The case for establishing an interoperable zero trust foundation for JADC2
Dan Schaaf is Senior Solutions Director and Army Sector CTO for GDIT, with more than 30 years’ experience implementing IT solutions and enterprise architecture for the U.S. Army and in the defense sector.
Defense officials for much of the past decade have recognized that future conflicts will require leaders to make decisions within minutes, or even seconds, and that the days of prolonged analysis are no longer an option. That concern was clearly spelled out more than three years ago by the National Defense Strategy Commission, which concluded that the state of the military’s Command and Control (C2) systems had “deteriorated” relative to potential competitors; and that the concept of a Joint All-Doman Command and Control (JADC2) network was clearly needed.
For all of the many strengths each of the services brings to the nation’s common defense, their central weakness remains the fact that the Air Force, Army, Marine Corps, Navy and Space Force each rely on separate and incompatible information networks. This reality leaves the Defense Department, and its ability to effectively defend and protect America’s interests, increasingly at risk.

Dan Schaaf, Senior Solutions Director and Army Sector CTO, GDIT
The vision for JADC2 is to create a single network to connect sensors to weapons systems and deliver information advantage at the speed of relevance. Currently the services are developing transformational IT capabilities tailored to their own needs, focused on cloud, data platforms and the implementation of zero trust. But for JADC2 to achieve warfighting capability, it is critical that DOD leaders put a stake in the ground and insist on establishing a set of common, foundational capabilities that will ensure that mission critical data can move across the DOD securely; data can be shared and analyzed where and when it’s needed; and the data can be trusted.
It is broadly accepted that a DOD-wide implementation of zero-trust security is foundational to the success of JADC2. But if DOD leaders do not establish critical zero trust capabilities, there are very real risks that as each of the services develop their own service-centric cloud environments and data platforms, they will also implement service-centric zero-trust capabilities. Ultimately this will increase the complexity of the operating environment and short circuit the DOD’s ability to access and exploit the relevant data and services required for joint and multi-domain operations.
To that end, DOD leaders should establish a foundational set of common zero trust capabilities and then require the services, the defense industry and our mission partners to use and ideally leverage those foundational zero trust capabilities.
The value of establishing a foundational DOD zero trust capability can be found in examining the use case of DOD’s decision to establish a PKI root certification authority for all identity and access management initiatives. By mandating the use of a common PKI root certification, the Defense Department created an environment that maintained and promoted cross-service interoperability and trust while still enabling each service to individually deploy identity and access management services.
Conversely, we can also learn from the DOD deployment of network directory services where they did not mandate the use of a trusted root. Though that deployment occurred more than two decades ago, the DOD still faces challenges to effectively federate and consolidate the multiple network domains that were created within the DOD, and which continue to significantly hamper efforts to develop a unified DOD network.
A way forward for cross-DOD zero trust
To further illustrate this point and conceptually describe what foundational zero trust capabilities should be developed, Figure 1 below is the GDIT zero trust architecture which demonstrates two key innovative concepts: 1) federated security enforcement and 2) centralized and data driven policy decision capability
Figure 1: GDIT Zero Trust Architecture

Source: GDIT
Along the center of Figure 1 is a “Policy Administration” capability that we propose. It represents the federated security enforcement devices which control the connection to resources. These are typically devices like firewalls or other access control mechanisms and are distributed throughout the enterprise today; but they also represent new and emerging zero-trust technologies that provide micro-segmentation of a network or dynamically establish software defined perimeters around resources.
Our recommendation for a foundational zero trust capability is the “Policy Decision” capability (along the bottom of Figure 1) which integrates a policy engine, a trust engine and a single source of truth. When centrally developed and managed, this capability will enable the DOD to incrementally deploy zero trust capabilities as well as integrate existing security enforcement devices.
To develop the “Policy Decision” capability, it’s critical that the DOD establishes the ground rules for what constitutes authoritative data — and ultimately lay the foundation for an enterprise-wide authoritative data environment. It’s also crucial that security enforcement systems working at machine speeds can discern what’s authoritative and what’s not in real time. That’s especially important as artificial intelligence within the trust engine is processing the data to determine relative risk and thresholds so that it is delivering the highest quality input to the policy engine that will synchronize the security enforcement devices and technologies.
Logically, the zero trust foundational capabilities should be delivered from a DOD cloud infrastructure to ensure the zero-trust management platform can operate securely and is also accessible by each service, the defense industry, mission partners and their data systems. Commercial clouds offer significant advantage for general purposes, but for joint operations, data must be integrated and served up without the friction arising from such factors as ingress and egress costs, data locality challenges or stovepipes resulting from disparate multi and hybrid cloud architectures among the military departments. Likewise, it makes sense for DoD’s own standardized capability for policy enforcement in support of JADC2 to be held in reserve, and not have different, even competing access regimes across the services.
A DOD Enterprise cloud is especially important for this use case. For those reasons, we are recommending DISA’s milCloud 2.0 cloud and contract as the location for the zero trust foundational capabilities. It can host the same innovative capabilities that leading edge companies host in the commercial cloud today; and it is located securely on DISA’s premises and inside DOD’s information networks. It is also FedRAMP-certified to meet DOD Impact Level 5 security ratings (and soon to be IL-6 certified) and it’s already accessible by all DOD components and authorized DOD partners.
By putting the foundational zero trust capabilities in place now and establishing a secure and accessible control plane for zero trust, DOD has a better chance of ensuring that they can protect any resource, anywhere and at any time. And just as importantly, it will accelerate warfighter capability by ensuring data from sensors, users and applications operating on and across JADC2 can be trusted and be used more universally.
Why SD-WAN takes on greater importance in hybrid IT environments
As government organizations continue to expand their hybrid IT environments and adopt zero trust security practices, agency leaders will need to move away from traditional wide area networks (WAN) and adopt newer software-defined networking (SD-WAN) solutions, says a long-time federal security expert in a new report.
That transition takes on new importance in light of the May 2021 White House executive order outlining new requirements to embed stronger security controls embedded into federal IT enterprise networks, including implementing zero-trust security architecture within the year.

Read the full report.
The executive order follows more than a year of fast-tracked modernization initiatives by federal and state agencies to support their remote workforce, including the deployment of online as-a-service platforms, digital voice and video applications and robotic process automation.
“As agencies integrate more digital services, they are looking to tap into the dynamic connectivity of hybrid IT environments. [However,] overlay security tools are no longer capable of adapting to these environments,” said Jim Richberg, field CISO at Fortinet and former National Intelligence Manager for Cyber in the Office of the Director of National Intelligence.
The uptick in demand for faster, more user-focused and secure tools require infrastructure upgrades to provide higher bandwidth, scalability, flexibility and integrated security. Software-defined wide area networking (SD-WAN) is proving to be one of the fastest-growing segments of the network infrastructure which can provide all these things, according to information from Gartner cited a new Scoop News Report, underwritten by Fortinet and immixGroup,.
Integrating security and networking has never been more important, said Richberg, and he pointed to research from Fortinet which showed ransomware instances that arrived through the endpoint increase by 700% in the second half of 2020.
“Even with multifactor or endpoint security solutions, the reality is that organizations still don’t know what is going in the environment,” he said, adding that with cyberthreats today, organizations can’t afford to function as if the network and security are separate. These two functions are increasingly converged, and SD-WAN is able to treat it as such.
The report points to several key benefits of SD-WAN networking. Most importantly, it supports zero trust strategies, including the ability to validate devices and users on the network, close visibility gaps in a hybrid environment and automate security policy updates across the network. Additionally, it is available for federal agencies to purchase under the Enterprise Infrastructure Solutions (EIS) contract task order.
According to Richberg, a best-of-breed SD-WAN solution tightly integrates networking connectivity and security, meeting multiple networking needs at once.
The report highlights five ways that advanced SD-WAN solutions, like those from Fortinet can be “self-healing,” using automation.
The report also delineates why not all SD-WAN solutions deliver the same level of security capabilities. More robust solutions, for instance, embedded with tried-and-tested artificial intelligence and machine learning technology, give agencies the ability to achieve a common operating picture of their networks and respond to threats more quickly.
“Adding AI to policy-driven automation allows the system to validate users and deal with low level security anomalies automatically, which frees agency employees to focus on those more complex tasks where they need to exercise their skill and judgement,” the report concluded.
Read more about why transitioning to secure SD-WAN is the right choice for government agencies.
This article was produced by Scoop News Group and sponsored by Fortinet and immixGroup.
OMB gives agencies 60 days to identify critical software and begin securing it
The Office of Management and Budget has given federal agencies 60 days to identify all their critical software in use or being acquired and a year to secure it, according to a memo issued Tuesday.
OMB directed agencies to focus on securing standalone, on-premise software performing “security-critical” functions or posing “significant potential for harm” if compromised, during the initial implementation phase of critical software guidance released by the National Institute of Standards and Technology on July 8.
The latest mandate comes after President Biden on May 12 issued an executive order titled Improving the Nation’s Cybersecurity, which required NIST to define critical software to help agencies prevent its unauthorized access, secure data and quickly respond to threats.
“The United States faces increasingly sophisticated malicious cyber campaigns that threaten the public sector, the private sector and ultimately the American people’s security and privacy,” said the memo. “The federal government must improve its efforts to detect, identify, deter, protect against, and respond to these campaigns and their perpetrators.”
Phase 1 of implementing NIST’s guidance includes software handling: identity, credential and access management; operating systems, hypervisors and container environments; web browsers; endpoint security; network control; network protection; network monitoring and configuration; operational monitoring and analysis; remote scanning; remote access and configuration management; and backup/recovery and remote storage.
NIST will update its guidance as needed to launch subsequent phases covering additional software categories selected by the Cybersecurity and Infrastructure Security Agency, which agencies will have one year from release to address.
Subsequent phases will cover: software that controls access to data; cloud-based and hybrid software; software development tools like code repository systems, testing software, integration software, packaging software, and deployment software; software components in boot-level firmware; and software components in operational technology (OT).
NIST defined critical software as that which, or is dependent upon software that:
- is designed to run with elevated privileges or manage privileges,
- has direct or privileged access to networking and computing resources,
- is designed to control access to data or operational technology,
- performs a function critical to trust, or
- operates outside of normal trust boundaries with privileged access.
Some cybersecurity experts found NIST’s definition narrow at the time and feel Phase 1’s focus on security products — rather than industrial control, financial, health and election systems — goes against the spirit of the cybersecurity executive order.
“I’d say software is critical if compromised it would cause significant loss of human life or irreparable infrastructure damage or extensive financial harm,” Jeff Williams, chief Technology Officer at Contrast Security, told FedScoop. “Maybe undermining democracy if it’s an election system, but the definition as it’s written right now doesn’t touch any of those systems.”
It is possible NIST was just trying to get a definition out the door or faced pressure from system integrators reluctant to add additional security controls to the software they sell the government, Williams added.
Of the systems Williams wants addressed, only OT was mentioned in OMB’s memo as software to be targeted in a later phase — though it does leave room for agency discretion.
“Agencies should keep in mind that the measures identified in the guidance from NIST are not comprehensive,” reads the memo. “Their adoption may not eliminate the need to implement additional security measures to satisfy requirements and objectives that lie outside the scope of the NIST guidance.”
DOD awards $1B contract to Peraton to counter misinformation
The Department of Defense has awarded a task order worth up to $979 million over a five-year period to Peraton to counter misinformation from U.S. adversaries.
The contractor will provide services to U.S. Central Command and its mission partners with operational planning, implementation and assessment services.
Peraton has undertaken such work for Central Command since 2016 under its counter-threat messaging support program, and according to the company, the latest contract represents a doubling of work already scheduled to be carried out under the program.
Commenting on the contract, Tom Afferton, president of Peraton’s cyber missions sector, said: “Since 2016, Peraton has executed campaigns to promote regional security and stability. Our ability to provide the U.S. government with insight, expertise, and influence helps ensure the safety of Americans, our allies, and the more than 550 million people under U.S. Central Command’s area of responsibility, spanning three continents and 20 nations.”
The award comes after Peraton earlier this month won an IT infrastructure contract from the Department of Veterans Affairs, which could be worth up to $497 million over seven years.
The Virginia company will provide infrastructure-as-a-managed service for storage and computing infrastructure facilities across the U.S. and globally. Announcing the award, Peraton said it will deliver an enterprise-scale solution that integrates on-premise infrastructure with the VA’s enterprise cloud architecture.
Since 2016, the Department of Defense has worked with private sector contractors to counter-messaging from U.S. adversaries including ISIS across media, including social networks.
The fiscal 2016 defense authorization bill included a clause stating that the secretary of Defense should develop “creative and agile concepts, technologies, and strategies” across all available media to counter and degrade the ability of adversaries to persuade, inspire and recruit.
Award-winning broadcaster Francis Rose joins Scoop News Group as VP of Multimedia Solutions
Washington, D.C., August 11, 2021 — Scoop News Group, the leading tech media company serving C-Suite decision-makers in the Government IT community, announced today that it has hired award-winning news broadcaster Francis Rose as Vice President of Multimedia Solutions.
Joining SNG, Rose brings 20 years of experience covering the top storylines in all three branches of the U.S. government as well as the military. He will play a key role in supporting the company’s multimedia offerings and building upon Scoop News Group’s robust network of digital content across all of its brands.
“I am thrilled to welcome Francis to our team during this tremendous time of growth,” said Goldy Kamali, CEO of Scoop News Group. “As we continue to expand our multimedia offerings and unveil exciting new developments, Francis is the obvious choice. His passion for community, which is at the heart of everything we do as a company, as well as his leadership amongst federal decision-makers for over 15 years on television and radio, made this a perfect fit.”
Rose brings an extensive background covering the management and business of the federal government, most recently as the host of ABC 7’s Government Matters daily television program. With Scoop News Group, he will continue his work chronicling the federal community on-camera and behind the mic, producing an online video series and daily podcast, among other things.
“I’m excited to join the team of experienced, respected pros at Scoop News Group,” said Francis Rose. “I share the company’s commitment to building community among the people who drive the business of the federal government. I hope my experience and background in creating compelling audio and video content for those people complements and enhances Scoop News Group’s world-class reporting and events.”
About Scoop News Group
Scoop News Group is the leading gov tech media company in the country and is comprised of five digital news brands — CyberScoop, FedScoop, StateScoop, EdScoop and WorkScoop — that reach the top mission and IT decision-makers in government.
Built on a foundation of award-winning journalism and the most prestigious executive events in the government IT community, we engage top C-level decision-makers and influencers in government every single day through our widely-read digital publications, newsletters, podcasts, videos and world-class events.
Hyten calls on defense industry to deliver more timely solutions
The military’s No. 2 officer, Gen. John Hyten, wants more from the defense industrial base, saying contractors need to deliver more timely capabilities that offer “integrated deterrence.”
In remarks made Wednesday, the vice chairman of the Joint Chiefs of Staff said industry can support new concepts like Joint Warfighting more effectively. The comments come as Hyten prepares to retire from the military in November after four decades in uniform.
“We are not delivering an end game,” he told an audience at the Space and Missile Defense Symposium Wednesday. “We have to do that.”
Hyten called out one specific need to have more sensors and better data analysis on missile defense. It has been an area where the military has experimented with new types of data integration and collection, but Hyten doesn’t appear satisfied.
“I would like to have overhead sensors that a see everything,” he said.
Hyten is not the only high-ranking officer to ask industry to focus on new tech. Adm. Michael Gilday, chief of naval operations, recently told industry to stop lobbying Congress to require the military to buy old platforms he says it doesn’t need.
“Although it’s in industry’s best interest … building the ships that you want to build, lagging on repairs to ships and submarines, lobbying Congress to buy aircraft that we don’t need … it’s not helpful,” Gilday said at the Navy League’s Sea-Air-Space conference. “It really isn’t in a budget-constrained environment.”
Gilday later added what he does want to see form industry, not just what they should not do: “Industry can help pivot to new technologies and new platforms.”
Hyten said in order to get industry up to speed on the new direction the military wants to experiment in, the Joint Requirements Oversight Council (JROC) will be hosting an industry day where leaders will brief contractors on the Joint Warfighting Concept (JWC). The JROC sets requirements for the military’s platforms and weapon systems and has been working on requirements for more data sharing that services will need to implement in their acquisitions.
The JWC has four pillars that all revolve around having weapon systems that can connect and share data with one another in order to converge their capabilities. They include long rang precision fires, Joint All Domain Command and Control (JADC2), contested logistics and information advantage. All four are predicated on the ability to share data and integrate capabilities, like with JADC2 where all sensors would be able to connect and use artificial intelligence to analyze data coming from a battlefield like a military internet-of-things.
Senate passes $1T infrastructure bill
Senate lawmakers have passed a $1 trillion bipartisan infrastructure spending bill, which if enacted, would provide funding a range of new federal cybersecurity funding measures.
Among the proposals included in the draft legislation is a $100 million fund for responding to and recovering from cyberattacks, and $21 million in funding for recruitment at the recently formed Office of the National Cyber Director (NCD).
The legislation now progresses to the House of Representatives, where it will be debated – and potentially amended by – lawmakers.
In its current form, the bill would give the Cybersecurity and Infrastructure Security Agency a new authority to declare a significant cybersecurity incident in coordination with the Department of Homeland Security. Such a declaration would give the DHS secretary access to the $100 million recovery fund. CISA would then have responsibility for managing the federal and non-federal response to such an attack — a measure that is intended to assist in the future response to digital security breaches such as the Colonial Pipeline hack in May.
The proposed $21 million included in the bill text gives NCD the budget to hire new cybersecurity staff, an issue that remains a major concern for federal officials in a tight labor market.
Progress of the infrastructure bill through the Senate was obstructed by disagreement over amendments, including the proposed introduction of new cryptocurrency reporting requirements. Lawmakers Tuesday morning voted 69-30 to approve the bill.
Other amendments that fell away before the bill progressed included a proposal by Senate Appropriations Committee ranking member Richard Shelby, R-Ala., which could have provided $2.5 billion for the rollout of 5G wireless technology at Department of Defense facilities.
Commenting on the passage of the bill, Sen. Gary Peters, D-Mich., said: “These provisions will help strengthen cybersecurity at every level of government, protect sensitive personal information, and strengthen our response to online assaults by providing the federal government and other public and private entities, such as critical infrastructure companies, with the resources to prevent and recover from attacks.”
How the pandemic served as catalyst for advancing zero trust
Zero-trust principles have encompassed cybersecurity discussions in one form or another for much of the past two decades. However, the widening adoption of the cloud, ever more sophisticated cyberattacks, and the rapid shift to employees working from anywhere, have pushed the need for zero trust architecture to top of agency IT priority lists.
At the same time, the pandemic served as a catalyst for accelerating security measures in government, say government sector cybersecurity experts during a recent IT security panel discussion.
“There are three subsets of culture that I’ve seen, thankfully, be changed positively through the pandemic that relate to cybersecurity and zero trust,” says Juliana Vida, chief strategy advisor at Splunk, and a former deputy CIO at the Pentagon.
“One of them is risk acceptance,” she says. She pointed to how the Department of Defense “put almost a million people into a remote work environment… leveraging cloud technology because they had to. They just didn’t have a choice anymore. It was [like] a burning platform — and a motivating factor…to accept certain levels of risk that maybe they wouldn’t have a year and a half ago,” she says. “And I think that’s a positive thing, because there are many other barriers in place that probably are worth reviewing.”
A second change was reflected in ways in which position — and who has priority in government organizations — are often tied to physical buildings, she says. “I think we’ve seen a leveling of the playing field, where all voices [and ideas] are equally important” with virtual meeting platforms. The pandemic helped “bust” certain social paradigms around work, she maintains.
The third change revolves around what Vida referred to as the “Big R” — requirement documentation in the government. “Yes, it’s still important. But I think what we saw in the last year was that the definition of what a requirement is, has changed. You could say that the pandemic is the requirement for having modern technology — for having agile and scalable cloud platforms — because you must modernize,” she argues. “Because if you don’t, you can’t work. To me, that’s the ultimate requirement.”
Many of those same themes hold true for Renata Spinks, acting senior information security officer and chief technology officer for the U.S. Marine Corps, who also shared her perspectives on security, zero trust and the impact of the pandemic during the panel discussion.
“I think the largest takeaway for me has been taking a look at what your risk acceptance model is. And the only way that you can truly make an assessment of where you will accept risk is knowing your landscape, understanding that terrain, and knowing where my enterprise begins and ends,” she says.
Spinks concurred with Vida about shifting social paradigms at work and the expanded notion of requirements in light of the changes agencies went through over the past year. “I’m going to add one more word, which is resilience,” she says. Agencies need to focus not only on evolving risks and requirements, but also on operational resilience to better manage the unexpected.
“I think the thought process of remote work and distributed workforce — meaning you’re working from multiple locations… because you need to — that’s why zero trust is so important in understanding those behaviors and making sure that you… have just what you need from a technology perspective,” she says.
“Now, with the emphasis on remote work and remote learning and telehealth, there’s just more of a general understanding across all sectors of American society that we need to pay attention to this. So that’s a good thing. I just hope that the momentum carries forward. It’s time to modernize and really lean into this zero-trust architecture,” she says.
“One of the biggest lessons that we’ve seen,” adds Vida, “and that I hear customers constantly talk about, is the power of cloud technology. Agencies that had already moved into the cloud — or had elements of any kind of hybrid cloud architecture — were able to pivot faster than those who didn’t. That’s because cloud provides the agility, the scale and the flexibility that is absolutely necessary to drive into a digital environment. And the cloud has the ability to manage, share, and manipulate huge volumes of data.”
Vida, like many IT advisors, cautioned against a “lift and shift” approach and instead, focusing on moving workloads in ways that capitalize on cloud-based applications and services. She also recommended that agencies continue to look at cloud platforms to break down silos, share information. “Because that’s where the power of data is — in leveraging everything that exists in an enterprise. I think we’re going to see a continuation of that because it drives efficiencies, drives economies of scale, and it just builds better partnerships,” she says.
Spinks reinforced that point by stressing the importance of establishing “the conditions for not only adopting cloud but employing cloud in your environment.”
“The Marine Corps migrated to an Office 365 environment what looked like very quickly,” she says, “but what we don’t talk a lot about is our infrastructure challenges that we had to overcome. And we spent countless hours with sometimes-planned outages and sometimes not. I would submit, even outside of the DoD — having come from Treasury and Department of Homeland Security — infrastructure across the world is just a place we’re going to have to really invest in.”
View the full on-demand discussion with Renata Spinks and Juliana Vida. And learn more about how Splunk is helping government secure their IT environments and strengthen their zero-trust architecture.
GAO denies Salient’s protest of US Patent Office’s $2B IT contracts
The Government Accountability Office denied Salient CRGT’s protest of five contracts worth $2 billion awarded by the U.S. Patent and Trademark Office for IT modernization, in a legal decision released Monday.
Salient contended USPTO‘s analysis of proposals didn’t align with the Business-Oriented Software Solutions (BOSS) solicitation’s evaluation scheme, which based awards on the highest technically rated proposals with “fair and reasonable” prices.
GAO found USPTO’s comparative analysis and awards to Booz Allen Hamilton, Halvik Corporation, RIVA Solutions, Science Applications International Corporation (SAIC), and Steampunk Inc. were “reasonable, adequately documented and consistent” with the solicitation.
“Salient does not identify, and our review of the record does not find, any distinguishing aspect of either Salient’s or Booz Allen’s proposal that the agency failed to consider,” reads GAO’s decision made July 21. “We deny this ground of protest.”
BOSS primarily sought agile development teams for modernization and maintenance of USPTO IT, and five 10-year, indefinite-delivery, indefinite quantity contracts were awarded — three to small businesses. After technical rating and pricing, criteria were ranked as follows: small business participation, technical approach, past performance, and program management and staffing approach.
After selecting three small business proposals, USPTO found SAIC’s higher technically rated than Salient’s and selected them along with Booz Allen as the highest technically rated non-small business proposals.
Salient protested USPTO’s analysis on the grounds the agency weighted past performance and program management and staffing approach — areas where the large businesses received “superior” ratings to Salient’s “satisfactory” ones — more heavily. SAIC’s overall rating was inflated as a result, Salient argued.
“The agency contends that it properly found SAIC’s proposal to be higher technically rated than Salient’s because the relative benefits identified in SAIC’s proposal under the most important factor, small business participation, as well as under the past performance factor, and the program management and staffing approach factor, outweighed the relative benefits identified in Salient’s technical approach,” reads the decision.
USPTO evaluated the small business participation and subcontracting plans of large business offerers Booz Allen and SAIC. SAIC proposed 36% of contract work would be done by small businesses, compared to Salient’s 27%, leading GAO to side with USPTO’s decision.
Salient also protested the award to Booz Allen on the grounds the company’s proposal was unreasonably found higher technically rated that SAIC’s, during a comparative analysis of just those two proposals.
Booz Allen proposed the worst small business participation of the three companies, which Salient felt meant they’d win out in a comparative analysis between the two. But GAO agreed the advantages of Booz Allen’s technical approach outweighed participation shortcomings.
Booz Allen, SAIC and Salient did not respond to a request for comment.
DOD considering marketplace for smaller cloud vendors as follow-on to JEDI replacement
The Department of Defense will look at setting up a marketplace for smaller cloud vendors as a “follow-on” contract to the eventual Joint Warfighter Cloud Capability (JWCC) acquisition.
Research about the potential launch of such a marketplace will take place after JWCC has been awarded, and is not expected to begin until April 2023.
Details of the JWCC were made public last month, after the DOD announced it was canceling the JEDI contract, following a nearly-two year acrimonious bid dispute of the contract’s initial award to Microsoft.
Danielle Metz, deputy CIO for information enterprise at the DOD, revealed details of the future program earlier this week to a virtual audience at a Potomac Officers Club conference.
“It will not be exclusive to the five U.S.-based hyperscale cloud service providers, but it will be available to anyone, any integrator or cloud service provider, that can meet the department’s requirements,” Metz said.
JWCC, on the other hand, will only be open to the largest “hyperscale” cloud providers, like Amazon Web Services and Microsoft, whose cloud systems are capable of offering secret and top-secret cloud environments
The goal of opening up to more service providers is to be able to provide services that fit across the department’s many mission areas. The idea of a marketplace was teased by acting CIO John Sherman when the JWCC was first announced.
Metz added that she expects by the time market research begins, the DOD will be much more “cloud fluent” and industry will have new technical innovations to offer.
Correction: Aug 11, 2021. This article was updated to clarify that the proposed marketplace will be a separate follow-on contract, rather than a part of the JWCC procurement itself.