TroutTrout

Reach DoD Zero Trust Target Level for OT. Without replacing a single device.

This guide maps DTM 25-003 to Access Gate, point by point. It covers all 7 DoD OT pillars, and no device is replaced.

Last updated:

The DoD is mandating Zero Trust across all OT systems

Under DTM 25-003, all DoD Components must reach Target Level Zero Trust across OT environments, including PLCs, SCADA, sensors, and legacy systems that cannot be patched or moved to the cloud.

Traditional IT security does not fit OT

The DoD guidance explicitly states that standard IT tools can be 'ineffective and potentially dangerous' in OT. Agents, scanners, and cloud enclaves disrupt safety-critical operations.

Legacy equipment is protected in place

OT environments put availability and safety above all. Security has to wrap existing assets without touching wiring, controllers, PLCs or HMIs: no updates, no agents, no downtime.

One appliance per site

Access Gate deploys a single appliance per site. It connects to your existing network and places a software-defined proxy in front of each OT asset. No network redesign. No downtime.

Why Trout

Built for OT Zero Trust from the start.

Every DoD OT-ZT pillar assumes the underlying infrastructure will remain unchanged. Trout's proxy-based architecture was designed from the ground up for exactly this constraint.

Proxy and SDN overlay

A software-defined overlay places a lightweight, identity-aware proxy in front of each OT asset. Zero changes to PLCs, HMIs, controllers, or switches.

No agents and no downtime

Access Gate connects to your existing network. All access (local, remote, contractor, OEM) passes through a Zero-Trust boundary without altering OT behavior.

Used in the defense industrial base

Runs in production environments with unpatchable, safety-critical systems. Defense contractors use it on the way to CMMC Level 2 and NIST 800-171.

DoD OT-ZT Pillars

One appliance covers all seven pillars.

Users

1. Users, Activities 1.1 to 1.9Access Gate ✓
DoD OT-ZT MandateTrout Capability
Identify all OT user accounts (1.1.1.OT)Identity gateway creates authoritative OT user and asset inventory
Enforce RBAC / least-privilege (1.2.2.OT)RBAC/ABAC enforced at the asset boundary, per task and port
Require MFA for OT access (1.3.1.OT)MFA enforced before any session initiation with OT assets
Control privileged accounts (1.4.x.OT)Privileged session broker with full recording and authorization
Manage contractor access (1.2.2.OT)Time-bound, identity-verified, fully audited contractor access
UNCLASSIFIED, PUBLIC RELEASE
Alignment Guide

Download the full DoD OT-ZT alignment guide.

Full point-by-point mapping of DTM 25-003 requirements to Trout Access Gate capabilities across all 7 Zero-Trust pillars. Unclassified, Public Release.

Done

What you'll find inside

Executive summary of DTM 25-003. Architecture overview of Trout Access Gate. Activity-by-activity mapping for all 7 pillars: Users, Devices, Applications, Data, Networks, Automation, and Visibility.

11 pages, Unclassified

Ready to assess your site?

Request a live demo to see how the Access Gate maps to your specific OT environment and accelerates your path to Target Level Zero Trust.

Request a demo
FAQ

Common questions about DoD OT Zero Trust.

7

DoD OT-ZT pillars, each with specific activities mandated by DTM 25-003, all covered by Trout Access Gate without disrupting operations.

DTM 25-003 is a DoD Directive-Type Memorandum issued in July 2025. It requires all DoD Components to reach Target Level Zero Trust across unclassified and classified systems, including Operational Technology (OT) environments. It defines 7 pillars and the specific activities each must address.

The DoD guidance explicitly states that traditional IT security approaches can be 'ineffective and potentially dangerous' in OT environments. OT systems put availability and safety first and rely on legacy industrial protocols. They cannot tolerate downtime, and often cannot run agents, be patched, or move to cloud enclaves.

Access Gate connects to your existing network and uses a software-defined networking (SDN) overlay. The overlay places a lightweight, identity-aware proxy in front of each OT asset. The underlying network stays unchanged: no rewiring, no recabling, no changes to PLCs, HMIs, or switches. All access then passes through a Zero-Trust enforcement boundary.

Yes. Trout Access Gate is fully on-premise and has no cloud dependency. Its policy engine runs locally, making it suitable for air-gapped, intermittently connected, and classified environments. No data leaves the site.

Access Gate is installed in a day per site. Once installed, it immediately starts building an asset inventory and enforcing access policies. The alignment guide documents which DoD activities are addressed out of the box and which require policy configuration.

DTM 25-003 directly mandates DoD Components. However, the same NIST 800-171 controls underpin CMMC Level 2, which defense contractors must meet to handle CUI. The 7-pillar framework provides a useful architecture reference for contractors preparing for CMMC assessments on OT environments.

Target Level is the baseline required by DTM 25-003. It covers the core activities within each pillar: identity verification, device inventory, network segmentation, data classification, and continuous monitoring. Advanced Level adds deeper capabilities like dynamic policy automation and behavioral analytics. Access Gate addresses Target Level across all 7 pillars.

Access Gate performs passive asset discovery to build a real-time inventory of every device on the network, including OT assets that cannot run agents or respond to active scans. This addresses Activities 2.1 through 2.7 without touching the devices. The overlay network then enforces deny-by-default access per device.

Yes. Access Gate generates session logs, policy configurations, segmentation baselines, and access control records that map directly to DTM 25-003 activities. Assessors can review who accessed what, when, through which protocol, and whether the session was authorized. All evidence is stored on-premise.

Access Gate runs a local policy engine that automates access decisions, alert generation, and configuration enforcement. Policies are version-controlled and can be deployed across multiple sites through the management plane. No cloud orchestration or external API calls are required.

The alignment guide is UNCLASSIFIED and publicly available. Access Gate itself operates in air-gapped, classified, and SCIF environments with no cloud dependency. Specific deployment guidance for classified networks is available through direct engagement with the Trout team.

Related hub

Zero Trust for OT networks

Architecture guides, protocol security whitepapers, comparison pages, and implementation resources for Zero Trust in OT environments.

Visit hub