Skip to content

Zero hour on Zero Trust: Unstructured data, and the race to protect government programs

Every year, the U.S. government needs to account for its spending.

In FY 2025, federal agencies reported an estimated $186 billion in improper payments across 64 programs — and that figure may be the lower limit. A 2024 analysis of federal spending suggests the government's fraud loss alone may range from $233 billion to $521 billion each year. The culprit isn't a lack of auditors or political will, but rather a data problem. Specifically, it's an unstructured data problem.

Think about where fraud and eligibility errors actually live. Not in database rows, but in the contract clause unparsed by IT systems…or the benefits form filled in by hand…or the PDF audit log never ingested or catalogued… or even the email chain that authorized a transaction your ERP indicates never happened. When your data governance only covers structured data, you're auditing just the exposed surface of the iceberg. The risk lives below the surface.

A mandate, not a suggestion

The federal government is pushing to reduce, and it has deadlines.

Office of Management and Budget (OMB) Memorandum M-22-09 set forth a federal Zero Trust architecture strategy, requiring agencies to meet specific cybersecurity standards and objectives to reinforce the government's defenses against increasingly sophisticated and persistent threats. For the Department of War (DoW) / (DoD) specifically, the mandate sets two firm milestones: all DoW components and supporting contractors must achieve Target Level Zero Trust by the end of Fiscal Year 2027, followed by a fully optimized Advanced Level by FY 2032.

The accountability is real. Organizations without Target Level certification by September 30, 2027, become ineligible for new DoW contract awards and cannot exercise options or extend existing periods of performance. This is not a grace period. It is a hard stop.

Zero Trust is framed in the DoD / DoW's own reference architecture and grounded in NIST 800-207: you cannot establish trust in a data asset you cannot see, classify, or verify. CMMC ties contractor certification to demonstrable data protection practices, which includes knowing sensitive information lives inside unstructured content. ASD STIGs mandate controls at the data layer. If your unstructured documents aren't catalogued and classified, you have a compliance gap — and auditors will find it.

The state government reckoning is coming, too

Federal agencies face statutory deadlines. State governments, for now, largely do not — but the pressure is compounding fast.

Analysts argued the success of the federal government's Zero Trust transition highlights the need for state and local mandates: "The strict deadline serves as a catalyst, compelling action and fostering a resilient cyber culture... This is something state and local governments must consider when fortifying for the future."

The logic is straightforward. States administer the programs where improper payment losses are most acute — Medicaid, SNAP, unemployment insurance, housing assistance. Medicare and Medicaid alone reported a combined $94 billion in improper payments in FY 2025. These are programs where eligibility decisions hinge on documents: case files, income verifications, provider credentialing records. Unstructured data, ungoverned.

States that wait for a federal mandate to begin governing their unstructured data are making a costly bet — that the window between "optional" and "required" will be long, and the cost of delay is lower than the cost of moving. History suggests the opposite.

Governing what you can't see

This is the core problem Collibra was built to solve. Collibra's data intelligence platform reaches beyond structured databases into contracts, PDFs, emails, and scanned documents — cataloguing, classifying, and making unstructured content governable at scale. That means agencies can answer the questions that matter: Where does sensitive data live? Can we trace a payment back to its authorizing documentation? Does our data posture meet the letter of Cybersecurity Maturity Model Certification (CMMC) and the spirit of Zero Trust? Have you reviewed the National Security Agency Cybersecurity Technical Report, Zero Trust Implementation Guidelines?”

The most significant transformation arising from the Zero Trust mandate goes beyond modernization of tools and tech to a profound shift in mindset and cultural adoption. The agencies and states that will win treat data governance as more than a compliance checkbox, and instead as the operational foundation of program integrity.

The FY 2027 deadline for federal agencies is fixed. The state-level reckoning is approaching. The question isn't whether to govern your unstructured data — it's whether you'll do it before the auditors arrive, or after.

***

Sources: U.S. GAO (GAO-26-108694, April 2026); Congressional Research Service (R48296, June 2026); OMB Memorandum M-22-09; DoD Zero Trust Strategy; GovTech / Lohrmann on Cybersecurity.

Keep up with the latest from Collibra

I would like to get updates about the latest Collibra content, events and more.

There has been an error, please try again

By submitting this form, I acknowledge that I may be contacted directly about my interest in Collibra's products and services. Please read Collibra's Privacy Policy.

Thanks for signing up

You'll begin receiving educational materials and invitations to network with our community soon.