CISA’s New Zero Trust Guidance Makes One Thing Clear: Identity Must Be Certain
CISA’s new report, The Journey to Zero Trust Using Secure Access Service Edge in a Modern TIC 3.0 Solution, is an important signal for every enterprise security leader. The federal government is moving away from the old perimeter security model. The model where you route every user through a VPN, inspect traffic at a central choke point, and assume that once someone successfully logs in, they can be trusted. That model no longer matches reality.
Employees work from anywhere. Applications live in the cloud. Sensitive data moves across SaaS platforms, private applications, mobile devices, and third party services. And attackers are no longer spending their time trying to break through a firewall. They are logging in with stolen credentials, phished push approvals, intercepted codes, manipulated recovery flows, and help desk resets.
CISA’s direction is clear. Security must become more dynamic, more distributed, and more aware of context.
Secure Access Service Edge, or SASE, provides an architecture for applying security policy closer to users, devices, applications, and data rather than relying on a static network perimeter. But there is a critical question behind every SASE or zero trust decision: How certain are you that the person requesting access is actually your employee? That is where most zero trust strategies still fail.
A SASE platform can evaluate device posture, geographic location, network context, application sensitivity, data classification, behavioral risk, and session activity. That is valuable. But if the person who authenticated is actually an attacker using a stolen password, a relayed MFA code, a phished authenticator approval, or a socially engineered help desk reset, then the platform is making a sophisticated access decision about the wrong person.
The entire zero trust architecture begins with a weak identity signal. That is exactly why Token belongs at the front of the zero trust conversation.
Zero Trust Is Only as Strong as Its Identity Signal
CISA’s guidance is not an endorsement of any specific vendor or product. It is a roadmap for moving beyond legacy, perimeter based security and toward policy driven access decisions that increase visibility, control, and resilience.
Token aligns directly with that model because Token provides the one signal that every SASE and zero trust platform needs most: high confidence that the human requesting access is the authorized human.
TokenCore Wearable, TokenCore Portable, and TokenCore Node are not simply another form of MFA. They are biometric assured identity devices designed to make authentication resistant to the attacks that defeat passwords, SMS codes, push notifications, and traditional authenticator apps every day.
Token uses phishing resistant FIDO2 authentication, secure hardware, live fingerprint verification, and cryptographic domain binding. The result is that access is not based on whether someone knows a password, receives a text message, taps approve on a push prompt, or convinces an IT help desk agent that they are an employee.
Access is based on proof. Proof that the device is the authorized device. Proof that the request is coming from the real application or domain. Proof that the authorized human is physically present and has provided a live biometric match. That is a fundamentally different model.
SASE Controls Access. Token Assures the Human.
SASE platforms are built to make smarter access decisions. They can determine whether a device is managed, patched, encrypted, compliant, or showing signs of compromise. They can limit access based on risk. They can protect data moving to and from cloud applications. They can inspect traffic and restrict access to sensitive systems.
Token makes those decisions trustworthy at the human identity layer. A managed laptop is important. But a managed laptop does not prove that the person sitting in front of it is the authorized employee. A compliant endpoint is important. But a compliant endpoint can still be used by an attacker who has convinced someone to approve a fraudulent login. A SASE policy engine is important. But it cannot fix an authentication system that accepts a stolen password or phished push notification as proof of identity.
Token closes that gap. The strongest modern security architecture combines both: The SASE platform evaluates the context of the access request. Token verifies the human behind the request.
That means organizations can make access decisions using the full picture:
-
Is the user authenticated through a trusted biometric device?
-
Is the device compliant and managed?
-
Is the user requesting access to a low risk SaaS application or a privileged cloud console?
-
Is the data sensitive?
-
Is the session behaving normally?
-
Is the application being accessed from the legitimate domain?
-
Should the user be allowed, restricted, required to step up authentication, or denied?
This is what real zero trust looks like.
Why Legacy MFA Cannot Support True Zero Trust
Many organizations believe they already have zero trust because they deployed MFA. That is not enough. SMS codes can be intercepted, relayed, or defeated through SIM swaps. Push notifications can be manipulated through MFA fatigue. Time based authenticator codes can be phished in real time. Recovery workflows and help desk resets can be socially engineered. Passwords can be stolen, reused, bought, or reset by an attacker who knows enough about the employee. These are not edge cases. They are now among the most common ways attackers gain access.
A phishing site can look exactly like a legitimate identity provider. An employee can enter their username and password. The attacker can relay the login flow in real time. The employee can then enter a one time code or approve a prompt, believing they are authenticating themselves. Instead, they have authenticated the attacker. That is not zero trust. That is trust with extra steps.
Token removes the shared secrets, codes, prompts, and judgments that attackers exploit. There is nothing meaningful to hand over on a fraudulent call. There is no six digit code to relay. There is no push request to approve. There is no password reset that gives an attacker the power to become the employee.
The Token device only authenticates after a live fingerprint match and only for the legitimate application origin for which the credential was created.
The Gold Standard for Human Identity in Zero Trust
The industry has spent years investing in better detection after attackers enter the network. Endpoint protection, SIEM tools, SOC teams, behavioral analytics, network monitoring, and incident response remain essential. But the best attacker to detect is the one who never gets in.
That is why Token is positioned to become the gold standard for identity within modern zero trust architectures. Not because Token replaces SASE. Because Token makes SASE stronger. Not because Token replaces endpoint security. Because Token ensures the endpoint is being used by the authorized human. Not because Token replaces identity providers. Because Token gives identity providers a much higher assurance authentication factor. And not because Token adds yet another layer of friction. Because it removes the friction of passwords, repeated codes, push prompts, and constant second guessing while giving enterprises a materially stronger basis for every access decision.
CISA’s new guidance is a reminder that the perimeter is no longer where trust should begin.
Trust should begin with identity. And identity should be more than a password, an approval, or a code. It should be biometric, cryptographically bound, phishing resistant, and physically tied to the authorized human.
That is biometric assured identity. That is Token.