software Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/software/ Breaking news about the market for products, systems and services for the U.S. intelligence community Sun, 12 Apr 2026 20:48:58 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg software Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/software/ 32 32 59882712 Who Builds the Mission Now? How the IC Is Expanding the Definition of a Developer https://intelligencecommunitynews.com/ic-insiders-who-builds-the-mission-now-how-the-ic-is-expanding-the-definition-of-a-developer/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-who-builds-the-mission-now-how-the-ic-is-expanding-the-definition-of-a-developer Sun, 12 Apr 2026 20:48:58 +0000 https://intelligencecommunitynews.com/?p=44313 From IC Insider Coder By Austen Bruhn, Staff Solutions Engineer — US Public Sector at Coder The hardest problems in...

The post Who Builds the Mission Now? How the IC Is Expanding the Definition of a Developer appeared first on Intelligence Community News.

]]>
From IC Insider Coder

By Austen Bruhn, Staff Solutions Engineer — US Public Sector at Coder

The hardest problems in IC software development in 2026 are not technical. They are organizational – it’s the challenge of overcoming mission knowledge gaps between the people who understand the problem and the people who can actually solve it.

The person who best understands a mission gap — the all-source analyst who has spent five years tracking a specific threat actor, the SIGINT specialist who recognizes patterns invisible to anyone outside their collection account — is rarely the person positioned to act on it. That knowledge gets translated into a requirement. That knowledge gets written down as a requirement, then turned into a statement of work and, ultimately, that becomes a contract. Somewhere in that chain, irreplaceable operational insight loses most of its fidelity.

This bottleneck rarely makes it into conversations about IC modernization. Infrastructure debt does. Talent retention does. Procurement timelines do. But the gap between the people who understand the mission and the people authorized to build tools for it is at least as consequential as any of those. And it’s been widening while the rest of the conversation moved on.

A new kind of builder is emerging

The conversation is starting to shift. CDAOs at major defense primes are investing in citizen developer programs — training analysts, logisticians, and specialists to build workflows, notebooks, and data transformations without traditional coding backgrounds. The Marine Corps Chief AI Officer has pushed for models where operators contribute directly to the tools they use in the field, rather than filing requirements and waiting. Gartner estimates that citizen developers now significantly outnumber professional developers in large enterprises, and the ratio is still moving even in the Defense Industrial Base (DIB).

What’s making this realistic rather than aspirational is the state of AI-assisted development. The DoD’s own Chief Digital and AI Office acknowledged in a February 2026 solicitation that its software development workforce “currently lacks standardized, enterprise-wide access to AI-enabled coding tools that are commonplace in the commercial sector,” and that the gap “limits developer productivity [and] slows the delivery of mission-critical software.” That gap is exactly the opportunity. An analyst who can describe a problem clearly, evaluate whether a proposed solution makes sense, and iterate is someone who can build useful things today in a way they couldn’t before. The underlying technical knowledge required has dropped significantly. The domain expertise those analysts already carry has not.

What this looks like on the mission

Take an OSINT analyst who has identified a gap in how the community is processing a new collection source.

Under the model most programs still operate on, that insight gets written down as a requirement. It gets reviewed, prioritized, and eventually turned into a statement of work or added to an existing program. Months later—sometimes longer—there’s a tool. Whether it still fits the original need is a separate question.

The alternative looks different.

That same analyst opens a compliant development environment, selects a template aligned to their data stack, and starts prototyping. An AI coding assistant helps fill in the gaps where they don’t have deep engineering experience. Within a few days, something is testable. Within a week, it’s shareable.
The key difference isn’t just speed. It’s fidelity. The person who understood the problem is still the one shaping the solution.

DoD’s Advana platform—a centralized, CAC-enabled data and analytics environment—has already shown what happens when that barrier is removed. Analysts can access data, build workflows, and share useful outputs without standing up a program first.

The opportunity for the IC is extending that model beyond analytics into broader development, so domain experts can do more than analyze data. They can build the tools they need, when they need them.

The infrastructure problem underneath all of this

None of it happens if standing up a compliant workspace takes two weeks or longer.

That’s the constraint that kills citizen developer initiatives before they start. When provisioning access to a development workspace still means navigating approvals, provisioning steps, and configuration work that only a handful of people understand, the friction is high enough that only few engineers bother. Domain experts who might prototype something valuable just don’t. The opportunity cost is invisible, so it doesn’t show up in any program’s risk register.

There are also constraints that don’t go away: accreditation boundaries, ATOs, and networks that weren’t designed for rapid iteration. Those are real, and they shape what’s possible.

Platform engineering addresses this at the source. Small, focused platform teams define what compliant development looks like, build it into self-service templates, and let anyone with access spin up a workspace in minutes — pre-configured, policy-compliant, ready to go. Workspace infrastructure is defined as code. Security controls are built in rather than added after the fact. The same template that works on an unclassified network works identically on a classified one, in an air-gapped facility, without asking the builder to re-platform when they change networks.

That last point matters more than it might sound. A senior analyst willing to try building something shouldn’t have to become a system administrator first. The infrastructure either gets out of the way or it doesn’t.

Security as the floor, not the door

The compliance model most programs inherited treats security as a gate: something you pass through at the beginning or prove at the end. That made sense when developers were a small, specialized population that could be managed through access controls and vetting processes.

It breaks down when the goal is to expand who builds. You can’t selectively enforce compliance based on whether someone has a traditional development background. What you can do is move the enforcement into the platform itself. Toolchain access is defined before anyone writes a line of code, audit logs are generated automatically, and policy is traveling with the workspace rather than depending on individuals to follow procedures correctly every time.

In a platform model, the controls are defined once and enforced everywhere. NIST’s Secure Software Development Framework (SSDF) has been making this argument at the policy level for years: security should be continuous and integrated, not a final checkpoint. Platform engineering is how that principle becomes operational reality. When compliance is built into the platform, it stops being the mechanism that determines who gets to start building.

What the IC actually stands to gain

The agencies that figure out how to turn domain expertise into repeatable, shareable capability will have something that can’t be easily replicated by competitors or contractors. The analyst who developed a novel approach to a collection problem retires, and under the current model, that approach retires with them — maybe preserved in a report, maybe not. A Science study published in early 2026 found that productivity gains from AI-assisted coding were sharpest among experienced practitioners — not junior developers. The IC’s senior analysts, operators, and specialists are exactly that population.

When those people can build tools that encode what they know, expertise becomes institutional rather than individual. An analyst’s data transformation becomes a template. A targeting workflow becomes a starting point for the next team. The distance between having an idea and building something useful around it starts to compress.

The competitive pressure here is real. Near-peer adversaries are moving aggressively to apply AI to their own software development and autonomous operations. The IC’s response can’t just be better infrastructure for the engineers it already has. It needs infrastructure that expands who gets to build, and that starts with ensuring the people who understand the mission are the ones shaping the tools.

The IC’s advantage will belong to the organizations that stop separating those two groups at all.

Austen Bruhn is a Staff Solutions Engineer for the US Public Sector at Coder, where he works with government and defense programs on secure, compliant development infrastructure across classification levels.

Coder is the AI software development company leading the future of autonomous coding. Coder helps teams build fast, stay secure, and scale with control by combining AI coding agents and human developers in one trusted workspace. Learn more at coder.com.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Who Builds the Mission Now? How the IC Is Expanding the Definition of a Developer appeared first on Intelligence Community News.

]]>
44313
The Software Factory Is Dead, Long Live the Software Factory https://intelligencecommunitynews.com/ic-insiders-the-software-factory-is-dead-long-live-the-software-factory/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-the-software-factory-is-dead-long-live-the-software-factory Mon, 09 Mar 2026 12:52:55 +0000 https://intelligencecommunitynews.com/?p=44022 From IC Insider Coder By Amanda Phelps, Head of Global Public Sector Partnerships and Alliances at Coder I have watched...

The post The Software Factory Is Dead, Long Live the Software Factory appeared first on Intelligence Community News.

]]>
From IC Insider Coder

By Amanda Phelps, Head of Global Public Sector Partnerships and Alliances at Coder

I have watched talented government and defense teams pour years of effort into software factories, and watched those same factories quietly become the thing slowing development down. That is not a failure of the people who built them. It is a signal that the model has run its course.

For the past decade, “software factory” has been the defining concept of digital transformation across the Department of Defense and the Intelligence Community. Initiatives like Platform One, Kessel Run, Black Pearl, and Kobayashi Maru proved that modern DevSecOps could work in sensitive environments, that containers could survive an ATO, and that developers did not need to wait months for infrastructure. Those teams deserve every bit of credit they receive.

But the model they pioneered is now collapsing under its own weight. The factories we built were cathedrals. What the mission needs now is something more flexible, like a framework.

The untenable cost of the monolith

The original software factories had to be centralized and monolithic. Kubernetes was not yet authorized. CI/CD pipelines could not yet satisfy NIST 800-53 controls. GitOps was unproven at the classification boundary. Early adopters bore enormous compliance burdens just to establish that modern development was possible in secure environments at all.

The fundamental problem is that monolithic factories try to be everything to everyone. A single factory is expected to serve programs building web applications and programs training machine learning models, teams operating in the cloud and teams in air-gapped facilities, experienced engineers and teams encountering modern development for the first time. That breadth creates impossible tradeoffs. Make the factory standardized and you alienate programs with specialized requirements. Make it flexible and you drown in configuration complexity until the factory itself becomes the bottleneck.

These factories also became single points of failure. When key personnel leave, institutional knowledge walks out with them. Platform teams get consumed by access requests, exception handling, and organizational overhead. The infrastructure meant to accelerate delivery starts slowing it down.

A maturing commercial ecosystem changes the calculus

What changed is that commercial technology matured in ways government-built factories cannot match.

Purpose-built infrastructure automation tools now treat cluster provisioning, configuration management, and infrastructure-as-code as solved problems. Declarative approaches — defining the desired state and letting automation handle the realization — enable agencies to enforce discrete access controls, reduce insider risk, and remove human error from provisioning. These capabilities are core to the tools, not incidental to them.

For the developer experience specifically, the shift has been equally significant. Secure, cloud-based development environments address one of the most persistent pain points in classified software development: standing up a compliant workstation and becoming productive. Developers in air-gapped facilities typically wait days, and weeks or months are not uncommon, for properly configured systems. Modern development environments can be provisioned in minutes from an approved template, with security controls built in rather than bolted on. Coder provides this capability for IC and DoD programs — teams define workspace infrastructure as code, enforce policy at the platform level, and support everything from unclassified development through classified and disconnected environments without changing the developer workflow.

This approach also shifts the maintenance burden from overworked government platform teams to vendors with engineering resources, SLAs, and dedicated security response. When something breaks, you open a ticket rather than lose months of capability development while someone reconstructs a Kubernetes cluster from memory.

Platform engineering: Smaller teams, greater scale

The successor to the software factory is not another factory. It is a platform engineering model where small, focused teams curate technology choices and define integration patterns rather than building and operating infrastructure from scratch.

This distinction matters enormously for the IC because the scalability problem that killed monolithic factories came down to headcount. When every program office queues behind a central platform team, scaling means hiring more government employees — slow, expensive, and constrained by hiring authorities that often have little relationship with the pace of mission need. When programs consume infrastructure through self-service catalogs built on proven commercial technology, scaling becomes a software problem. That is solvable.

In this model, platform teams do three things well:

  1. Define what compliant deployment looks like
  2. Curate the approved components that programs draw from, and
  3. Provide self-service interfaces that let development teams operate within security guardrails without creating a ticket for every resource request

 

The result is portable compliance. A workspace template that meets security requirements in an unclassified environment should work the same way on a classified network and function without modification in an air-gapped facility. Policy travels with the infrastructure.

The cross-domain problem

For the IC specifically, the platform engineering transition carries an additional imperative that defense-focused discussions tend to overlook: cross-domain development.

A developer supporting a program that spans multiple classification levels does not simply move between environments. They context-switch between different physical machines, credential sets, toolchains, and organizational processes. Work products moving between domains pass through transfer processes measured in hours or days. Managing cross-domain workflows has historically required dedicated personnel whose primary function is shepherding data across boundaries rather than building capability.

Platform engineering changes this. When development environments are defined as code and centrally managed, it becomes possible to maintain consistent toolchains and security baselines across classification levels while preserving the hard separations that protect sources, methods, and program equities. A developer’s workspace on the low side and their workspace on the high side can be structurally identical. Cross-domain transfer processes can integrate into the development workflow rather than function as afterthoughts. The compliance burden shifts from individuals performing manual procedures to the platform enforcing those procedures automatically.

IC programs are already deploying remote development infrastructure that spans classification boundaries with consistent policy enforcement and without asking developers to re-platform every time they change networks.

The democratization of building

Here is where this transition becomes genuinely transformative — and where the IC has a specific advantage to capture.

The IC has always had a large population of domain experts who are not software developers but who possess operational knowledge no development team can fully replicate. All-source analysts who understand threat actor behavior in ways that cannot be captured in a requirements ticket. SIGINT specialists who recognize patterns in data only visible through years of operational exposure. Collection managers who understand source constraints in ways that lose critical nuance when translated to pure technicians.

Platform engineering, combined with the right development infrastructure, is beginning to make these people builders. Not in the traditional software development sense, but in the sense of constructing tools, notebooks, workflows, and analytical environments that extend individual expertise into repeatable, shareable capability. An analyst who can prototype a data transformation that makes a new collection source exploitable is not writing production software. But they are producing real mission value — in ways that centralized software factories were never designed to support.

The enabling condition is a development environment that removes the infrastructure tax on exploration. When standing up a secure, compliant workspace requires a ticket and a two-week wait, only credentialed engineers do it. When it requires a template selection and a few minutes, the population of people who can meaningfully participate in building expands dramatically. Compliance becomes the baseline from which everyone works, not a gate that filters who can start.

What is actually dying (and what is not)

What is dying is the centralized, monolithic software factory that inserts itself as the critical path for every development team it serves. The model where a single isolated organization controls the infrastructure, tools, processes, and standards for all programs is giving way to something more sustainable.

The mission need those factories served is not dying. It is growing. Agencies still need to compress delivery timelines, elevate security postures without stifling innovation, retain technical talent, and deliver capability at the speed modern threats demand. The difference is that the IC no longer needs to build its own factory to achieve those outcomes. The Air Force’s Platform One has evolved toward a platform-of-platforms model. The Navy has moved to multi-vendor strategies that reduce lock-in and increase operational resilience. Across the IC, organizations are realizing they can adopt proven frameworks and adapt them to their compliance requirements rather than rebuilding from scratch.

The path forward

The question is no longer whether modern DevSecOps practices can work in classified environments. That is proven. The questions now are much harder to solve.

Can we build development infrastructure that genuinely serves the cross-domain operating reality of the intelligence enterprise, rather than forcing developers to absorb that complexity as manual overhead? Can we extend the population of people who build to include analysts, specialists, and operators whose domain expertise is the IC’s most irreplaceable asset? Can we shift enough of the compliance burden into the platform itself that security becomes an accelerant rather than a constraint?

Platform engineering makes all of this achievable. Small teams can support large organizations. Compliance becomes portable and workspaces repeatable across classification levels. The maintenance burden that currently consumes government talent shifts to software. The distance between having an idea and building something useful around it can be measured in minutes.

The factory that tried to control everything is giving way to a platform that enables everyone. That is not a loss. It is the next evolution the mission has been waiting for.

About the Author

Amanda Phelps leads Global Public Sector Partnerships and Alliances at Coder, where she works with government and defense organizations to enable secure, compliant development environments across classification levels. She specializes in creating partnership strategies that accelerate software delivery for programs in the public interest.

About Coder

Coder is the AI software development company leading the future of autonomous coding. Coder helps teams build fast, stay secure, and scale with control by combining AI coding agents and human developers in one trusted workspace. Coder’s award-winning self-hosted Cloud Development Environment (CDE) gives teams the power to govern, audit, and accelerate software development without trade-offs. Learn more at coder.com.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post The Software Factory Is Dead, Long Live the Software Factory appeared first on Intelligence Community News.

]]>
44022
DIA posts audit software RFI https://intelligencecommunitynews.com/dia-posts-audit-software-rfi/?utm_source=rss&utm_medium=rss&utm_campaign=dia-posts-audit-software-rfi Tue, 13 Jan 2026 12:44:36 +0000 https://intelligencecommunitynews.com/?p=43585 On January 12, the Virginia Contracting Activity (VACA), on behalf of the Defense Intelligence Agency (DIA), posted a request for...

The post DIA posts audit software RFI appeared first on Intelligence Community News.

]]>
On January 12, the Virginia Contracting Activity (VACA), on behalf of the Defense Intelligence Agency (DIA), posted a request for information (RFI) for audit management software. Responses are due by 12:00 p.m. Eastern on February 2.

VACA is seeking information from qualified vendors with proven expertise in delivering comprehensive software solutions designed for Internal Audits, Inspections, and Evaluation engagements to support the DIA’s OIG and its mission.

The purpose of this RFI is to explore potential software application that can provide comprehensive central management of internal audits, inspections and evaluation oversight projects. The desired tool should facilitate the entire audit lifecycle, from planning and execution to reporting, ensuring proper access levels are maintained for sensitive information.

Additionally, it should support the review and feedback process on draft work products prior to finalization. Given the sensitive nature of the work and the confidentiality of audit documents, it is imperative that all data is processed within OIG-controlled U.S. government network environments. The software must be compatible with DIA’s existing information system infrastructure and capable of being deployed on-premises systems for the OIG’s use.

Following review of the provided information, the agency will contact vendors whose solutions best align with its requirements to schedule virtual demonstrations of software.

Review the DIA audit software RFI.

Source: SAM

Start 2026 ahead of the competition with a paid subscription to IC News. You’ll get full access to our searchable archive of 15,000+ articles, plus new articles each weekday.

 

The post DIA posts audit software RFI appeared first on Intelligence Community News.

]]>
43585
Defense Unicorns launches UDS Registry https://intelligencecommunitynews.com/defense-unicorns-launches-uds-registry/?utm_source=rss&utm_medium=rss&utm_campaign=defense-unicorns-launches-uds-registry Mon, 30 Jun 2025 14:36:16 +0000 https://intelligencecommunitynews.com/?p=42067 On June 30, Defense Unicorns announced the launch of UDS Registry, a software registry that stores, manages, and distributes Zarf...

The post Defense Unicorns launches UDS Registry appeared first on Intelligence Community News.

]]>
On June 30, Defense Unicorns announced the launch of UDS Registry, a software registry that stores, manages, and distributes Zarf and other OCI (Open Container Initiative) artifacts. UDS Registry is the first software registry of its kind to offer the speed, reliability, and mission-critical performance required by defense systems operating in the most extreme environments.

“UDS Registry gives the U.S. and our allies an American-made software solution that secures our software supply chain and maintains trust and reliability across the software development lifecycle,” said CEO and co-founder Rob Slaughter. “We are insanely proud of the team at Defense Unicorns that continues to develop world-class software solutions for the most critical and extreme software environments in the world.”

UDS Registry integrates seamlessly with Zarf, the most widely used open-source airgap tool in the world, developed by Defense Unicorns, as well as UDS, Defense Unicorns’ enterprise platform solution, to enable rapid and secure software delivery. Designed to work alongside UDS Core and UDS Tactical Edge, it offers a centralized capability to manage and verify packages, from container images to complex bundles.

Modern warfighters confront a vital obstacle: delivering trusted software into contested, disconnected, and classified environments remains frustratingly slow. Manual processes, fragmented metadata, and unreliable version control introduce delays that undermine both mission readiness and cybersecurity. UDS Registry was purpose-built to remove these barriers.

With its airgap-native architecture, UDS Registry gives teams the ability to catalog, validate, and deploy mission software anywhere. Every package is continuously scanned, cryptographically signed, and enriched with a Software Bill of Materials (SBOM), Common Vulnerabilities and Exposures (CVEs) data, and procurement metadata. Role-specific views provide tailored access for SREs, operators, and program managers, reducing deployment friction and enhancing visibility across the stack.

In just four years, Defense Unicorns has become the world leader in open source software for defense systems, and has built an impressive client base including the U.S. Navy, U.S. Air Force, U.S. Space Force, U.S. Army, and multiple U.S. cyber initiatives around the globe.

“UDS transforms how software moves from development to delivery, bringing speed, trust, and operational clarity to mission-critical environments,” said Jeff McCoy, co-founder and chief technology officer at Defense Unicorns. “The idea is to give you all the data you need, so regardless of environment or connectivity limitations, you can effectively operate wherever the mission demands.”

Source: Defense Unicorns

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post Defense Unicorns launches UDS Registry appeared first on Intelligence Community News.

]]>
42067
NSA and CISA highlight MSL importance https://intelligencecommunitynews.com/nsa-and-cisa-highlight-msl-importance/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-and-cisa-highlight-msl-importance Wed, 25 Jun 2025 13:50:48 +0000 https://intelligencecommunitynews.com/?p=42038 On June 24, the National Security Agency and the Cybersecurity and Infrastructure Security Agency (CISA) released a joint Cybersecurity Information Sheet...

The post NSA and CISA highlight MSL importance appeared first on Intelligence Community News.

]]>
On June 24, the National Security Agency and the Cybersecurity and Infrastructure Security Agency (CISA) released a joint Cybersecurity Information Sheet (CSI) to highlight the importance of adopting memory safe languages (MSLs) in improving software security and reducing the risk of security incidents.

Memory safety affects all software development and is a critical aspect to a holistic approach to security. Adopting MSLs will directly improve software security for all.

The CSI, “Memory Safe Languages: Reducing Vulnerabilities in Modern Software Development,” details these various benefits of MSLs, citing several examples and case studies, and highlights the additional advantages that MSLs bring to reliability and productivity. Reducing memory-related vulnerabilities is critical and the consequences of not addressing memory safety vulnerabilities can be severe, including data breaches, system crashes, and operational disruptions.

MSLs incorporate built-in mechanisms, such as bounds checking, memory management, and data race prevention, to guard against various memory bugs and vulnerabilities. Without these safeguards, such weaknesses could be exploited by malicious actors. By embedding these safety features directly at the language level, MSLs prevent memory safety issues from the outset.

The authoring agencies urge organizations to consider whether adopting MSLs is practical for their circumstances, and provides adoption approaches and engineering considerations to ensure effective implementation of MSLs into their software. MSL adoption does not require existing code to be completely rewritten, and the report provides guidance to leverage interoperability to integrate with existing codebases. Further, the report also details ways non-MSLs can be made safer in cases where adopting an MSL is not practically feasible.

To strengthen national cybersecurity and reduce memory vulnerabilities, software producers, especially those for National Security Systems (NSS) and critical infrastructure, should utilize this guidance to plan for and begin using MSLs for their software systems.

Read the full report, “Memory Safe Languages: Reducing Vulnerabilities in Modern Software Development.

Source: NSA

Your competitors read IC News each day. Shouldn’t you? Learn more about our subscription options, and keep up with every move in the IC contracting space.

The post NSA and CISA highlight MSL importance appeared first on Intelligence Community News.

]]>
42038
AWS Marketplace adds federal addendum https://intelligencecommunitynews.com/aws-marketplace-adds-federal-addendum/?utm_source=rss&utm_medium=rss&utm_campaign=aws-marketplace-adds-federal-addendum Wed, 12 Mar 2025 12:31:29 +0000 https://intelligencecommunitynews.com/?p=41177 On March 10, Amazon Web Services (AWS) announced the launch of the Federal Addendum to the Standard Contract for AWS Marketplace (SCMP). This...

The post AWS Marketplace adds federal addendum appeared first on Intelligence Community News.

]]>
On March 10, Amazon Web Services (AWS) announced the launch of the Federal Addendum to the Standard Contract for AWS Marketplace (SCMP). This novel approach to contracting can help streamline government approvals of software procurement and speed up the government’s access to third-party software solutions using AWS Marketplace by offering a pre-negotiated and consistent end-user license agreement (EULA) for each purchase.

In 2019, AWS Marketplace worked with legal, procurement, and sales leaders from our buyer and seller communities to develop the SCMP, a pre-negotiated agreement designed to capture common ground between buyers and sellers. The SCMP has helped accelerate contract approvals by up to 80 percent.

Negotiating EULAs for individual independent software vendors (ISVs) is time-consuming and burdensome—especially for US federal government customers who have limited approval authorities such as contracting officers that are authorized to approve EULAs. To overcome this potential bureaucratic slowdown and speed up the delivery of cutting-edge technology solutions to federal government customers using AWS Marketplace, you can now use the Federal Addendum to SCMP.

The Federal Addendum is a previously negotiated contract that was developed in collaboration with the customer and seller communities to accelerate transactions. It’s available for all AWS Marketplace sellers to adopt for their private offers to federal government customers, including in the AWS Marketplace for the U.S. Intelligence Community. It addresses common federal government requirements for commercial supplier agreements, such as removing unenforceable clauses.

Source: AWS

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post AWS Marketplace adds federal addendum appeared first on Intelligence Community News.

]]>
41177
Sonatype unveils AI SCA https://intelligencecommunitynews.com/sonatype-unveils-ai-sca/?utm_source=rss&utm_medium=rss&utm_campaign=sonatype-unveils-ai-sca Mon, 10 Mar 2025 23:39:32 +0000 https://intelligencecommunitynews.com/?p=41166 On March 4, Sonatype announced end-to-end AI Software Composition Analysis (AI SCA) capabilities that enable enterprises to harness the full...

The post Sonatype unveils AI SCA appeared first on Intelligence Community News.

]]>
On March 4, Sonatype announced end-to-end AI Software Composition Analysis (AI SCA) capabilities that enable enterprises to harness the full potential of AI. With its expertise in open source governance, Sonatype now extends its trusted platform to protect, manage, and optimize AI/ML models across development and deployment. Sonatype is the first and only company providing an end-to-end AI SCA solution, ensuring that enterprises can adopt AI with the same level of safety and productivity as traditional open source.

Open source AI/ML adoption is soaring — over the last 12 months, Sonatype has identified more than 300,000 models within customer software supply chains. As organizations rush to integrate AI-powered software and agentic AI solutions, they face the same security, compliance, and governance challenges that once plagued open-source software adoption.

“No one knows open source like Sonatype, and AI is the next frontier. Just as we revolutionized open source security, we are now doing the same for AI,” said Mitchell Johnson, chief product development officer at Sonatype. “We are the first company to address the entire AI/ML supply chain — giving enterprises and developers the confidence to deliver AI-powered solutions without compromising security, compliance, or velocity. By integrating seamlessly into existing DevOps workflows, we ensure developers can innovate freely while staying secure.”

In The Forrester Wave: Software Composition Analysis (SCA) Software, Q4 2024 report, the Forrester analyst noted Sonatype’s forthcoming AI capabilities would “catapult Sonatype ahead on both software supply chain and generative AI (genAI) SCA” and awarded Sonatype the highest possible marks in several categories, including AI component analysis.

“It has never been easier for organizations to integrate open source AI models into software, but with open source AI consumption comes the same risk facing users of traditional open source. It is imperative that we, as an industry, secure their use now in order to prevent unmanageable security workloads in the future,” said Brian Fox, co-founder and CTO at Sonatype. “We are proud to offer developers and security teams an end-to-end platform that provides the visibility and governance capabilities needed to use AI models safely, setting organizations up for easy and efficient long-term security.”

Source: Sonatype

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Sonatype unveils AI SCA appeared first on Intelligence Community News.

]]>
41166
NSA publishes recommendations for making national security-related software understandable https://intelligencecommunitynews.com/nsa-publishes-recommendations-for-making-national-security-related-software-understandable/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-publishes-recommendations-for-making-national-security-related-software-understandable Fri, 17 Jan 2025 15:32:28 +0000 https://intelligencecommunitynews.com/?p=40749 On January 16, the National Security Agency (NSA), the Cybersecurity and Infrastructure Agency (CISA), the Defense Advanced Research Projects Agency...

The post NSA publishes recommendations for making national security-related software understandable appeared first on Intelligence Community News.

]]>
On January 16, the National Security Agency (NSA), the Cybersecurity and Infrastructure Agency (CISA), the Defense Advanced Research Projects Agency (DARPA), and the Office of the Under Secretary of Defense for Research and Engineering (OUSD R&E) published a report that urges a national effort to better understand the behavior of software underpinning national security and critical infrastructure systems.

The Cybersecurity Information Sheet (CSI), “Closing the Software Understanding Gap,” points to the need for policy action, technical innovation, and resources to help systems owners and operators better construct and assess their software-controlled systems across all conditions – normal, abnormal, and hostile.

“A lack of understanding of software imposes risks on many critical systems that are dependent on software to run properly and as intended,” said Neal Ziring, NSA Research Technical Director. “This report is a national call for the government and private sectors to work together to prioritize understanding software as a national effort critical to the nation’s success in the future.”

Currently, the nation’s ability to build software outstrips its ability to understand it, leaving systems vulnerable to exploitation, the CSI states. Undiscovered behavior in software has exposed critical vulnerabilities in aircraft, military systems, and supply chains and impacted national security objectives, with the CSI citing numerous examples.

The CSI outlines a call to action to address gaps in software understanding through:

  • Policy action – As technical capabilities mature, policy needs to evolve to require and formalize processes for characterizing software behavior before it is introduced into critical systems.
  • Technical innovation – Technical capabilities for measuring software and reasoning about its behavior need to be developed to reduce risk. All suitable techniques, including formal methods and artificial intelligence, should be leveraged to develop rigorous, reliable, rapid, and inexpensive capabilities.
  • ​Resources – Significant sustained investments in research, development, and engineering are needed to support a unified set of software understanding capabilities. Public and private partnerships with industry should also be explored to ensure practical and efficient solutions that can be leveraged across missions and diverse systems.

 

Read the full report here.

Source: NSA

Start 2025 ahead of the competition with a paid subscription to IC News. You’ll get full access to our searchable archive of 13,000+ articles, plus new articles each weekday.

The post NSA publishes recommendations for making national security-related software understandable appeared first on Intelligence Community News.

]]>
40749
NSA publishes ESF recommendations on standards development https://intelligencecommunitynews.com/nsa-publishes-esf-recommendations-on-standards-development/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-publishes-esf-recommendations-on-standards-development Thu, 01 Aug 2024 12:36:39 +0000 https://intelligencecommunitynews.com/?p=39385 As technology continues to develop at an increasingly rapid pace, the U.S. needs to participate in and position itself as...

The post NSA publishes ESF recommendations on standards development appeared first on Intelligence Community News.

]]>
As technology continues to develop at an increasingly rapid pace, the U.S. needs to participate in and position itself as the leader in the creation of global standards, according to an Enduring Security Framework (ESF) report released on July 30 by the National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA).

The report, “Recommendations for Increasing U.S. Participation & Leadership in Standards Development,” recognizes both economic reasons and national security concerns requiring increased U.S. participation in standards development organizations (SDOs). U.S. participation in standards is critical to protecting the security of the American people, expanding economic opportunity, and defending democratic values.

“We’re always working toward open, transparent, consensus-driven standards,” said Atiya Yearwood, deputy chief of NSA’s Cybersecurity Collaboration Center. “This is how we innovate, adapt, advance, and prosper while also protecting security. Areas such as quantum computing and AI are rapidly evolving, and need to be developed carefully and securely, so we need U.S. industry to continue the tradition of strong leadership from the beginning phase of standards development.”

The ESF Industry Specifications Group (ISG) Working Panel, an NSA and CISA-led public-private cross-sector working group, developed the report to provide recommendations for industry, academia, and the U.S. government to sustain and grow engagement in SDOs.

The ESF urges early engagement in critical emerging technology (CETs) standards-related activities, the development of a more standards-savvy U.S. workforce, engagement with academia to grow the next generation of standards experts, and establishing the United States as a venue of choice for hosting standards meetings.

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA publishes ESF recommendations on standards development appeared first on Intelligence Community News.

]]>
39385
Army posts new modern software development RFI https://intelligencecommunitynews.com/army-posts-new-modern-software-development-rfi/?utm_source=rss&utm_medium=rss&utm_campaign=army-posts-new-modern-software-development-rfi Tue, 28 May 2024 13:25:00 +0000 https://intelligencecommunitynews.com/?p=38794 On May 23, the U.S. Army Contracting Command – Aberdeen Proving Ground (ACC-APG) posted a request for information (RFI) for...

The post Army posts new modern software development RFI appeared first on Intelligence Community News.

]]>
On May 23, the U.S. Army Contracting Command – Aberdeen Proving Ground (ACC-APG) posted a request for information (RFI) for a new modern software development multiple award IDIQ. Responses are due by 4:00 p.m. Eastern on June 10.

Software is essential to modern military operations. It is a key component in the Army’s weapons, business, and training systems and is embedded into the enterprise processes that make the Department function. These systems enable the Army to detect and track adversaries, protect operations from cyber threats, and improve the accuracy and effectiveness of decisions and actions. Software drives improved outcomes and effectiveness in our missions and operations.

Consequently, the Army’s ability to rapidly develop, deliver, and adapt resilient software is critical to achieving a competitive advantage over adversaries. ACC-APG is pursuing a new Multiple Award Indefinite Quanty Indefinite Delivery Contract for Modern Software Development for which task orders will be issued for software enablement efforts in support of Army systems. For the purposes of this action, a “software enablement effort” is defined as: (a) development of a custom software solution; (b) customization, integration, or modification of a software solution; (c) software as a service enablement; or (d) software security and hosting modernization.

ACC-APG seeks input on the proposed contract strategy, initial statement of objectives, and answers to targeted questions. Specifically, ACC-APG is seeking suggestions on how to establish a phased source selection that will enable the Army to award an effective and expedited Multiple Award contract to the most qualified contractors.

Review the Army modern software development RFI.

Source: SAM

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

The post Army posts new modern software development RFI appeared first on Intelligence Community News.

]]>
38794