Skip to main content

CISA outlines TIC 3.0 approach using SASE and telemetry

In June 2026, CISA published guidance for using Secure Access Service Edge in a “modern TIC 3.0” solution, explicitly naming SASE as a compliant path away from the centralized gateway model and toward distributed enforcement with required telemetry.

Research Overview

The update traces policy changes from the Trusted Internet Connections (TIC) framework through OMB guidance that removed the mandatory routing requirement associated with TIC 2.0.

CISA positions TIC 3.0 as the operational implementation of that shift and describes SASE within the compliant approach agencies can follow.

Key Findings

CISA frames the central change as moving from prescribing where security controls must be deployed to prescribing what those controls must accomplish.

The guidance allows agencies to distribute enforcement across a cloud-delivered architecture, while requiring visibility and telemetry in accordance with specified logging levels.

Technical Breakdown

CISA says agencies should maintain continuous verification through elements such as identity and access controls, ongoing monitoring, and least-privilege enforcement.

The guidance also describes Transport Layer Security (TLS)/SSL break and inspect as “no longer a universally recommended solution,” citing encrypted-traffic analysis using AI and machine learning and the engineering complexity created by TLS 1.3, QUIC, and post-quantum cryptography-related developments.

Operational Impact

CISA’s telemetry requirement ties agency logging to CISA’s Comprehensive Log Aggregation (CLAW) destination, with the description that telemetry differs when traffic is not decrypted versus when it is.

Without decryption, the telemetry described focuses on source, destination, and bytes transferred, while decryption is described as enabling layer-7 context such as application, activity, identity, and context.

Conclusion

The vendor brief characterizes CISA’s TIC 3.0 guidance as a shift to distributed SASE-based enforcement with mandated visibility and logging to CLAW, while it highlights a contentious area around TLS break-and-inspect recommendations. Blog Signals brief is a fact-based summary of the vendor blog.

Source: netskope.com, by Venkat Sundaram.