Innovation

Mission, Security and the Case for a Broader Federal Technology Market

Written by Fed Gov Today | Jul 30, 2026, 8:10:05 PM

Presented by Carahsoft

The federal government needs the scale and resources of major technology providers, but some of its most important mission problems may be solved by much smaller companies.

Drew Mykelgard, Executive Director of Federal Programs at Carahsoft, believes the federal technology ecosystem works best when agencies can draw from both. The government should be able to access large infrastructure providers as well as specialized companies capable of addressing narrow but meaningful mission requirements.

That opportunity, however, comes with an obligation. Companies that want to work with the federal government must understand that security cannot be treated as a feature added near the end of product development.

The government is an enormous buyer of technology, Mykelgard noted, spending hundreds of billions of dollars each year on software and related capabilities. That naturally attracts companies interested in entering the market. But the federal government is not an ordinary customer.

“Our systems have to be safe and secure,” Mykelgard said.

Some federal agencies are routinely targeted by sophisticated nation-state actors. Others may have more flexibility in the amount of risk they can accept. In every case, the technology provider must understand the mission and be prepared to meet the appropriate security standard.

That is not always how young companies develop. Startups and rapidly growing software firms often concentrate first on building features and attracting customers. Security may become a priority only after the product has reached a certain level of maturity.

Mykelgard said that approach can create serious problems in government, where agencies hold tax records, health information, student loan data and other information that citizens expect them to protect. A breach can damage more than a system. It can weaken public confidence in the services government provides.

“If there is a breach, that confidence goes away super fast,” he said, “and it’s really hard to rebuild.”

The answer is not to close the federal market to newer or smaller providers. Mykelgard argues that agencies need those companies because they frequently bring capabilities that larger firms may never build.

He pointed to an application developed at the Department of Veterans Affairs to help veterans stop smoking. It was created by veterans to meet the needs of a specific veteran population. The project did not require the workforce of a global technology company. It required a small team that understood the users, cared about the outcome and was willing to work closely with the agency.

Across government, similar mission needs exist at every scale.

“There’s such a wide variety of mission sets,” Mykelgard said. “You could go by every agency and find something cool like that.”

Smaller companies can bring specialized products, modern development practices and outside expertise into government. They may employ talented engineers, security professionals and product leaders who would not otherwise enter federal service. When agencies and companies work closely together, government can help shape the provider’s roadmap while the provider helps the agency keep pace with commercial innovation.

Getting to that point is rarely easy.

“It is absolutely painful and it’s hard,” Mykelgard said of working with government.

Federal acquisition can be difficult to navigate. Security requirements can be extensive. Rules are often created in response to past failures and understandable concerns, but the cumulative effect can discourage companies that do not have large federal sales and compliance organizations.

The companies that persist are often the ones most invested in the mission. They are willing to listen, adjust their products and remain engaged through a long sales and authorization process.

Mykelgard believes government should make that process easier where it can, but not by reducing the importance of security. The opportunity lies in replacing outdated and duplicative requirements with more effective methods of assurance.

That includes the broader movement from periodic compliance toward continuous security.

For years, much of federal security assessment depended on documentation packages reviewed at set intervals. An organization could demonstrate that a required control existed at the moment of an assessment, even though the system and threat environment might change many times before the next review.

Modern adversaries do not operate on an annual schedule. They scan, probe and attack continuously. Agencies and technology providers need security practices that operate at a comparable pace.

Mykelgard credits former Federal CIO Greg Barbacoa with helping push the government away from a model centered on heavy documentation and toward one focused on automation, continuous evaluation and security outcomes.

“Our enemies are attacking our systems all the time,” Mykelgard said. “We can’t look at these systems once a year and accept that that’s secure.”

The full effect of that shift may take years to appear. Agencies will need to change policies, budgets and internal processes. Congress and the executive branch will need to reinforce the direction. Technology companies will need to integrate compliance evidence directly into engineering and operations.

Eventually, Mykelgard believes the old model will look as dated as non-agile development or resistance to cloud computing.

The result should be a federal market that is easier for mission-focused companies to enter but more demanding about the security evidence they provide. Instead of rewarding organizations for producing the largest package of documents, government can reward those that demonstrate strong security as part of how they build and operate their products.

That balance—greater access paired with greater responsibility—could give agencies the innovation they need without asking them to sacrifice the trust of the people they serve.