Federal DevSecOps Moves from Pilots to Operational Capability

Become an Insider.

Get Government Technology Insider news and updates in your inbox.

Get started by entering your email below.

Related Content

More Content

When technology moves slowly but threats and mission requirements do not, the gap between identifying a need and delivering a capability becomes a risk of its own. Across the public sector, leaders are increasingly calling for software delivery at the speed of relevance, while efforts are putting greater emphasis on eliminating barriers between innovation and operational capability. The conversation is shifting from whether agencies should adopt federal DevSecOps to what it will take to make modern software delivery part of the way government operates. That question was central to the conversations at the recent Carahsoft DevSecOps Conference, where government and industry leaders examined what comes next for federal software delivery.

From Innovation to Operational Execution

Federal government agencies have spent years building the foundation for modern software delivery. Agencies have established software factories, invested in DevSecOps platforms, experimented with agile methodologies, and developed approaches for continuous authorization. The next challenge is turning those individual investments into an operating model that can scale across missions.

January 2026 Department of War (DoW) announcement outlining a major overhaul of its innovation ecosystem provides a clear example of this direction. The department described a move toward a unified and fast-moving innovation enterprise focused on getting technology to the warfighter, while organizing innovation around technology, product, and operational capability.

“We are rolling out the red carpet for innovators who want to work with the War Department,” said Emil Michael, Under Secretary of War for Research and Engineering. “This new structure creates a stronger identity for our innovation ecosystem and gives industry a more direct path to move technology into the hands of the American warfighter.”

The distinction between innovation and operational capability is important. A prototype, platform, or successful pilot only creates value when it ultimately improves the mission. Modernization, therefore, has to be measured not by how much technology an agency adopts, but by how effectively it can turn technology into sustained operational results.

Building a Modern Software Ecosystem

DevSecOps is often described through technologies such as containers, CI/CD pipelines, automated testing, security scanning, and infrastructure automation, but those capabilities cannot overcome organizational processes that continue to operate at a different pace.

A sophisticated development environment cannot accelerate delivery if acquisition takes years to approve a capability. A software factory cannot deliver operational value if its products become trapped in lengthy ATO and transition processes. Agile development loses much of its value when teams must define every detail of a capability before users have an opportunity to test it.

Modern development practices therefore require modern operating models. The War Department’s innovation overhaul reflects that challenge by emphasizing the removal of legacy barriers and creating strong connections between operational problems, technology providers, and the people responsible for transitioning capabilities into use.

This also creates an opportunity to rethink the relationship between government and industry. Commercial organizations can bring technology, expertise, and proven practices, while government brings the mission context and operational requirements. Creating a more direct path between the two does not mean eliminating oversight; it means making sure necessary processes enable rather than unnecessarily impede mission delivery.

Making the Mission the Measure

As these pieces come together, the definition of successful modernization also needs to evolve. Rather than treating compliance, development, infrastructure, or technology adoption as separate objectives, agencies can evaluate them according to whether they ultimately improve the mission.

Dave Raley, Chief Digital Services Officer who lead Operation StormBreaker for the Marine Corps, emphasized that perspective following the conference. “The goal should be the mission outcome, securely and in compliance,” he said. That means asking whether an organization is better equipped to recognize a need, respond to it, learn from users, and improve the resulting capability. Speed is an important part of the equation, but so are security, usability, adaptability, and the ability to sustain a capability once it reaches production.

The broader definition of success is particularly important as agencies move beyond isolated pilots. If modern development practices remain confined to experimentation while critical programs continue to follow legacy models, their impact will remain limited.

Moving Beyond the Pilot Mentality

Recent developments across the DoW suggest that this mindset is beginning to change. In an April interview with Federal News Network, then-Army CIO Leo Garciga described an Army continuous ATO pipeline that expanded from supporting two simultaneous development efforts to 23 while reducing one delivery cycle from roughly 30-45 days to about a week. He framed the objective around improving the “ability to deliver capabilities that really matter.”

The significance extends beyond that individual example. It demonstrates what becomes possible when modern development environments are treated as operational infrastructure rather than technology demonstrations. The measure is no longer how sophisticated the platform is, but what mission owners can accomplish with it.

“The measure of modern development environments isn’t how sophisticated the technology is, but what mission owners can accomplish with it.” – Dave Raley

This is also where DevSecOps and broader federal innovation policy increasingly intersect. Continuous authorization, automated security, and modern development practices are valuable not just because they are more efficient, but because they can help agencies respond to changing circumstances without repeatedly rebuilding the processes required to deliver each new capability.

A New Model for Government and Industry

Starting today, the federal government needs to ensure that modern software practices are repeatable. This will require continued investment in DevSecOps and continuous authorization, but technology alone will not be enough. Acquisition, requirements, governance, organizational incentives, and partnerships with industry all need to support a model in which agencies can move from mission need to operational capability more effectively.

The conversations at the Carahsoft DevSecOps Conference, and the direction of the broader federal modernization efforts, suggest that this transition is already underway. The question is no longer whether modern software practices can work in government; it is whether agencies can make them the norm.

Skip to content