization. It is settled federal policy – Executive Order 14028 became the Federal Zero Trust Strategy, reaffirmed by EO 14144 with phishing-resistant multifactor authentication retained after the June 2025 EO, and the Cybersecurity and Infrastructure Security Agency's Jan 2025 report confirms agency implementation ("Zero Trust Architecture Implementation," CISA, 2025). The same identity and logging backbone, reinforced by OMB Memorandum M-26-14, also enables cross-agency collaboration, so frame zero trust as a mission enabler, not just a control.

The Solution

Prioritize identity and access controls.

Deploy identity, credential, and access management (ICAM) with personal identity verification/common access card (PIV/CAC) and phishing-resistant MFA, and use CISA's Continuous Diagnostics and Mitigation (CDM) program for identity and asset visibility.

Segment access and mature zero trust.

Apply least privilege and microsegmentation across the CISA Zero Trust Maturity Model pillars, sequencing work against the agency's M-22-09 zero trust implementation plan and reporting progress to OMB and CISA.

Enable secure cross-agency collaboration.

Use shared ICAM, access, and logging controls to support secure information sharing, tracing each to current policy (Federal Zero Trust Strategy, OMB M-22-09, reaffirmed by EO 14144).

Back to Top

Make every federal service simple, secure, and seamless

The Challenge

Legacy delivery slows public service.

The public expects fast, simple, accessible services, but fragmented delivery models and weak product practices hold agencies back. Government is now judged against commercial digital experiences, so delivery must reorganize around products and outcomes, with AI as the lever to close the gap.

Why It Matters

Better delivery improves public outcomes.

Modern digital delivery cuts friction, improves accessibility, and lifts transparency and accountability. The public benchmarks government against commercial experiences, and AI tooling is now mature enough to close the gap, so agencies that embed AI into service design now will outpace those treating AI as a separate track.

The Solution

Adopt product-centered delivery.

Organize around high-impact service providers and customer experience metrics under OMB Circular A-11 Section 280, funding persistent product teams over one-off projects.

Build modern, accessible services.

Standardize Agile/DevOps on shared platforms like Login.gov with modern continuous integration/continuous delivery, and build to Section 508 and the US Web Design System (USWDS) under the 21st Century Integrated Digital Experience Act (IDEA).

Use AI to modernize service delivery.

Apply AI such as virtual assistants, document processing, case triage, self-service, to cut wait times, governed per OMB M-25-21 using responsible AI guardrails.

Back to Top

Empower the federal cyber and IT workforce

The Challenge

Skills gaps constrain modernization.

IT teams must cover cyber, cloud, AI, data, and legacy work while competing for scarce talent. Talent, not technology, is the binding constraint on the whole agenda, so workforce planning is an execution risk to manage now.

Why It Matters

Modernization depends on people.

Agencies can't run secure, modern, AI-enabled services without the skills to operate and govern them; a stronger workforce raises execution capacity and cuts dependency risk. Every other priority – AI, zero trust, modernization, post-quantum – fails without talent, and OMB Memorandum M-25-21 directs agencies to build AI workforce capacity, making upskilling a near-term execution risk, not a long-term HR project.

The Solution

Identify critical capability gaps.

Map GS-2210 IT and cyber roles to the NICE Cybersecurity Workforce Framework to pinpoint gaps in cyber, cloud, data, and AI.

Invest in practical upskilling.

Use role-based training, certifications, and CIO Council and Office of Personnel Management (OPM) reskilling programs tied to priority initiatives.

Clarify roles and accountability.

Define FITARA, aligned responsibilities across CIO, CISO, CDO, and vendor teams to cut duplication and speed delivery.

Back to Top

Strengthen software and hardware supply chain risk management

The Challenge

Supply chain risk is inherited risk.

Agencies run on commercial off-the-shelf software and hardware, so a flaw or backdoor in a vendor's product becomes the agency's breach. With federal policy shifting from one-size-fits-all attestation to agency-owned risk decisions, the burden is now on each agency to know what is in its software and hardware and to judge whether it can be trusted.

Why It Matters

Accountability for supply chain security now sits with the agency.

Office of Management and Budget Memorandum M-26-05 rescinded the government-wide secure-software attestation mandate in favor of a risk-based approach, making each agency head responsible for assuring the software and hardware on its network. That raises the stakes on in-house capability. Agencies that can assess vendor security, demand software bills of materials (SBOMs) where risk warrants, and build to NIST's Secure Software Development Framework stay resilient, while those waiting for a federal checklist will be exposed.

The Solution

Maintain a software and hardware inventory.

Keep a complete inventory and, per OMB M-26-05, set software and hardware assurance policies matched to mission risk, requesting SBOMs from vendors where risk warrants.

Build to the NIST Secure Software Development Framework.

Express security expectations to vendors using NIST Special Publication 800-218, the Secure Software Development Framework (SSDF), and validate provider practices through a comprehensive risk assessment.

Manage third-party and supply chain risk.

Apply the CISA Cyber Supply Chain Risk Management (C-SCRM) approach and secure-by-design principles to vet suppliers and contain inherited risk.

Back to Top

Accelerate cloud adoption for speed and scale

The Challenge

Cloud is the foundation, but adoption has lagged.

Agencies need scalable, resilient infrastructure to run AI, data, and modern services, yet slow authorization, hybrid complexity, and rising cloud costs have held adoption back and locked value in legacy environments. The challenge is moving to cloud quickly without sacrificing security or overspending.

Why It Matters

Cloud authorization is finally moving at mission speed.

Office of Management and Budget Memorandum M-24-15 directed a modernization of the FedRAMP, and the GSA's FedRAMP 20x ("GSA Announces FedRAMP 20x," GSA, 2025) has cut cloud authorization from roughly a year to about five weeks, removing the historic blocker to adoption. Agencies that pair this faster onramp with a deliberate hybrid-cloud and cloud-cost management (FinOps) strategy will scale AI and digital services quickly, while those without one simply trade legacy lock-in for cloud sprawl and surprise bills.

The Solution

Accelerate through FedRAMP and FedRAMP 20x.

Adopt FedRAMP-authorized services and use the FedRAMP 20x automated path to authorize secure cloud in weeks rather than months.

Adopt a deliberate hybrid- and multi-cloud strategy.

Apply Cloud Smart principles and Trusted Internet Connections (TIC) 3.0 to place each workload where it best balances mission, security, and cost across on-premises and multiple clouds.

Control cloud cost and consumption.

Stand up cloud FinOps and use the Data Center Optimization Initiative (DCOI) to track spend, right-size workloads, and avoid lock-in and sprawl.

Back to Top

Testimonials

“The Women in Tech leadership course gave me a deeper understanding of what I’ve gone through as a woman in IT, including imposter syndrome and a lack of confidence."

Kristine Peluso, Section Chief Strategic Management & Communications, MTIO, Defense Health Agency

View Full Case Study
More Case Studies

Our People

Janice Clatterbuck headshot

Janice Clatterbuck

Executive Counselor

View Full Bio
Bryan Groden headshot

Bryan Groden

Executive Counselor

View Full Bio
Amanda Harrison headshot

Amanda Harrison

Executive Counselor

View Full Bio