TroutTrout
Back to Glossary
DTM 25-003DoD Zero TrustDefense industrial base

DTM 25-003

3 min read

DTM 25-003 is a Department of Defense Directive-Type Memorandum that operationalizes the DoD Zero Trust Strategy across the defense industrial base. It carries the zero-trust implementation targets published for DoD components in the 2022 DoD Zero Trust Strategy out to the contractors that handle CUI or connect to DoD networks.

What is DTM 25-003?

A Directive-Type Memorandum is how the DoD issues policy that needs to take effect before it can be folded into a formal, permanent directive. DTM 25-003 uses that mechanism to push zero trust past the DoD's own boundary and into the supply chain. Where CMMC tells a contractor which controls to implement, DTM 25-003 speaks to the architecture those controls should add up to.

What does DTM 25-003 require?

The memorandum frames contractor obligations against the seven pillars of the DoD Zero Trust Reference Architecture: User, Device, Application and Workload, Data, Network and Environment, Automation and Orchestration, and Visibility and Analytics. Each pillar has target-level and advanced-level capabilities on phased timelines. For contractors, the practical weight lands in three places:

  • Identity enforcement per session. Every access decision is made at request time from identity, device posture, and context, not granted once at network admission.
  • Encrypted and logged data flows. Transport is encrypted end to end where technically feasible, with session-level audit tying each access to an authenticated user.
  • Continuous verification. Authorization is re-evaluated during a session rather than trusted for its duration.

Who must comply with DTM 25-003?

Defense contractors and subcontractors that handle CUI or connect to DoD networks. It reaches the same population as CMMC Level 2, the Defense Industrial Base that already lives under DFARS and NIST SP 800-171, but it changes the emphasis from a checklist of controls to the shape of the architecture underneath them.

How does DTM 25-003 relate to CMMC?

They cover overlapping ground through different lenses. CMMC codifies the 110 NIST SP 800-171 Rev 2 controls with a C3PAO assessment gate. DTM 25-003 adds architectural expectations, zero-trust principles, session-level enforcement, and continuous verification, that shape how those controls are implemented.

The two can diverge. A contractor that meets the letter of CMMC with a VPN-based remote access model can still fall short of DTM 25-003's session-level verification. Conversely, a genuine zero-trust architecture that satisfies DTM 25-003 will usually clear CMMC's access-control minimums with room to spare.

What does DTM 25-003 mean for OT?

OT is where the memorandum's assumptions strain. Legacy controllers cannot produce device posture signals, cannot participate in continuous verification, and cannot terminate encrypted sessions. DTM 25-003's targets assume the enforcement point sits in front of the asset, not on it. That is why network-layer identity gateways and micro-DMZ designs show up so often in OT zero-trust work.

Access Gate provides session-level identity enforcement, encrypted transport, and continuous authorization in front of OT assets, which maps to the pillar objectives DTM 25-003 sets. See DoD Zero Trust OT Alignment.

Related terms