“We are rolling out the red carpet for innovators who want to work with the War Department,” said Emil Michael, Under Secretary of War for Research and Engineering.
From foundation to an operating model
Federal agencies have spent years creating the technical building blocks for faster software delivery — establishing software factories, investing in DevSecOps platforms, experimenting with agile methodologies, and developing approaches for continuous authorization. The Washington conversation has shifted: the question is no longer whether agencies should adopt federal DevSecOps, but what it takes to make modern software delivery part of how government operates.
Department of War’s January 2026 overhaul
In January 2026 the Department of War (DoW) announced a major overhaul of its innovation ecosystem that illustrates this next stage. The department described a move toward a “unified and fast-moving innovation enterprise” focused on getting technology to the warfighter, and said it would organize innovation around technology, product, and operational capability. Emil Michael framed the change as simplifying industry access — “rolling out the red carpet” — and creating “a more direct path to move technology into the hands of the American warfighter.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleOrganizational barriers: acquisition, ATO, and pace
The source material highlights a persistent mismatch: modern development tools and practices cannot overcome organizational processes that operate at a slower pace. Technologies commonly associated with DevSecOps — containers, CI/CD pipelines, automated testing, security scanning, infrastructure automation — are necessary but not sufficient. A sophisticated development environment cannot accelerate delivery if acquisition takes years to approve a capability; a software factory cannot deliver operational value if products become trapped in lengthy Authority to Operate (ATO) and transition processes; and agile development loses much of its value if teams must define every detail before users can test a capability. The War Department’s overhaul explicitly emphasizes removing legacy barriers and creating stronger connections between operational problems, technology providers, and those responsible for transitioning capabilities into use.
Operational measures: mission outcomes, continuous authorization, and security
Speakers at the Carahsoft DevSecOps Conference argued that success must be measured by mission outcome rather than by compliance checkboxes or technology adoption metrics alone. Dave Raley, Chief Digital Services Officer who lead Operation StormBreaker for the Marine Corps, summarized that perspective: “The goal should be the mission outcome, securely and in compliance.” That formulation asks whether an organization can recognize a need, respond to it, learn from users, and sustain a capability in production — balancing speed with security, usability, adaptability, and sustainment.
The reporting also ties modern development practices to broader federal policy tools: continuous authorization and automated security can do more than streamline one program — they can create repeatable processes that reduce the need to rebuild governance and security workflows for each new capability.
What this means for technologists, procurement leaders, and mission owners
- Technologists and security teams: Expect emphasis on automation and continuous authorization as operating infrastructure rather than one-off demonstrations; CI/CD pipelines, automated testing, and security scanning must plug into persistent paths to production.
- Procurement and acquisition leaders: The DoW overhaul and conference conversations signal pressure to rethink acquisition timelines and governance so acquisition and oversight “enable rather than unnecessarily impede mission delivery.”
- Mission owners and industry vendors: The stated goal is a more direct path from technology to operational use — industry will be offered clearer access, while mission owners will be asked to evaluate modernization by whether capabilities improve operational results, not by pilot counts alone.
The change is not hypothetical. In an April interview with Federal News Network, then-Army CIO Leo Garciga described an Army continuous ATO pipeline that grew from supporting two simultaneous development efforts to 23, and that reduced one delivery cycle from roughly 30–45 days to about a week. That concrete example shows what the article’s authors and the conference participants mean by treating modern development environments as operational infrastructure: the metric is what mission owners can accomplish, not how many cutting-edge tools are in the stack.
The conversation at the Carahsoft DevSecOps Conference and the Department of War’s January announcement point to a clear test ahead: can agencies convert pilots and platforms into repeatable, governed, and secure operating models that consistently deliver mission outcomes? The shift from experimentation to operation is underway; whether it becomes the norm will turn on changes to acquisition, governance, and the day-to-day paths that carry code from developer workstations into operational use.




