Tag: CMMC

  • FedRAMP High Arrives for Defense Supply-Chain Compliance

    FedRAMP High Arrives for Defense Supply-Chain Compliance

    On September 1, 2026, Baltimore-based FutureFeed and CyberIllumination announced that both platforms have achieved FedRAMP High Authorized (Class D) status. FutureFeed is a compliance platform for NIST SP 800-171 and CMMC used across the Defense Industrial Base (DIB); CyberIllumination, operated by Continuous Compliance LLC and currently in beta, gives prime contractors and subcontractors a shared view of supply-chain cybersecurity posture.

    Per the release, Class D aligns with the historical FedRAMP High baseline, the standard applied to federal systems where a loss of confidentiality, integrity, or availability could have severe or catastrophic consequences. The authorizations followed independent third-party assessments of each platform’s security controls. Cloud service provider Project Hosts supported both efforts. FutureFeed reports more than 1,400 clients and 350-plus partners across the DIB.

    Executive Summary

    The announcement is narrow in substance and broad in signal. Two platforms that hold defense contractors’ most sensitive compliance artifacts — system security plans, risk assessments, audit evidence, supplier posture records — now carry the federal government’s highest authorization tier for unclassified cloud workloads. FedRAMP, the Federal Risk and Authorization Management Program, standardizes how cloud services are security-assessed for government use; its High baseline sits above the Low and Moderate tiers and applies to data whose compromise would be severe or catastrophic.

    Why it matters: the data these platforms aggregate is arguably more sensitive than any single customer’s own environment. A compliance tool serving 1,400 DIB organizations holds a consolidated map of where the defense supply chain is weakest — which controls are unimplemented, which remediation plans are open, and for how long. That concentration is exactly the profile FedRAMP High was written for, and it is the strongest argument in the release.

    What the release does not do is quantify its central marketing claim. It states that “few compliance platforms reach FedRAMP High” without a figure, names no federal agency customer, and does not disclose the authorization pathway, effective date, or cost. The security assessment is independently validated; the competitive framing around it is not.

    The Compliance Tool Becomes the Concentration Risk

    There is a structural irony in defense compliance software. To help a contractor prove it protects Controlled Unclassified Information (CUI), the platform must first collect a detailed inventory of that contractor’s security gaps. Multiply that across a customer base the size of FutureFeed’s stated 1,400 clients and 350-plus partners, and the vendor accumulates something no individual contractor holds: a cross-sectional view of where the defense industrial base is unprotected, documented in audit-ready detail.

    That is the honest case for FedRAMP High here, and it does not depend on marketing language. A system security plan describes architecture, boundaries, and control implementation. A plan of action and milestones (POA&M) is, functionally, a dated list of known weaknesses and when they will be fixed. Aggregated, these are high-value targets regardless of whether the platform itself ever touches a federal network. Holding the aggregator to the same bar as the systems it describes is a defensible design principle.

    For buyers, the practical read is that vendor due diligence in this category should now include the platform’s own authorization posture, not just its feature list. For competing vendors, the announcement raises the reference point in procurement conversations even where no regulation formally requires it.

    What FedRAMP High Buys — and What It Does Not

    Context matters for interpreting the tier. Under DFARS 252.204-7012, cloud service providers handling covered defense information for contractors are generally expected to meet requirements equivalent to the FedRAMP Moderate baseline. High sits above that. So this is a vendor electing to exceed the common contractual floor for its market segment — a legitimate differentiator, but one worth describing precisely rather than as a pass/fail gate that competitors have failed.

    It is also worth separating what an authorization certifies from what it implies. FedRAMP attests that a defined system boundary was assessed against a control baseline by an independent assessor at a point in time, and that continuous monitoring obligations apply thereafter. It does not certify product quality, data-handling ethics, uptime, or that every customer workload runs inside the authorized boundary. The release states that CyberIllumination runs in AWS GovCloud on U.S. soil; it does not state the hosting arrangement for FutureFeed, nor whether existing customers are automatically served from the authorized environment.

    The economics deserve a mention because they shape the market. FedRAMP authorization is a capital-intensive exercise in assessment, documentation, and ongoing monitoring — historically a barrier that favors larger vendors or those buying a compliant platform-as-a-service underneath them. That is precisely the gap Project Hosts describes filling with its FasTrack program, which the release says provides a path to authorization without securing an agency sponsor. Sponsorless pathways lower the barrier meaningfully; they also make “few platforms reach FedRAMP High” a claim with a shorter shelf life than the announcement implies.

    The Flow-Down Problem and the Case for Authorize-Once

    CyberIllumination’s stated premise is the more interesting product thesis in the release: compliance obligations flow down every tier of the defense supply chain, but visibility does not. A prime contractor may hold a contract requiring assurance about subcontractors it has limited insight into, while a small supplier answers substantially the same questionnaire for every prime it serves. The proposed fix — a supplier authorizes one compliance record and shares it with multiple primes, with audit logs of who accessed what — replaces N questionnaires with one record.

    This is a two-sided network, and two-sided networks are hard to start. Suppliers only benefit if enough primes accept the shared record; primes only adopt if enough suppliers are on it. The audit-log design is a sensible trust mechanism for the supplier side, since the objection to shared compliance data is usually not transparency but loss of control over who sees weaknesses. Whether primes will accept a third-party record in place of their own assurance process is an adoption question the release does not address.

    One detail is worth flagging plainly and without prejudice: the release describes CyberIllumination as currently in beta. Authorizing a pre-general-availability product at the High baseline is unusual sequencing, though not improper — building to the standard before scale is arguably better practice than retrofitting. It does mean the authorization currently applies to a platform with an undisclosed production customer base, and readers should not infer commercial traction from a security designation.

    Background

    Defense contractors have faced formal cybersecurity obligations for roughly a decade, beginning with DFARS clauses requiring implementation of NIST SP 800-171 to protect Controlled Unclassified Information. Self-attestation proved uneven, and the Department of Defense responded with the Cybersecurity Maturity Model Certification program, which introduces third-party verification and is being phased into contracts. The practical effect has been a surge in demand for software that helps contractors document, evidence, and sustain compliance rather than reconstruct it before each assessment.

    FutureFeed, based in Baltimore, built its business in that market, reporting more than 1,400 clients and 350-plus partners including managed service providers and consultants. CyberIllumination extends the same logic upward into the supply chain, addressing a persistent structural gap: obligations flow down through every contracting tier, but reliable visibility into whether lower tiers have met them does not flow back up. FedRAMP, meanwhile, has spent recent years modernizing its authorization process to reduce cost and time-to-authorization — context that makes new High-tier entrants in specialized software categories more likely, not less.

    Source: FutureFeed and CyberIllumination Achieve FedRAMP High Authorized (Class D) Status, the Federal Government’s Highest Cloud Security Bar — PR Newswire release issued from Baltimore on September 1, 2026, announcing FedRAMP High authorizations for two Defense Industrial Base compliance platforms.

  • AI Agents as Digital Actors: Governance Lags Adoption

    AI Agents as Digital Actors: Governance Lags Adoption

    Info-Tech Research Group, an IT research and advisory firm, published new research on 28 August 2026 from Arlington, Virginia, arguing that enterprise AI agents should be governed as a distinct class of digital actor rather than as ordinary IT assets or as earlier generative AI models. The blueprint, Govern Enterprise AI Agents While Preserving Innovation, sets out a three-phase framework for managing agent identity, access, autonomy limits and ongoing oversight.

    The firm names five governance gaps it says organizations hit as agent use spreads: shadow AI, capability mismatch, runtime drift, unmanaged access and ambiguous ownership. The blueprint ships with a governance playbook, a charter example, an executive dashboard template and a glossary. Info-Tech says it serves more than 30,000 IT, HR and marketing leaders and has operated for nearly 30 years.

    Executive Summary

    The core claim is narrow and worth taking seriously: an AI agent does not merely produce output, it takes action. It can call systems, trigger workflows and make decisions on its own, at machine speed. That breaks the assumption underneath most enterprise AI governance to date, which is that a human reviews and approves a model’s output before anything consequential happens. Info-Tech’s position is that one-time approval gates cannot govern something that keeps operating after the gate.

    Altaz Valani, principal advisory director at Info-Tech, frames the problem in the release as a mismatch on both sides: agents cannot be governed like IT assets because they act across systems, and they cannot be governed like employees because, in the firm’s words, they move quicker and lack emotions, conscience and consequences. The practical translation is that the controls that work on people — training, incentives, accountability, the fear of being fired — have no purchase here. What is left is identity, credentials, permissions, monitoring and a defined kill switch.

    That is not a new discipline. It is the same control discipline that regulated supply chains already run under. On the same day, Nelson Miller Group announced it had earned Cybersecurity Maturity Model Certification (CMMC) Level 2, the US Department of Defense standard that obliges defense manufacturers to demonstrate control over access to sensitive information. The difference is that defense suppliers are made to prove those controls by contract, while most enterprises are deploying agents years ahead of anything comparable.

    Approval Gates Do Not Govern Things That Keep Moving

    Most enterprise AI governance was designed for a request-and-response world. A team proposes a use case, a committee reviews it, a model is approved, and a human checks the output before it becomes a decision. That control model has a hidden dependency: the risk sits still long enough to be reviewed. An agent breaks the dependency because the approval happens once and the behaviour continues indefinitely, across systems, with credentials attached.

    Info-Tech’s five named gaps are really five ways that assumption fails. Shadow AI means agents created outside sanctioned tools that IT does not know exist — the same problem as unsanctioned SaaS, except the unsanctioned thing holds credentials and acts. Capability mismatch means an agent’s autonomy and access outrun the validation and monitoring applied to it. Runtime drift means an agent quietly expands its scope as tools, prompts and permissions change, so the thing running in month six is not the thing that was approved in month one. Unmanaged access means service accounts and permissions let an agent do more than anyone intended. Ambiguous ownership means that when something goes wrong, no one is clearly accountable.

    None of these are exotic. They are the standard failure modes of any privileged non-human identity, which is why the useful reading of this research is deflationary rather than alarming: agentic AI is largely an identity and access management problem wearing new clothes. The genuinely new part is speed and volume. As Valani notes in the release, many people will have multiple agents working for them — which means identity populations that were once measured in employees start being measured in some multiple of employees.

    The CMMC Parallel: Regulated Sectors Already Do This, Under Contract

    The comparison worth drawing is with the defense industrial base. CMMC is the US Department of Defense’s framework for verifying that contractors and subcontractors protect sensitive government information; Level 2 aligns with the NIST SP 800-171 control set for controlled unclassified information, covering access control, identification and authentication, audit and accountability, configuration management and incident response. Nelson Miller Group’s 28 August 2026 announcement that it earned Level 2 certification is, in commercial terms, a supply chain credential: it is how a manufacturer stays eligible for programs that handle protected data.

    Strip away the acronym and the CMMC control families read like a specification for governing agents: know every identity, prove who owns it, restrict what it can reach, log what it did, detect when it drifts, and be able to respond. The defense supplier does this because a contracting officer requires it and an assessment verifies it. The enterprise deploying a fleet of agents has no equivalent forcing function — no customer withholding a purchase order, no assessor arriving to check the evidence.

    That asymmetry is the real story. Control discipline in enterprise technology almost never arrives because it is a good idea; it arrives because a contract, a regulator or an insurer demands proof. Agentic AI is currently in the window between capability and requirement. Firms in regulated supply chains have an unusual advantage here: the muscle memory of proving controls to a third party transfers directly to governing non-human identities. Firms without that history are building the practice from a standing start, and doing it while the agents are already running.

    What the Release Substantiates, and What It Does Not

    This is analyst research promoting a paid deliverable, and it should be read as such — evenly, without either deference or dismissal. What is substantiated is a structured method. The three phases are specific and sequenced: Phase 1 establishes governance authority, decision rights and a small set of enforceable guardrails; Phase 2 maps the agent lifecycle, discovers agents wherever they are created, classifies them by risk and defines runtime monitoring and intervention actions by risk tier; Phase 3 assigns accountability across business owners, technical owners, AI governance and enterprise risk, then defines metrics, executive dashboard reporting and a phased rollout. The named artifacts — playbook, charter example, executive dashboard, glossary — are the ordinary output of this kind of advisory engagement and are reasonable to expect.

    What is not substantiated is the scale of the problem the framework addresses. The release describes a widening gap between adoption and governance but offers no survey data, no incidence rates for shadow agents, no measured cost of a runtime-drift failure and no baseline for how many organizations currently classify agents by risk at all. It refers to case studies without naming an organization or an outcome. The assertion that agents “lack conscience and cannot be morally incentivized” is a framing device rather than a finding; it is intuitively correct and empirically untested as stated here.

    That is not a criticism of the firm — vendor and analyst releases are marketing documents by design, and this one is unusually specific about method for the genre. It does mean a buyer should treat the framework as a hypothesis to be tested against their own environment rather than as evidence that their environment is on fire. The prudent question for a CIO is not whether the five gaps sound plausible, but which of them they can actually measure in their own estate this quarter.

    Who Gains: Identity Vendors, Platform Owners and Whoever Owns the Log

    If agent governance becomes an identity problem, the commercial gravity moves toward whoever already holds the identity layer. Identity and access management providers, privileged access management vendors and cloud platforms that issue and rotate machine credentials are positioned to extend existing products rather than sell new categories. Security operations vendors benefit from the runtime monitoring requirement, since drift detection is a telemetry problem before it is a policy problem. Governance, risk and compliance platforms gain a new object type to track.

    The harder position belongs to business units that have deployed agents quickly using departmental budgets and low-code tooling. Info-Tech’s Phase 2 — find agents wherever they are created — is the phase that generates conflict, because discovery inevitably surfaces work that was never registered with IT. Organizations that treat that discovery as an audit failure will drive the remaining agents further underground; the ones that treat it as an inventory exercise will get better data.

    For infrastructure operators specifically, there is a second-order consequence worth noting. Agents that act autonomously across systems generate authentication events, API calls and audit records continuously rather than in bursts tied to human working hours. Logging, retention and monitoring costs scale with that behaviour. Governance frameworks tend to be discussed as policy; the bill arrives as storage, egress and detection capacity.

    Background

    Info-Tech Research Group is an IT research and advisory firm that publishes structured methodologies — it calls them blueprints — covering IT strategy, security and governance, alongside affiliates McLean & Company for HR research and SoftwareReviews for software buying data. Its business model is subscription advisory, so its research releases both inform the market and market the firm; that dual purpose is standard for the analyst sector and is worth holding in mind when reading any single publication.

    The wider context is a two-year shift from generative AI, where models produce content a human then uses, to agentic AI, where software is granted credentials and permitted to act. That shift moves AI from a content-quality question into an access-control question, territory enterprise security teams have worked in for decades under frameworks such as NIST SP 800-171 and, for defense suppliers, the Department of Defense’s CMMC program. The unresolved issue is timing: regulated supply chains prove their controls because contracts require it, while most enterprises are deploying agents without an equivalent obligation.

    Source: AI Agents Must Be Governed as Persistent Digital Actors, Advises Info-Tech Research Group — the firm’s 28 August 2026 announcement of its Govern Enterprise AI Agents While Preserving Innovation blueprint, with background from Nelson Miller Group’s same-day CMMC Level 2 certification release.

  • Exostar Powers Fujitsu’s Trusted Supply Chain Service for Japan’s Defense Sector

    Exostar Powers Fujitsu’s Trusted Supply Chain Service for Japan’s Defense Sector

    Exostar, the Herndon, Virginia-based secure-collaboration provider, announced on August 20, 2026 that it is supplying its “Exostar Managed on Microsoft 365” environment-building technology for Fujitsu Limited’s new “Fujitsu Trusted Supplychain Service,” which Fujitsu is launching in Japan for the country’s defense and critical-infrastructure sectors.

    The service will run on ISMAP-registered infrastructure in Japan — ISMAP being Japan’s government cloud-security assessment program — giving customers in-country data residency while inheriting security controls Exostar has already deployed for the U.S. Defense Industrial Base. The arrangement extends a collaboration between the two companies that began in 2019.

    Executive Summary

    The announcement is a technology-provision deal: Exostar builds and manages the secure Microsoft 365 environment inside Fujitsu’s service, while Fujitsu operates and sells the offering in Japan. The environment includes a managed enclave — a walled-off cloud workspace where sensitive files stay put rather than scattering across suppliers’ own systems — plus centralized identity and access management, multi-factor authentication, partner onboarding, information-sharing controls, and audit-ready activity logging.

    Why it matters: cybersecurity requirements for defense suppliers are converging across allied nations. The U.S. Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) program, built on the NIST SP 800-171 standard, governs contractors that handle controlled unclassified information (CUI). Japan’s Ministry of Defense and its Acquisition, Technology & Logistics Agency (ATLA) have introduced closely aligned requirements, alongside Japan’s Economic Security Promotion Act of 2022. Multinational supply chains increasingly need one trust layer that satisfies both regimes.

    For Exostar, the deal exports a platform proven in U.S. defense environments — a Microsoft GCC High enclave with FedRAMP Moderate Equivalency — into a second allied market through a local operator. For Fujitsu, it adds vetted enclave technology to a domestic compliance service without building it from scratch.

    Allied Cybersecurity Mandates Are Converging on a Common Standard

    The most significant context in this release is regulatory, not technical. NIST SP 800-171 — a U.S. catalog of security controls for protecting sensitive-but-unclassified government information on contractor systems — has become a de facto international baseline. The U.S. enforces it through CMMC; Japan’s defense ministry and ATLA have adopted closely aligned supplier requirements. When two allied procurement regimes converge on the same control set, a vendor that has already operationalized those controls at scale can sell essentially the same capability into both markets.

    That is the strategic logic here. Exostar says its platform is used by more than half of the U.S. Defense Industrial Base, including 98 of the top 100 firms — a company-provided figure, but one that, if accurate, represents exactly the kind of installed-base credibility Japanese defense suppliers facing new mandates would want to borrow rather than rebuild. For smaller suppliers especially, achieving NIST 800-171-level security independently is expensive; inheriting controls from a managed enclave is the shortcut the compliance market has been moving toward.

    The Shared-Responsibility Enclave Model, and Its Limits

    The service uses what the release calls a shared responsibility model: Exostar’s managed environment provides many of the technical controls (encryption, access management, logging), while customers remain responsible for organizational requirements — policies, training, personnel vetting, and physical security. This is an honest framing worth noting, because “compliance in a box” claims in this market often gloss over it. An enclave can dramatically reduce a supplier’s technical burden; it cannot make an organization compliant by itself.

    The economics still favor the model. Concentrating sensitive information in one controlled environment, rather than distributing it across dozens of supplier systems of varying maturity, shrinks the attack surface and the audit surface simultaneously. The trade-off is concentration risk and dependency: suppliers’ most sensitive collaboration flows through a single third-party-managed environment, which raises the stakes on that environment’s own security and availability — a question the release, understandably, does not explore.

    Data Sovereignty as a Design Requirement, Not an Afterthought

    The structure of the deal is itself instructive. Exostar did not simply extend its U.S.-hosted service to Japanese customers; its technology is integrated into a Fujitsu-operated service running on ISMAP-registered infrastructure inside Japan. Data residency — keeping data physically and legally within national borders — and in-country operation are explicit features. This reflects a broader pattern in allied technology cooperation: security capabilities cross borders, but data and operations increasingly do not.

    For the infrastructure industry, that pattern has real consequences. Every allied market that mandates in-country operation for sensitive workloads creates demand for sovereign cloud capacity, local data centers, and partnerships pairing a foreign technology provider with a domestic operator. The Exostar–Fujitsu structure — U.S. platform expertise, Japanese infrastructure and go-to-market — is a template likely to recur as other allies formalize supplier-security regimes.

    Winners, Losers, and the Competitive Field

    The clearest beneficiaries, if the service performs as described, are mid-tier Japanese defense and critical-infrastructure suppliers that face rising security requirements without the IT resources of a prime contractor. Fujitsu gains a differentiated compliance offering; Microsoft benefits indirectly, since the enclave is built on Microsoft 365. The competitive pressure falls on standalone secure-collaboration and governance/risk/compliance vendors targeting Japan, who now face an incumbent domestic integrator paired with the dominant U.S. defense-collaboration platform.

    That said, the release is a technology-provision announcement, not a results announcement. It names no customers, no adoption targets, no pricing, and no launch date beyond “launching in Japan.” The 2019-era Fort# Forum collaboration shows the relationship has history, but the market impact of this new service is, at this stage, a projection rather than a demonstrated outcome.

    Background

    Exostar was built around the U.S. defense supply chain’s need to collaborate on sensitive programs without leaking controlled information. The company says more than half of the U.S. Defense Industrial Base — including 98 of the top 100 defense firms — transacts business over its platform, and that over 25 of the top global biopharmaceutical companies also use it. Its U.S. defense offering runs in a Microsoft GCC High enclave with FedRAMP Moderate Equivalency, the assurance tier used for handling controlled unclassified information.

    The Japanese market context has shifted markedly since the companies first partnered in 2019 on Fujitsu’s Fort# Forum offering. Japan’s Economic Security Promotion Act of 2022 and new Ministry of Defense and ATLA supplier requirements — closely modeled on the U.S. NIST SP 800-171 standard — have pushed Japanese defense and critical-infrastructure suppliers toward the same kind of formalized cybersecurity compliance that CMMC now enforces in the United States.

    Source: Exostar Technology Enables Fujitsu’s Trusted Supply Chainservice for Japan’s Defense and Critical Infrastructure Sectors — Exostar press release via PR Newswire, August 20, 2026, announcing its secure Microsoft 365 technology provision for Fujitsu’s new supply-chain security service in Japan.