Trout Software's Access Gate v26.6 Brings Zero Trust Overlay to U.S. Water Utilities
Trout Software and Carahsoft released Access Gate v26.6 on August 25, 2026, targeting U.S. water and wastewater OT systems. The overlay enclave architecture blocks lateral movement from compromised workstations to PLCs and SCADA by default.
Water Utilities Get Zero Trust OT Segmentation Through Existing Federal Contracts
Trout Software and Carahsoft released Access Gate v26.6 on August 25, 2026, specifically built to bring zero trust-style protection to U.S. water and wastewater utilities. The product uses an overlay enclave architecture that segments OT assets so that a compromised workstation cannot move laterally to PLCs, HMIs, or SCADA systems without explicit policy permission. For municipal CISOs and OT leaders, this matters because it addresses the primary ransomware propagation vector in critical infrastructure without requiring a full network redesign.
The distribution strategy is what makes this announcement commercially significant. Access Gate v26.6 is available through NASA SEWP V contracts NNG15SC03B and NNG15SC27B, TIPS Contract 220105, OMNIA Partners Contract R240303, E&I Contract EI00063~2021MA, and The Quilt Master Service Agreement MSA05012019-F. This means municipal utilities and authorities can procure the product through existing contract vehicles, cutting procurement lead time from months to weeks and reallocating budget from bespoke network segmentation projects to an off-the-shelf product.
Competitive Positioning Against OT Security Incumbents
This puts Trout Software into direct competition with Zscaler's Zero Trust Exchange for OT and critical infrastructure, Palo Alto Networks' Prisma Access with IoT security, and Fortinet and Cisco's OT/ICS microsegmentation offerings. The differentiation is sector-specific packaging for water and wastewater plus turnkey public-sector procurement through Carahsoft, a dominant government IT distributor.
The overlay enclave approach differs from traditional network segmentation in one critical way: it assumes breach and enforces access policies at the application level rather than relying on perimeter controls. If a utility employee's workstation is compromised through phishing or credential theft, the attacker cannot pivot to SCADA systems because the enclave denies access by default. This aligns with the post-Colonial Pipeline and post-Oldsmar shift in OT security, where regulators and insurers now expect utilities to demonstrate lateral movement controls.
Budget and RFP Implications for Municipal Buyers
For CISOs at municipal utilities, this product changes the budget conversation in three ways. First, procurement through existing co-op contracts eliminates the need to run a full competitive bid process, which typically adds 6-12 months to deployment timelines. Second, the explicit policy-based access model gives utilities concrete evidence for regulators and boards that they are addressing post-incident ransomware propagation in OT environments. Third, buyers can now benchmark other vendors' OT segmentation proposals against an off-the-shelf alternative with transparent public-sector pricing.
Expect RFPs in water and critical infrastructure to start requiring overlay enclave architecture or equivalent as a baseline feature rather than a nice-to-have. Vendors that rely on traditional VLAN-based segmentation or perimeter firewalls will need to explain why their approach is superior to policy-based microsegmentation that assumes workstation compromise.
Zscaler and Cloudflare Expand Zero Trust Distribution in Adjacent Segments
Two other zero trust developments this week provide context for how vendors are competing for public-sector and emerging use cases. On August 18, 2026, Zscaler and Carahsoft expanded their partnership to deliver Zscaler's Zero Trust Exchange to SMB and mid-market customers in federal, state, and local government. This lowers procurement friction for smaller agencies and education institutions that previously found Zscaler too enterprise-centric, and it increases price pressure on Cloudflare One, Palo Alto Prisma Access, and Cisco Secure Access in mid-market public sector.
On August 5, 2026, Cloudflare launched an Identity-Aware AI Gateway that requires authenticated user identity on every AI request leaving enterprise networks, applying zero trust principles to LLM traffic. This competes with Microsoft's Entra and Defender for Cloud controls for AI and AccuKnox's Zero Trust Security platform for AI and APIs. For buyers evaluating AI governance, this means inline, identity-aware control for outbound AI traffic is now a procurement option rather than a build-it-yourself project.
What to Watch
Watch for Trout Software to expand Access Gate's sector-specific packaging to electric utilities, manufacturing, and other OT-heavy industries. If uptake is strong in water and wastewater, competitors will respond with their own pre-packaged OT enclave offerings through Carahsoft and similar distributors. For municipal buyers, the risk is that waiting too long means losing the current procurement advantage of established contract vehicles before competitors flood the same channels. The opportunity is that overlay enclave architecture is now a concrete alternative to expensive network redesign projects, with transparent public-sector pricing and fast procurement paths.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
