Across every large-scale standardization effort I have observed, the most common pitfall is the one S3 exists to correct: solution and execution decisions made by people dozens of layers removed from the point of actual service delivery, with limited context, limited relevant experience, or both, substituting proxy concerns (compliance posture, political optics, budget optics) for the outcome itself. The result is technically defensible decisions that are operationally wrong.
Enterprise architecture illustrates the pattern. An enterprise architecture program is well suited to Horizon 1 and Horizon 2 work, where it creates shared understanding and a common vocabulary between leaders and delivery staff about known systems, teams, and structures. Applying an enterprise architecture decision-making structure to Horizon 3 is a different matter entirely. In my experience it pulls solution details upward into forums where leaders are asked to discuss and decide levels of detail they have neither the context nor the proximity to decide. The conversation feels rigorous, everyone leaves with action items, and the decision is wrong in ways no one in the room was positioned to see.
For the standards program, the Horizon 3 risk is concrete: standards written about technology that does not yet exist, by people who will never implement them, reviewed by people who will never operate them, imposed on people who were never asked. The mitigation is participation structure, not consultation process, and it is the responsive standards function described in S3: practitioners in active delivery hold the pen, federal staff are structured as enablers who clear barriers and publish results, and ratification follows working experiments at the speed those experiments move.