---
title: "Why Only 500 Apps Can Sell to the U.S. Government"
episode: 94
podcast: "The LeanScale Podcast"
publisher: "LeanScale"
guest: "Irina Denisenko"
guest_title: "CEO, Knox Systems"
date_published: 2026-07-17
date_modified: 2026-07-22
duration: 00:54:34
word_count: 9482
topics: ["enterprise-sales", "gtm-strategy", "mergers-acquisitions", "pricing-packaging", "brand-positioning"]
canonical_url: https://leanscale-knowledge-hub.netlify.app/podcast/irina-denisenko-knox-selling-to-government/
source: "LeanScale Podcast Knowledge Hub — https://leanscale-knowledge-hub.netlify.app"
license: "Free to quote and cite with attribution to The LeanScale Podcast."
---

# Why Only 500 Apps Can Sell to the U.S. Government

_Irina Denisenko on FedRAMP, the federal sponsor bottleneck, and turning a 3-year, $3M gauntlet into 90 days_

**Episode 94 · The LeanScale Podcast**  
Irina Denisenko, CEO, Knox Systems · Hosted by Anthony Enrico  
Published July 17, 2026 · Updated July 22, 2026 · 00:54:34  
Canonical: https://leanscale-knowledge-hub.netlify.app/podcast/irina-denisenko-knox-selling-to-government/

**Topics:** Enterprise & Public-Sector Sales · GTM Strategy · Mergers & Acquisitions · Pricing & Packaging · Brand & Positioning


## Executive summary

There are fewer than 500 software applications cleared to sell to the U.S. federal government. Anthony Enrico points out he has more than that on his iPhone. That gap is the shape of a $150 billion annual market that almost no vendor can get through the door of — and it is the subject of this conversation with Irina Denisenko, CEO and co-founder of Knox, a FedRAMP managed cloud built to unlock the federal market for modern SaaS.

Irina's authority is lived, not theoretical. As co-founder and COO of Class (class.com) she went through the full FedRAMP gauntlet, then did something almost no one else has: rather than grind through a three-year, $3M authorization from scratch, she acquired the 15-year-old managed service provider that already ran Adobe's federal applications — because the fastest (if not cheapest) way to get FedRAMP is to buy a company that already has it. Two years later she spun that boundary out as Knox with her co-founders, the acquired firm's CTO and chief architect. Today Knox runs Adobe's federal infrastructure as anchor tenant plus 50+ customers (ClickHouse, Sierra AI, Armis, BigID, Celonis), holds 16 agency sponsorships across the DoD/DoW, DHS, VA, Treasury, and Commerce, and moves companies through the process in 90 days.

The heart of the episode is a clear-eyed tour of what FedRAMP actually demands and where it really breaks. Technically, it means carving your commercial app into a separate enclave, turning on encryption you probably don't have, dropping any subprocessor that isn't itself FedRAMP, and passing a tax-audit-style assessment by an accredited 3PAO (Coalfire, Schellman) against 425 controls — versus roughly 95 for SOC 2 — then re-auditing forever, with continuous monitoring and 30/90-day remediation SLAs. But the controls aren't the hard part. The hard part is getting a federal sponsor — a CISO or CIO willing to underwrite your cyber risk with their reputation and their job, knowing a breach could put them in front of a Senate subcommittee. It's the one piece of the process you literally cannot buy, because paying for it is bribery. Sponsors come from mission owners pushing top-down and bottom-up over years, with no guarantee of success.

Irina reframes the payoff in ways most operators miss. Scarcity creates monopoly and duopoly economics: only ServiceNow and Salesforce are FedRAMP for ITSM; only Oracle and Workday for the HRIS RFP that Oracle just won for $100M at OMB. The government can't easily buy anything under $1M and buys for 10,000–100,000 users at a time, so ACVs and deal sizes dwarf commercial norms — but it wants vendors already proven at commercial scale (recognizable enterprise logos, ~$50M revenue). And FedRAMP throws off a 'halo effect': the first call after a certification press release is usually not a government agency but a commercial financial-services or healthcare buyer who treats FedRAMP as a pre-diligenced, CYA-grade environment. At Class, FedRAMP unlocked $20M in ARR — only $5M of it government; $15M was commercial. Irina argues FedRAMP is becoming a 'super SOC 2,' made more urgent because AI has collapsed breach-to-exploit time from ~45 days to under a minute.

Who should listen: founders and CEOs weighing whether (and when) to pursue federal, revenue executives sizing the ACV and deal-cycle math of public-sector selling, and any GTM leader in a regulated market wondering whether a compliance investment can become a commercial moat. The throughline is that public-sector go-to-market is less a sales problem than a market-structure and trust problem — and the vendors who clear the bar inherit durable, sticky, multi-year demand almost no one else can touch.


## Key takeaways

1. **Fewer than 500 apps can sell to the U.S. government — and that scarcity is the opportunity** — FedRAMP is so hard that under 500 applications hold it today, against a $150B annual federal IT market (about half of it cyber and adjacent tooling). More than 80% of that spend is still trapped in legacy on-prem systems (COBOL, AllScripts, Lotus Notes) that are, in Irina's words, sitting-duck security risks.
   _Why it matters:_ The barrier that keeps you out is the same barrier that protects you once you're in. Treat FedRAMP as a market-entry moat, not just a compliance checkbox.
   _For:_ Founders, Revenue Executives

2. **The 425 controls are hard; the federal sponsor is harder** — FedRAMP High requires ~425 controls versus ~95 for SOC 2, plus a separate enclave, heavy encryption, FedRAMP-only subprocessors, and a 3PAO assessment. But the true bottleneck is getting a CISO or CIO to sponsor you — to underwrite your cyber risk with their reputation and their job on the line.
   _Why it matters:_ Budget and plan around the sponsor, not the technical controls. You can throw money and engineers at the controls; you cannot engineer your way past a human being who has to stake their career on you.
   _For:_ Founders, Revenue Executives, Sales Leaders

3. **You literally cannot buy a sponsor — that's bribery** — Every other part of FedRAMP can be solved with enough money, time, and resources. The single exception is the sponsor: paying for it is bribing the government and is illegal. Sponsors are won through mission owners, program budget holders, networking, and top-down/bottom-up pressure — often over multiple years, with programs and priorities that can evaporate before you finish.
   _Why it matters:_ Federal go-to-market is a relationship and mission-alignment motion, not a procurement transaction. Find the funded mission that must have your tool, then work the system from both the program owner and the political/appointee level.
   _For:_ Revenue Executives, Sales Leaders, Founders

4. **Scarcity manufactures duopolies — and duopoly pricing and quality** — Because so few vendors clear FedRAMP, whole software categories run on one or two options. Only ServiceNow and Salesforce are FedRAMP for ITSM (against 50+ commercially); only Oracle and Workday competed for the OMB HRIS RFP. Products in these positions run years behind their commercial versions and command monopoly-grade pricing.
   _Why it matters:_ If you can become the third (or first modern) FedRAMP option in a category, you enter a market with structurally weak competition and pricing power that doesn't exist commercially.
   _For:_ Founders, Revenue Executives

5. **The fastest way to get FedRAMP can be to buy a company that already has it** — Rather than build from scratch, Irina acquired the 15-year-old MSP running Adobe's federal boundary to get her prior company FedRAMP fast — 'not the cheapest, but the fastest way.' When friends asked how she did it, the answer ('I had to buy a company') shut the conversation down, which is exactly what revealed the Knox opportunity: productize the boundary so others can inherit it.
   _Why it matters:_ In authorization-gated markets, an acquisition of an already-authorized asset can beat a multi-year organic build. The same logic is why Knox's 'inherit the boundary' model works.
   _For:_ Founders, Revenue Executives

6. **The 'luxury condo' model: inherit the boundary and the sponsors instead of building your own house** — Doing FedRAMP alone is like breaking ground on a house in the most exclusive zip code. Knox runs the condo building; customers move into a single-tenant floor, bring their own furniture (CI/CD, APM stack, hyperscaler), and inherit ~80% of the 425 controls plus Knox's 16 (soon 20) agency sponsors — collapsing three years into 90 days.
   _Why it matters:_ Compliance infrastructure can be a shared, inheritable asset. The sponsor inheritance — not just the technical controls — is what makes the speed possible.
   _For:_ Founders, Revenue Executives

7. **The government buys at scale — and rarely for under $1M** — It's very hard for the federal government to buy anything for less than $1M straight out of the gate; the contracting overhead makes smaller deals a waste. Agencies buy for 10,000–100,000 users at a time, and lean toward vendors already proven at commercial scale with recognizable enterprise logos.
   _Why it matters:_ Recalibrate ACV and deal-cycle expectations upward. A federal deal can be an order of magnitude larger than your biggest commercial deal — but you must be able to prove enterprise-scale delivery in the 'quals.'
   _For:_ Revenue Executives, Founders

8. **Self-assessment before you spend a dollar: have you proven yourself commercially?** — The gating question is whether you've delivered at enterprise scale for a brand the government recognizes — everything else (the enclave, the assessor, the controls) can be spun up. Commercial-first companies typically pursue federal around ~200 people and ~$50M revenue; defense-tech companies that are government-first can go as small as 50–75 people.
   _Why it matters:_ If you can't list hefty logos at scale in an RFP response, you'll struggle regardless of your product. Earn commercial credibility first, then pursue federal.
   _For:_ Founders, Revenue Executives

9. **The FedRAMP 'halo effect': your first call is a commercial buyer, not a government agency** — After a FedRAMP announcement, the first inbound is usually an existing commercial customer in financial services or healthcare, because FedRAMP is treated as a pre-diligenced environment the Air Force, Army, DHS, and Treasury have already signed off on. It functions as a CYA mechanism for a buyer's own CISO — valuable even if you never believe it's strictly 'more secure.'
   _Why it matters:_ Underwrite the FedRAMP investment partly on commercial upside. In regulated markets it's a differentiator that closes deals long before the first government contract.
   _For:_ Founders, Revenue Executives

10. **FedRAMP is becoming the 'super SOC 2' — and it doesn't have to include the government** — SOC 2 went from 'maybe I need it' to 'don't even call me without it.' Irina sees FedRAMP (or a FedRAMP equivalency) trending the same way for true-enterprise buyers deploying 10,000+ users. At Class, of the $20M ARR FedRAMP unlocked, only $5M was government (Air Force, Army TRADOC); $15M was financial services, healthcare, and enterprises like BCG and Coca-Cola.
   _Why it matters:_ Even a company with zero government ambition can justify FedRAMP as a commercial-positioning play in cyber-sensitive, over-indexed-on-compliance markets.
   _For:_ Founders, Revenue Executives

11. **AI makes hardening urgent: breach-to-exploit collapsed from ~45 days to under a minute** — Research (CrowdStrike, Kaspersky, McAfee) put the mean time from system access to exploitation around 45 days; in the last year it has dropped to under a minute, driven by an effectively infinite supply of thinking, brute-forcing black-hat agents. Legacy government systems full of decades-old known vulnerabilities become national-security risks.
   _Why it matters:_ The security rationale for FedRAMP and for modernizing off legacy systems is accelerating, not stable. Compliance timelines that assumed a slow threat environment are now dangerously behind.
   _For:_ Founders, Revenue Executives, Sales Leaders

12. **Federal revenue is sticky both ways — a pro and a con** — Government contracts are big, long-term, and very sticky, so once you're in, you're in. The flip side: any doubt that you'll be around for the next 10 years can lose you the deal before it starts, which is why proven commercial durability matters so much in the quals.
   _Why it matters:_ Position for longevity, not just capability. Multi-year deployments (train, change-manage, roll out to tens of thousands) mean the buyer is really choosing a decade-long partner.
   _For:_ Revenue Executives, Sales Leaders, Founders

13. **The upside is generational: $100M checks the commercial market can't match** — In just the prior 30 days, Oracle won a ~$100M HRIS contract for the Office of Management and Budget (Oracle vs. Workday, another duopoly) — reportedly a per-year, multi-year award replacing an 1980s-era system. Even 'non-sexy' categories like HRIS produce nine-figure deals.
   _Why it matters:_ For the right company, a single federal contract can fundamentally change who you are in the market. That asymmetric upside is what makes the multi-year, sponsor-gated slog worth modeling seriously.
   _For:_ Founders, Revenue Executives


## Frameworks

### FedRAMP (Federal Risk and Authorization Management Program) (01:40)

**Definition:** A government-wide set of security and compliance controls a technology company must meet before U.S. federal agencies are allowed to put government data into its system. FedRAMP High carries ~425 controls (versus ~95 for SOC 2) and requires a separate enclave, encryption in transit and at rest, FedRAMP-only subprocessors, and assessment by an accredited third-party assessor.

Irina frames FedRAMP as the driver's license for federal software: you can't even bid without it. It is much larger and more involved than SOC 2, and only ~500 applications have achieved it, which is precisely why the market behind it is so under-served.

### The Federal Sponsor & Authorization to Operate (ATO) (07:00)

**Definition:** After a 3PAO assessment, a company must find a federal sponsor — a CISO or CIO within an agency (or the DoD/DoW) willing to underwrite its cyber risk and grant an Authorization to Operate. This is the step where a senior official stakes their reputation and job on the vendor.

Irina calls this 'easily the hardest part.' A breach can put the sponsoring official in front of a House and Senate subcommittee and usually ends their tenure, so sponsors are structurally risk-averse — which is why so few applications clear the bar.

### You Can't Buy a Sponsor (10:40)

**Definition:** Every part of FedRAMP can be solved with enough money and time except getting the sponsor — paying for that is bribing the government and is illegal. Sponsors are won through funded mission owners, program budget holders, networking, and combined top-down (political appointees, agency secretaries) and bottom-up pressure.

This reframes federal GTM as a mission-alignment and relationship motion with no guaranteed path or timeline. A program can disappear before a multi-year sponsorship effort concludes, adding to the scarcity of authorized apps.

### Continuous Monitoring (the Forever-Audit) (05:14)

**Definition:** FedRAMP is annually re-audited and requires monthly continuous monitoring: a check-in with the government across CVEs, misconfigurations, and overall security posture, with strict remediation SLAs (30 days for high-criticality findings, 90 days for medium).

Beyond the multi-year, multi-million-dollar initial authorization, maintenance runs at least $500K–$1M per year forever. FedRAMP is a standing operational commitment, not a one-time certification.

### The Exclusive Zip Code & Luxury Condo Model (22:58)

**Definition:** Doing FedRAMP alone is like buying land in the most exclusive zip code and building your own house (permits, architects, supplies, inspection, forever). Knox instead runs the 'luxury condo building' on Main Street: customers move into a single-tenant floor, bring their own furniture (CI/CD, APM, hyperscaler), and inherit ~80% of the 425 controls plus Knox's agency sponsors.

The metaphor captures why inheritance collapses a three-year build into 90 days: the boundary, infrastructure, and — critically — the sponsors already exist. Customers come as they are rather than re-architecting their application.

### Acquire-to-Accelerate (Buy the Authorization) (25:34)

**Definition:** In an authorization-gated market, the fastest (if not cheapest) route to FedRAMP can be to acquire a company that already holds it, then build on that boundary — rather than pursue a multi-year organic authorization.

Irina used this to get Class FedRAMP by acquiring the MSP behind Adobe's federal apps; realizing the tactic wasn't reusable by others ('I had to buy a company') is what surfaced the Knox productization opportunity.

### FedRAMP Duopoly Economics (15:10)

**Definition:** Because so few vendors clear FedRAMP, entire federal software categories run on one or two authorized options — ITSM has only ServiceNow and Salesforce; the OMB HRIS RFP came down to Oracle and Workday. Monopoly/duopoly conditions push prices up and product quality years behind commercial equivalents.

This is the market-structure argument for pursuing FedRAMP: entering a category with one or zero modern competitors yields pricing power and demand that don't exist in the crowded commercial market.

### The $1M Floor & Buying at Scale (32:27)

**Definition:** The federal government rarely buys anything for under $1M — the contracting overhead makes smaller deals uneconomic — and it purchases for 10,000–100,000 users at a time, favoring vendors already proven at commercial scale.

Deal sizes are an order of magnitude above commercial norms (where a big enterprise deal might be low-hundreds-of-thousands), but agencies de-risk by choosing vendors with recognizable enterprise logos that have handled comparable scale and bureaucracy.

### Federal Readiness Self-Assessment (35:25)

**Definition:** Before spending a dollar on federal, ask whether you've proven yourself at enterprise scale commercially — the one gate that can't be spun up. Commercial-first companies typically qualify around ~200 people / ~$50M revenue with a few enterprise logos; defense-tech, government-first companies can pursue it as early as 50–75 people.

Everything technical about FedRAMP can be built; commercial credibility cannot be faked in the RFP 'quals,' where you must name hefty logos at scale. Readiness is mostly a proof-of-scale question.

### The FedRAMP Halo Effect (Super SOC 2) (37:10)

**Definition:** FedRAMP acts as a pre-diligenced, CYA-grade trust signal in commercial regulated markets. After a certification announcement the first inbound is often a financial-services or healthcare buyer, not a government agency — so FedRAMP behaves like a 'super SOC 2' that differentiates and closes commercial deals.

At Class, FedRAMP unlocked $20M ARR of which only $5M was government and $15M was commercial. Even companies with no federal ambition can justify FedRAMP as a positioning play in cyber-sensitive markets, and Irina expects a FedRAMP equivalency to trend toward table stakes for true-enterprise buyers.


## Quotes

_Speakers inferred from an undiarized transcript — verify before attributing._

> "If you're a SaaS product, you are going to have to achieve FedRAMP. And indeed, there's less than 500 applications that have it today, because it is so challenging."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (02:04)

> "SOC 2 has about 95 controls, and FedRAMP High, where most folks want to be, has 425. So it is a much bigger, much more involved process."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (04:00)

> "It's my reputation on the line, and frankly it's my job on the line. More likely than not, I'll be sitting in front of a House and Senate subcommittee being grilled on what happened."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (07:52)

> "The one piece of this entire process that you literally are not allowed to throw money at is getting the sponsor, because that's called bribing the government, and that's illegal."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (10:40)

> "There's 500 applications approved, which to me is mind-boggling, because I'm pretty sure I have more than 500 apps on my iPhone."
>
> — Anthony Enrico, The LeanScale Podcast Ep. 94 (13:56)

> "For the folks that have FedRAMP, they are operating in basically monopoly conditions."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (14:32)

> "Today, there are two solutions that provide ITSM. One is called ServiceNow and one is called Salesforce that are FedRAMP."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (15:10)

> "AI has really changed the landscape. Something that took 45 days on average from entry to exploit is now down to under a minute, certainly under an hour."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (45:25)

> "What Knox does is we run the luxury condo building on Main Street in that zip code, and our customers move into a floor of that ever-growing skyscraper."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (22:58)

> "The fastest way — not the cheapest, but the fastest way — for me to get that company FedRAMP was to acquire a company that was already FedRAMP."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (25:34)

> "Everyone asked me how I did it, and I said, oh, I had to buy a company. And that immediately shut down the conversation."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (26:10)

> "On average, it is very hard for the US government to buy anything for less than $1 million, straight out of the gate."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (32:27)

> "You can't even get on the road without a driver's license. It's the same thing here — you can't even bid on these opportunities if you don't have FedRAMP."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (36:06)

> "The first call they get is actually not from a government agency. It's from an existing commercial customer who says, hey, I saw your FedRAMP announcement."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (37:10)

> "Getting FedRAMP for class.com unlocked $20 million of additional ARR. We were at 20 when we acquired; we were at 40 two years later, and all of that additional 20 came from getting FedRAMP."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (41:34)

> "This feels like it could be the super SOC 2 for some companies."
>
> — Anthony Enrico, The LeanScale Podcast Ep. 94 (44:11)

> "Oracle just won a $100 million contract for HRIS, for the Office of Management and Budget."
>
> — Irina Denisenko, The LeanScale Podcast Ep. 94 (47:47)


## Practical advice by role

### Founders

- Run the self-assessment before spending a dollar: the one gate you can't spin up is whether you've delivered at enterprise scale for a brand the government recognizes. Commercial-first companies typically get real around ~200 people and ~$50M revenue with a few hefty logos.
- If federal is one to two years out but you sell into financial services or healthcare, consider FedRAMP now for the halo effect — it's a commercial differentiator (a 'super SOC 2') that closes regulated deals well before your first government contract.
- In an authorization-gated market, evaluate acquiring an already-authorized asset instead of a multi-year organic build. Buying the boundary (or inheriting one via a managed cloud) is often the fastest path, even if not the cheapest.
- Model the asymmetric upside honestly: federal deals rarely fall below $1M and can reach nine figures, but they're multi-year, sponsor-gated, and slow. Weigh that against a maintenance cost of $500K–$1M per year, forever.

### Revenue Executives

- Recalibrate ACV and deal-cycle math for public sector: the government buys for 10,000–100,000 users at a time and rarely under $1M — an order of magnitude above a big commercial deal — but expects proof of enterprise-scale delivery in the RFP 'quals.'
- Target categories with duopoly or monopoly FedRAMP conditions (e.g., ITSM's ServiceNow/Salesforce, HRIS's Oracle/Workday). Being the third or first modern authorized option means pricing power and demand that don't exist commercially.
- Position for a decade, not a deal. Federal contracts are big and sticky, but any doubt you'll be around in 10 years loses them — lead with commercial durability and recognizable logos.
- Don't waste cycles you can't win: a federal buyer will end the conversation the moment they learn you aren't FedRAMP. Qualify the requirement first.

### Sales Leaders

- Organize federal pursuit around the sponsor, not the paperwork. Find the funded mission that must have your tool, arm the program/budget owner to make the case to the CIO, and work both top-down (appointees, secretaries) and bottom-up.
- Never treat the sponsor as something to buy or shortcut — it's illegal, and the entire relationship dies on the attempt. It's earned through networking, mission alignment, and pressure over time.
- Build your quals library early: name-brand enterprise references at scale (think Coca-Cola, P&G, BCG, banks, hospital systems) are what let a government buyer get comfortable, since no one gets fired for choosing a proven name.


## AI takeaways

**Thesis:** AI is the accelerant that makes FedRAMP urgent, not optional. By collapsing breach-to-exploit time from ~45 days to under a minute, AI turns legacy government systems into national-security liabilities — while AI-native companies like Sierra AI race to clear FedRAMP so the government (and regulated commercial buyers) can use them.

- **AI compressed the attack window to near-zero** — An effectively infinite supply of thinking, brute-forcing black-hat agents dropped mean time from access to exploit from ~45 days to under a minute in a single year — the security case for hardening and FedRAMP is accelerating fast.
- **Legacy systems are sitting ducks** — 80%+ of the $150B federal IT market runs on decades-old on-prem systems (COBOL, AllScripts, Lotus Notes) with long-known, easily exploited vulnerabilities — exactly what AI-era attackers target first.
- **AI-native software needs a federal on-ramp** — Sierra AI (Bret Taylor, Clay Bavor) achieving FedRAMP High via Knox shows the demand: reasoning agents for VA support, tax help, and airline rebooking can only serve the government once authorized.
- **The model explosion raises the stakes** — Irina notes how new and fast-moving the landscape is — Mistral, Fable, DeepSeek, Kimi, Qwen and others are only months old — making a FedRAMP or FedRAMP-equivalency baseline plausibly table stakes within 5–10 years.

**Agent & automation ideas**

- A federal-market intelligence agent that maps funded agency missions, budget/program owners, and sponsor relationships to a vendor's ICP — surfacing where a sponsor is winnable and which RFPs require FedRAMP.
- A compliance-evidence agent that continuously drafts and tracks continuous-monitoring artifacts (CVE remediation, misconfiguration findings) against the 30/90-day SLAs to lower the cost of maintaining FedRAMP.
- An RFP 'quals' assistant that assembles enterprise-scale reference logos and proof points into government-ready responses, since inability to show hefty logos at scale is the most common disqualifier.


## Operations takeaways

### Revenue operations

- **Federal readiness is a proof-of-scale gate.** The disqualifier isn't the controls (spin-up-able) but whether you can show enterprise-scale delivery for recognizable logos in the RFP quals — build that reference library before pursuing federal.
- **Requalify pipeline on the FedRAMP question.** A federal buyer ends the conversation the moment they learn you aren't FedRAMP — instrument qualification so reps don't burn cycles on unwinnable public-sector deals.
- **Recalibrate ACV and cycle length.** Deals rarely fall below $1M, buy for 10K–100K users, and run multi-year — the unit economics and forecasting assumptions differ by an order of magnitude from commercial.
- **Underwrite FedRAMP on commercial upside too.** The halo effect means much of the ROI shows up as financial-services and healthcare demand (at Class, $15M of a $20M unlock) — model both revenue streams, not just government.

### Pipeline & marketing ops

- **The sponsor is the real gate.** Federal pipeline stalls on getting a CISO/CIO to underwrite risk, not on the technology — orchestrate mission owners, budget holders, and appointees rather than running a standard sales sequence.
- **You can't buy or shortcut the gate.** Attempting to pay for a sponsor is illegal; progress comes from mission alignment, networking, and combined top-down/bottom-up pressure, often over years with no guaranteed close.
- **Duopoly categories are the softest targets.** Where only one or two vendors are FedRAMP (ITSM, HRIS), competition is structurally weak and multi-year behind — prioritize entering those categories.
- **Commercial announcements generate federal-adjacent inbound.** A FedRAMP press release most often first draws a regulated commercial buyer — route that halo-effect inbound deliberately, not just government demand.

### Customer operations

- **Federal deployments are multi-year commitments.** At 10K–100K users, deployment, training, and change management take a year or more — the buyer is choosing a decade-long partner, so staff for the long tail.
- **Stickiness cuts both ways.** Government contracts are big and hard to displace once won, but any doubt about your 10-year durability loses the deal up front — reinforce longevity throughout the relationship.
- **Continuous monitoring is an ongoing ops load.** Monthly ConMon check-ins with 30/90-day remediation SLAs and annual re-audits mean FedRAMP is a standing operational obligation, not a one-time certification.
- **Meet customers where they are.** Knox lets customers keep their own CI/CD, APM stack, and hyperscaler rather than re-architecting — reducing friction is core to the 90-day model and to adoption.


## Metrics mentioned

| Value | Metric | Context |
| --- | --- | --- |
| <500 | Apps with FedRAMP | Fewer than 500 software applications are cleared to sell to the U.S. federal government today — the scarcity at the center of the episode. |
| $150B / year | Federal IT market | Annual U.S. federal IT spend, roughly half of it cyber and adjacent tooling; 80%+ still stuck in legacy on-prem systems. |
| 425 vs ~95 | FedRAMP vs SOC 2 controls | FedRAMP High requires ~425 controls against roughly 95 for SOC 2 — a much larger, more involved process. |
| ~30 | Accredited 3PAO assessors | About 30 companies are accredited to assess applications against FedRAMP; Coalfire and Schellman are the two biggest. |
| 30 / 90 days | Continuous-monitoring SLAs | Remediation windows for high-criticality (30 days) and medium (90 days) findings during monthly continuous monitoring. |
| ~3 years · ~$3M | Traditional FedRAMP cost & time | The conventional path to FedRAMP, plus at least $500K–$1M per year to maintain it, forever. |
| 90 days · 80% of controls | Knox timeline & inheritance | Knox compresses the process to ~90 days; customers inherit ~80% of the 425 controls plus its agency sponsors. |
| 16 (→20 by year-end) | Knox agency sponsorships | Sponsorships customers inherit, across DoD/DoW (Army, Air Force, Navy), DHS, VA, Treasury, Commerce, and a long tail. |
| ~45 days → <1 minute | Breach-to-exploit time | Mean time from system access to exploitation has collapsed in the AI era, per CrowdStrike/Kaspersky/McAfee research. |
| >$1M · 10K–100K users | Government purchase floor & scale | It's hard for the government to buy anything under $1M; agencies buy for tens of thousands to 100,000+ users at a time. |
| +$20M ($5M gov / $15M commercial) | Class FedRAMP ARR unlock | FedRAMP grew Class from $20M to $40M ARR; only $5M was government (Air Force, Army TRADOC), $15M was financial services, healthcare, and enterprise. |
| ~200 people · ~$50M rev | Federal readiness threshold | Typical size for a commercial-first company to pursue federal; defense-tech, government-first firms can start at 50–75 people. |
| $100M (Oracle, OMB HRIS) | Largest recent check | Oracle won a ~$100M HRIS contract for the Office of Management and Budget in the prior 30 days — reportedly a per-year, multi-year award (Oracle vs. Workday). |


## Entities mentioned

- **Knox Systems** (company) — Irina's company; the FedRAMP managed cloud ('luxury condo') that lets customers inherit an existing boundary and 16 (soon 20) agency sponsors, compressing a 3-year, $3M process into 90 days. Runs on AWS/Azure/GCP as single-tenant sub-accounts; 50+ customers. · https://leanscale-knowledge-hub.netlify.app/company/knox-systems/
- **Adobe** (company) — Knox's anchor tenant; Adobe Connect, Adobe Learning Manager, and other Adobe apps ran in the federal boundary Knox was built on for ~15 years. · https://leanscale-knowledge-hub.netlify.app/company/adobe/
- **Class** (company) — Irina's prior company (co-founder & COO); achieving FedRAMP unlocked $20M ARR (from $20M to $40M), of which only $5M was government. The acquisition made to get FedRAMP fast seeded Knox. · https://leanscale-knowledge-hub.netlify.app/company/class-com/
- **Sierra AI** (company) — Bret Taylor and Clay Bavor's conversational-AI company; a recent Knox customer that achieved FedRAMP High — cited as a marquee example of AI-native software reaching the federal market (VA, airline rebooking, tax use cases). · https://leanscale-knowledge-hub.netlify.app/company/sierra-ai/
- **ClickHouse** (company) — Named among Knox's 50+ FedRAMP customers in the cold open. · https://leanscale-knowledge-hub.netlify.app/company/clickhouse/
- **Armis** (company) — Named among Knox's 50+ FedRAMP customers ('Armas' in transcript). · https://leanscale-knowledge-hub.netlify.app/company/armis/
- **BigID** (company) — Named among Knox's 50+ FedRAMP customers ('Big ID' in transcript). · https://leanscale-knowledge-hub.netlify.app/company/bigid/
- **Celonis** (company) — Named among Knox's FedRAMP customers (transcribed as 'Salonis'). · https://leanscale-knowledge-hub.netlify.app/company/celonis/
- **Coalfire** (company) — Named as one of the two biggest accredited FedRAMP third-party assessors (3PAOs), out of ~30 total, that audit an application against the controls. · https://leanscale-knowledge-hub.netlify.app/company/coalfire/
- **Schellman** (company) — Named alongside Coalfire as one of the two largest accredited FedRAMP 3PAOs. · https://leanscale-knowledge-hub.netlify.app/company/schellman/
- **CrowdStrike** (company) — Cited (with Kaspersky and McAfee) as a source of the breach-to-exploit research showing mean time from access to exploitation dropping from ~45 days to under a minute. · https://leanscale-knowledge-hub.netlify.app/company/crowdstrike/
- **Irina Denisenko** (person, guest) — CEO & co-founder of Knox, the FedRAMP managed cloud unlocking the U.S. federal market for modern SaaS; former co-founder/COO of Class (class.com). · https://leanscale-knowledge-hub.netlify.app/guest/irina-denisenko/
- **Anthony Enrico** (person, host) — Co-founder of LeanScale and host of The LeanScale Podcast. · https://leanscale-knowledge-hub.netlify.app/guest/anthony-enrico/
- **Salesforce** (tool, CRM) — Named as one of only two FedRAMP-authorized ITSM/help-desk options for the government (with ServiceNow), and invoked in the 'no one gets fired for choosing Salesforce' line — the duopoly example for federal software.
- **ServiceNow** (tool, ITSM Platform) — Named as one of only two FedRAMP ITSM solutions available to the government, against 50+ commercial help-desk options — Irina's core illustration of federal duopoly conditions.
- **Oracle** (tool, ERP / HRIS) — Cited as having just won a ~$100M federal HRIS contract for the Office of Management and Budget, and as one of only two FedRAMP HRIS options (with Workday) — the single biggest check discussed.
- **Workday** (tool, HRIS / HCM) — Named as the other FedRAMP HRIS option in the OMB modernization RFP that Oracle won — another federal duopoly.


## FAQ

**Q: How do you sell software to the U.S. government?**

A: To sell software to U.S. federal agencies you generally must achieve FedRAMP authorization, which lets the government put its data into your system. That means carving your app into a separate secure enclave, meeting ~425 security controls, passing an audit by an accredited third-party assessor (3PAO), and — the hardest step — getting a federal sponsor (a CISO or CIO) to grant an Authorization to Operate by underwriting your cyber risk. Without FedRAMP you can't even bid on most opportunities.

**Q: What is FedRAMP?**

A: FedRAMP (the Federal Risk and Authorization Management Program) is a U.S. government-wide set of security and compliance controls a technology company must meet before federal agencies can use its software with government data. FedRAMP High requires roughly 425 controls — versus about 95 for SOC 2 — plus encryption, FedRAMP-only subprocessors, an independent 3PAO assessment, a federal sponsor's authorization, and ongoing annual audits with monthly continuous monitoring. Fewer than 500 applications hold it today.

**Q: Why are there fewer than 500 FedRAMP-authorized applications?**

A: Because FedRAMP is extraordinarily hard and expensive — traditionally about three years and $3M, plus $500K–$1M a year to maintain forever. The biggest bottleneck is human, not technical: a senior federal official (CISO or CIO) must sponsor you by staking their reputation and job on your security, and they can't be paid to do it (that's bribery). Sponsors are won slowly through funded missions and networking, with no guaranteed success, so very few apps ever clear the bar.

**Q: Why is getting a federal sponsor the hardest part of FedRAMP?**

A: A federal sponsor — a CISO or CIO — has to underwrite your cybersecurity risk, meaning they personally vouch that putting sensitive agency data into your system is safe. If a breach happens, their reputation and job are on the line, and they may be grilled by a Senate subcommittee. You literally cannot pay for a sponsor because that is bribing the government. Sponsors are earned through funded mission owners, program budgets, networking, and top-down and bottom-up pressure, typically over years.

**Q: What is the FedRAMP 'halo effect'?**

A: The halo effect is FedRAMP's commercial payoff: after a company announces its authorization, the first inbound call is often not a government agency but an existing commercial customer in financial services or healthcare. Buyers treat FedRAMP as a pre-diligenced environment the U.S. military and major agencies have already vetted — a CYA signal for their own security teams. At Class, FedRAMP unlocked $20M in ARR, and $15M of it was commercial rather than government.

**Q: Is FedRAMP worth it if you never sell to the government?**

A: Often, yes. Irina describes FedRAMP as a 'super SOC 2' — a differentiator that closes deals in regulated commercial markets like financial services and healthcare that over-index on cybersecurity and compliance. Because so few companies have it and everyone understands how hard it is (she compares it to a PhD), it sets you apart even with buyers who aren't formally required to have it. She expects a FedRAMP equivalency to trend toward table stakes for true-enterprise buyers within 5–10 years.

**Q: How much does the U.S. government spend on software, and how big are the deals?**

A: U.S. federal IT spend is about $150 billion a year, roughly half of it on cyber and adjacent tooling. Because contracting overhead is so high, the government rarely buys anything for under $1M and typically purchases for 10,000 to 100,000 users at a time. Deal sizes dwarf commercial norms — a single recent example is Oracle's ~$100M HRIS contract for the Office of Management and Budget.

**Q: How does Knox get companies FedRAMP in 90 days?**

A: Knox runs a FedRAMP managed cloud — the 'luxury condo' model. Instead of building your own authorization from scratch (the 'exclusive zip code, build your own house' path), your company moves into a single-tenant floor of Knox's existing boundary across AWS, Azure, or GCP, brings its own CI/CD and monitoring, and inherits about 80% of the 425 controls plus Knox's 16-plus agency sponsors. Inheriting the sponsors and infrastructure is what compresses a three-year process into roughly 90 days.


## Timeline

- **00:00** — Cold open + intro
- **01:40** — What FedRAMP actually is (and the 425 controls)
- **05:30** — Continuous monitoring and the forever-audit
- **06:40** — The exclusive zip code: building your own house
- **07:00** — Why the federal sponsor is the hardest part
- **11:00** — How you actually get a sponsor — and why you can't buy one
- **15:20** — 500 apps, $150B: the most underbuilt market in software
- **16:00** — The ServiceNow / Salesforce duopoly
- **19:50** — 45 days to under a minute: why AI makes this urgent
- **24:50** — The luxury condo: FedRAMP in 90 days
- **28:40** — 'I had to buy a company': the Adobe origin story
- **33:40** — The smallest company that can pull this off
- **42:30** — The halo effect + the $20M ARR unlock
- **50:00** — FedRAMP as the new SOC 2
- **54:10** — The biggest check: Oracle's $100M government deal


## Related episodes

- **Ep. 87: Most Acquisitions Fail Like This — What Nobody Tells You About M&A** (Chris Heller) — Irina's 'I had to buy a company' origin story pairs directly with a deep dive on making acquisitions work. · https://leanscale-knowledge-hub.netlify.app/podcast/chris-heller-why-most-acquisitions-fail/
- **Ep. 89: Why He Left the CEO Seat to Become a CRO** (Alex Wakefield, AcuityMD) — A CRO's view from medtech — enterprise selling into a heavily regulated, compliance-gated market like the one FedRAMP creates. · https://leanscale-knowledge-hub.netlify.app/podcast/alex-wakefield-acuitymd-ceo-to-cro/
- **Ep. 88: Why AI Won't Close Your Biggest Deals** (Michael Kiernan, CRO at Nextdoor) — Enterprise deal reality and the limits of AI in complex selling — a companion to public-sector deal cycles and the AI-security urgency here. · https://leanscale-knowledge-hub.netlify.app/podcast/michael-kiernan-nextdoor-ai-wont-close-deals/
- **Ep. 91: Why Outcome-Based Pricing Is a Trap for Most AI Companies** (Roee Hartuv) — Pricing and packaging counterpart to the federal ACV, $1M floor, and duopoly-pricing discussion. · https://leanscale-knowledge-hub.netlify.app/podcast/roee-hartuv-outcome-based-pricing-trap/
- **Ep. 90: Why Your Niche Isn't Niche Enough** (Gary Frazier) — Positioning and differentiation — the flip side of using FedRAMP as a 'super SOC 2' moat and halo-effect signal in regulated markets. · https://leanscale-knowledge-hub.netlify.app/podcast/gary-frazier-niche-brand-positioning/
- **Ep. 95: Why AI Means More RevOps Hires, Not Fewer** (Jimmy O'Halloran, New Relic) — Enterprise GTM operating rigor plus the AI-and-data-security thread that runs through both conversations. · https://leanscale-knowledge-hub.netlify.app/podcast/jimmy-ohalloran-new-relic-revops-consumption-revenue/


## Full transcript

_Machine-transcribed and not diarized; speaker attribution is inferred._  
_Transcript only, as a separate file: https://leanscale-knowledge-hub.netlify.app/podcast/irina-denisenko-knox-selling-to-government/transcript.md_

### 00:00 — Cold open + intro

**[0:00]** Today, we're meeting with Irina Denesenko, CEO and co-founder of Knox, the company unlocking the U.S. federal market for modern Saas at speeds nobody thought possible. After living through the FedRAMP gauntlet at a prior company, Irina did something almost nobody else has. She acquired a 15-year-old managed service provider that already had a FedRAMP boundary serving Adobe, then built on top of it to create what she calls a luxury condo in the most exclusive zip code in software. Today, Knox runs the federal infrastructure for Adobe as its anchor tenant, plus 50-plus customers including ClickHouse, Sierra AI, Armas, Salonis,

**[0:44]** and Big ID. And a process that traditionally takes three years and three million dollars now takes only 90 days. In this conversation, Irina breaks down the real economics of selling into the U.S. government, the qualification framework every GTM leader needs before they spend a dollar on federal, and why this is the most under-built $150 billion market in software. Irina, thank you so much for being here. This is a huge topic and thing that companies are wrestling with that is really, really difficult to navigate through. I'd really like to kick off, I think anyone listening, very few know exactly what it takes to get through that

**[1:27]** FedRAMP process, and I would love if you could just walk us through the reality of what it means to be able to sell to the federal government. Yeah, well first off, Anthony, thank you for having me. Very excited to be here. And yeah, let's get into it. So at the high level, in order to serve the U.S. government, if you're a technology company, you're going to need to secure that technology to a very high standard, and that is what FedRAMP is fundamentally. It is a set of security and compliance standards that controls, as they're called in this space, that you have to meet as a tech company, as

### 01:40 — What FedRAMP actually is (and the 425 controls)

**[2:04]** a SaaS company, in order for the government to be allowed to put government data into your system, to do whatever your system does, be it something in the AI data infra space, be it HRIS, ERP, business productivity tooling, be it health IT, legal IT, doesn't matter. If you're a SaaS product, you are going to have to achieve FedRAMP. And indeed, there's less than 500 applications that have it today, because it is so challenging, just to give you a flavor of what it takes to achieve FedRAMP really quickly. Again, it's a security standard. So what that means is you're going to have to take your application, your commercial

**[2:43]** application as it stands today, carve it out into a totally separate enclave within probably AWS Azure, GCP, wherever you're already running that application, so meaning a separate instance. And then you're going to have to bring in a third party assessor. So there are about 30 companies that are accredited to do this. Coldfire and Shellman are the two biggest, but there's a number of others, Fortrium, A-Line, and so on. And you are going to have to very much like a tax audit, they're going to have to assess your application against the FedRAMP controls. And a lot of those controls have to do with how are you encrypting, how

**[3:18]** are you protecting government data in transit and at rest, and where it, you know, specifically you are going to have to turn on all sorts of encryption that you probably don't have. You're going to have to be very, very limited in your subprocessor choice for your application, because if your subprocessor is meeting your other services that you're leveraging above and beyond, you know, native hyperscaler services, if they're not FedRAMP as well, then you can't use them anymore, and so on and so forth. So, you know, there's a long list of technical controls, it's technical security controls that you have to meet, as well as a handful

**[4:00]** of controls that are going to feel very familiar to folks who have done SOC 2 around disaster recovery, and so on. Those are, I would argue, the easiest piece of this entire process, because again, most folks have done this because they've gone through SOC 2. To put in perspective, SOC 2 has about 95 controls, and FedRAMP High, which is, you know, where most folks want to be, has 425. So it is a much bigger, much more involved process. And the last thing I'll say is, so you're bringing a third-party assessor, they assess you once, then you have to go get a federal sponsor, a CISO or CIO within the federal government or the Department

**[4:39]** of War, to underwrite your risk, your cyber risk. That's called getting a sponsor and an authorization to operate. That's easily the hardest part, if the first part wasn't even hard enough. And then, by the way, once you achieve FedRAMP, which typically takes multiple years and multiple millions of dollars, you're then going to have to basically do that process every single year forever to maintain FedRAMP, because it is an annually audited standard, and it is a very rigorously annually audited standard. Plus, so you're going to spend another at least half a million to a million dollars a year just maintaining

**[5:14]** it annually. Plus, you will have to do something called continuous monitoring, which is a monthly check-in with the government, where you're going through all of your CVEs, all of your misconfigurations, basically the security posture of your entire environment, and the agencies that are leveraging your application are going to hold you accountable to remediating all of those findings within very strict SLAs, 30 days for high criticality, 90 days for medium, so on and so forth. All that to say, that's why I often describe getting FedRAMP as moving into a very exclusive zip code, as you mentioned, and building your own house

### 05:30 — Continuous monitoring and the forever-audit

**[5:57]** in that zip code. For anyone that's ever built their own house or even moved into an existing house and had to do any fixing up, but certainly anyone that's ever broken ground and built their own house on a piece of property, you know it's very challenging. Everything from getting the permitting to finding the architects to getting the supplies, to getting it ultimately inspected and deemed safe to live in, and then constantly having to do that cycle over and over again every year. It is not for the faint of heart. It's not unlike doing that to get FedRAMP. I want to pull on something really interesting that you said, because this sounds very, very

**[6:33]** involved. One, making updates to your product, making sure it's meeting certain standards, having the 400 plus controls, but you said arguably the hardest part is getting the executive sponsor or getting the federal sponsor to essentially sign off on your FedRAMP process. Why is that the most difficult part and what does it take to get a sponsor? Great question. When you are getting a sponsor, what you're asking, a CISO or CIO, it depends on the agency if it's the CISO or CIO, but basically what you're asking this very senior level official to do is underwrite your cybersecurity risk. You are asking them to evaluate your

### 07:00 — Why the federal sponsor is the hardest part

**[7:16]** vouch for the fact that yes, I'm going to put very sensitive, let's say DHS data or IRS data or Army data, whatever agency department we're talking about. I am vouching as the CISO or CIO of that department, of that agency. I'm vouching for the fact that we're going to put sensitive data into the system. It's not going to get popped, and if it does get popped, of course we're going to fire that vendor and there will be action against that vendor. But more importantly for me, the CISO or CIO, it's my reputation on the line and frankly it's my job on the line and I'm going to be more likely than not, depending on the

**[7:52]** severity of the breach or the incident, I'll be sitting in front of a House and Senate subcommittee being grilled on what happened and then there's usually consequences thereafter. Namely, I'm usually not the CISO or CIO for much longer of that department after an incident like that. All that to say, it's not dissimilar from when the CISO or CIO of JP Morgan signs off on a very large technical, especially institution-wide technology transformation and bringing in lots of different tooling. It's not unlike the stakes that they take on but as you can appreciate, it's arguably even higher because in the government you

**[8:36]** have folks that are, you know, they could go get way higher paying jobs elsewhere but they actively choose to serve the mission and they make a big sacrifice to do it, especially in the IT security world. There's no shortage of high paying industry jobs that would hire them but they actively choose to serve the government and the people of the United States. All that to say, you know, the last thing they want to do is take risk that they don't fully understand and they can't justify is worth it. So coming back to why are there so few applications, you know, it's not like the CISOs and CIOs are anti-innovation and

**[9:18]** anti-technology by no means but they are wrestling with the fact that you've got, you know, highly sensitive data and everyone would love for the opportunity to be able to take a bite out of, you know, frankly, let's be honest, the government has a lot of money to spend. Because it doesn't feel like it because it's hard to, you know, navigate it and so on but, you know, it's, as you mentioned at the beginning, it's $150 billion annually of spend, you know, that's bigger than any single and that's just the IT spend, you know, there's tons of other dollars that is spent. About half of that is cyber tooling kind of is and cousin tools,

**[9:58]** you know, data tools, etcetera. So it's a massive, massive addressable market for many applications for many companies but it's understandable why getting the sponsor or getting that signature from a CISO, CIO is hard. And typically, how would people go about doing that? Is that a networking exercise? It is a bottom-up pressure from the team pressuring that CISO to go look for certain applications? How would a company typically make that happen? You know, what's interesting is I often joke that, you know, I described that whole FedRAMP process of you've got to go get a third-party, you got to, you know, kind of rebuild your

**[10:40]** app in a way, got to get a third-party assessor, all of that stuff, right? And I often joke, you know, pretty much every part of FedRAMP you could throw money at because, you know, at the end of the day, with enough money and resource and time, you can accomplish any of those things. The one piece of this entire process that you literally are not allowed to throw money at is getting the sponsor because that's called bribing the government and that's illegal. And so how do people get sponsors? Well, typically the way it works is you've got a mission owner, so it could be a program manager, it could be, you know, there is a funded program, project,

### 11:00 — How you actually get a sponsor — and why you can't buy one

**[11:19]** whatever it might be within, let's say, the Treasury, right? Let's say the IRS is doing a big modernization effort and it's got a number of work streams that it's firing on and you have found the budget owner and the program owner and the mission owner and so on that's holding the decision of what tools are we going to use. You are one of the tools they want to use. Once they have established that, okay, we want to use this, you know, MDR tool. If you are not FedRAMP, what you're going to have to do is go with that program owner, mission owner, to the CIO of that agency and say, hey, we'd like to use this. This

**[11:56]** is why nothing else that is FedRAMP will work. This is why nothing that's legacy that we're already using will work. Here's why I need this specific tool. And oh, by the way, now I am asking you, CISO or CIO, to sponsor this tool. So now they're going to have to go and do this massive security review, which comes back to what we were just talking about, which is they're going to inherently want to push back because again, it's enlarging their risk area. So how do you get to a yes? Well, you get to a yes indeed through networking, indeed through pressure from both that mission owner or having multiple missions that really, really

**[12:35]** want your tool. You know, certainly this is where, you know, being plugged into the political appointees, not many of the IT leadership across the government is not politically appointed their career government folks. But particularly in this, in the current administration, the CIO role has switched from a career role to a political role. And so being plugged in to either that role or into the secretary role, which is obviously politically appointed. So the cabinet level positions, basically, you know, as with any organization, if you can come in from the top down, and from the bottom up, you're always going to have a better

**[13:11]** shot. But suffice it to say, you know, it is a, it is a process that can take years, often takes years. And there is no guarantee of success, because you are, you are, people leave, priorities change, budget, budgets change, etc, etc. By the time you finish a process that you started three years ago, you know, the program might not even be around anymore. There's so much of that happens so often that it's, it, again, it just, it is yet another nail in the coffin, if you will, of us being able to have a truly flourishing marketplace of solutions. And, and there is no, you know, step one, do this, step two,

**[13:56]** do this, it's very much a you've got to work the system. Yeah, which probably explains something that you mentioned earlier that there's 500 applications approved, which to me is mind boggling, because I'm pretty sure I have more than 500 apps on my iPhone. So for there to only be 500 apps to choose from, I'm thinking there's so many jobs to be done within the government that we probably take for granted the software we have access to, that a lot of people in the government just simply don't have access to. I'm assuming that's due to this process as well as a sensitive nature, but also that

**[14:32]** sounds like a big opportunity and makes going through what you're describing really, really worthwhile. What do you think? No doubt. I mean, listen, there's for the folks that have FedRAMP, I mean, they are operating in basically monopoly conditions, and I'll give you or duopoly conditions and I'll give you a perfect example. Pretty much any institution, certainly any large institution on the planet needs to have a help desk tool, right? And ITSM, you got to be able to make tickets, track tickets, resolve tickets, sometimes forget about tickets, you know, that process

**[15:10]** exists no matter if you are running the army, the IRS, the VA, everywhere. Today, there are two solutions that provide ITSM. One is called ServiceNow and one is called Salesforce that are FedRAMP. Now, obviously on the commercial marketplace, you have, I don't even know the exact number, at least 50. I mean, just, you know, if you Google help desk, there's at least 50, there's, you know, certainly at least 10 off the top of my head that I could rattle off that are enterprise grade serving banks and hospital systems and so on. And then a super, super long tail of folks who serve the kind of SMBs and so on. The challenge,

### 15:20 — 500 apps, $150B: the most underbuilt market in software

**[15:54]** as you might imagine, this is not Salesforce's or ServiceNow's fault by any means, so this is not throwing stones at them. But the reality is when you have a duopoly in a market where every single part of the US government needs a help desk and they only have two to choose from and that's, by the way, a good scenario. In most cases, the government has, you know, either one or zero to choose from. But in this case, they have two to choose from. What do you think happens to the pricing and the quality of the product and the service that those guys receive? It's a, you know, multi years behind their commercial offering because

### 16:00 — The ServiceNow / Salesforce duopoly

**[16:26]** on the commercial side, they compete with, you know, 50 competitors and in this space, they compete with one other competitor. You know, you want to talk about, you know, certainly there's, especially last year, but you know, even this year, there's still so much talk across the government around efficiency and hey, you know, why are we spending $10 on something that should cost us 50 cents and, you know, all of that kind of stuff. I mean, here's a perfect example, right? The outcome of this setup is exactly what you would expect it to be, right? And it's everyone is just acting in their own best interest with the

**[16:56]** setup that, you know, is in front of them. And so absolutely, there's this massive, massive opportunity to not just introduce more competition in place in software categories where there are at least one or two entrants, but to massively unlock the 80 plus percent of that $150 billion that is still stuck in legacy on-prem, you know, cobalt and all scripts and, you know, all sorts of, you know, Lotus Notes and all sorts of stuff that, you know, again, on the commercial side, we haven't heard about in decades. And yet the reality is there's still decent sized, in some cases, large chunks of our government that are running these systems,

**[17:40]** which, you know, not to be alarmist, but very quickly become national security risks, because I can tell you, you know, one thing those systems are not is secure. They are sitting duck systems that have all sorts of known vulnerabilities, that have been known for decades, that, you know, are very easy to exploit. So it's critical that we move fast, especially in, you know, the age of AI where, you know, the, I think the meantime from access to a system to actually exploiting a system, you know, on average used to be something like 45 days, again, give or take, you know, just across all the research from CrowdStrike

**[18:25]** and Kaspersky and McCoffee, and et cetera, et cetera. Just in the last year that's gone down to, I think the last research that I read was under a minute, because you have, you know, unlimited agents, unlimited, you know, basically unlimited resources to just hit every, just brute force through everything, because now you have, you know, thinking black hat agent hackers that are at infinite supply. All of that to say, it only becomes more critical for us to harden our systems, the way you typically harden the system as you move into something that's, you know, more modern, and most of that is SAS. So to bring it around

**[19:03]** full circle on why the opportunity is both, it's a financial one, it's also a security one. Yeah, and I want my government, of course, to have security, but also to have levels of productivity that are seen on the commercial side as well, and want them to be able to operate efficiently, not just the efficiency, but also just the quality of work too. And I know this impacts all areas. It impacts the healthcare system, the VA, and impacts all of the areas that really make a difference day to day to the lives of the citizens. So I think it's a really, really worthy cause to help companies get their products government ready, get the

**[19:48]** products in a position where the government can trust them, and then give them the opportunities to leverage those to help our nation better. And not to mention, you know, the perhaps the most ironic part of all of this is literally the country that, you know, invented AI, you know, invented the internet, and not just invented it, you know, you might argue, well, it's, you know, kind of, it had moments everywhere, at the very least, to commercialize these technologies into the massive scale that they are today, or becoming the massive scale that they are today. And that's just two examples

### 19:50 — 45 days to under a minute: why AI makes this urgent

**[20:24]** of, you know, we could go on and on. The irony is that the environment and the government that, you know, certainly had something to do with the fact that, you know, this continues to be the nation of innovation, and where the entire world still wants to come and do their, you know, very best work and build their biggest companies here, not anywhere else on the planet. It is extra insulting that literally the folks in that government, whether it's federal employees, whether it's the warfighter, don't have access to a lot of this technology. And indeed, and that's why, you know, we're so honored to serve,

**[21:02]** you know, most recently, one of the applications that we just announced very recently that achieved FedRAMP high with high baseline with Knox is Sierra AI, you know, and Sierra AI, I mean, I can't think of a more kind of no, first of all, innovative, you know, team, right, Brett Taylor and Clay, and that whole team is just absolutely impeccable in terms of cutting edge AI technology. But two, it's such a no brainer use case, right? I mean, what are they ultimately doing? They're creating AI agents that can talk to you and take you through, you know, an airline rebooking when you are invariably stranded by, you know,

**[21:40]** pick your airline or, you know, ultimately, you know, you have a problem with your taxes, call in, you're a veteran and you're dealing with the VA system, you know, have someone that can be a lot more helpful than, you know, a typical operator guide you through something. I mean, the sky's the limit in terms of, you know, thinking, reasoning agents that can get on the phone with you or on a text with you or whatever, and actually be incredibly helpful and take action and so on and so forth. Yeah, I mean, talk about unlocking great productivity and just user experience for everyone all around. What's not to love, you know? Yeah,

**[22:18]** and you made a claim earlier that I really want to dig into the how and go into the nuts and bolts. So the way you laid out the process, typically it's a three year $3 million hope you get a sponsor project might get shut down before you even have a chance to do it type of process. Yeah, but you've been able to get people through this in 90 days. How is Knox able to do that? Yeah, great question. So to build on the real estate analogy that we talked about, so if going at it alone and doing FedRAMP on your own is like trying to move into pick your most exclusive zip code in whatever part of the country you live in

**[22:58]** for anyone listening, you know, thinking through what's it going to take for me to get the permit to break ground, you know, build my own house there and continue to live there. What Knox does is we run the luxury condo building on Main Street in that zip code and our customers move into a floor of that ever-growing skyscraper and inherit. It's very important. We talked about sponsors and how hard they are to get and so on. It's very important about how Knox works is our customers inherit all of our sponsors. So we hold 16 sponsorships today and by the end of the year it'll be 20 across all of the major departments and

**[23:39]** agencies that spend the most amount of money on technology and IT across the government. So all of the main departments within the DoW, DoD, so that's Army, Air Force, Navy as well as the DHS, the VA, Treasury, Commerce and a whole long tail of other agencies. So specifically, you know, we're a managed cloud. We're that luxury condo building and by allowing our customers to inherit both the sponsors as well as the underlying infrastructure, right? When you think about the difference between building your own house and moving into a condo, when you move into a condo, you obviously don't have to break ground.

**[24:14]** You don't have to put in the plumbing and put in the electric and get, you know, build the structure. You're just moving into a unit and you bring your own furniture and there you go. That's exactly what you're doing with Knox. So you're inheriting, I mentioned FedRampi has about 425 controls, you're inheriting 80% of those from Knox right out of the gate because we're ensuring that you're secured to and compliant against those controls. And there's the very quick one-liner and you mentioned this in your opening, so this is just to build on something you said there, you know, how did Knox get such valuable real estate? You

### 24:50 — The luxury condo: FedRAMP in 90 days

**[24:53]** don't just wake up one morning and want to run the largest FedRamp managed cloud. And that's it. How did this come to be? Well, indeed, Knox in its initial incarnation was only serving Adobe for the first 15 years of its life. Adobe Connect, Adobe Learning Manager, ACMS, and kind of a long tail of Adobe applications have been sitting in this environment for the last 15 years and I actually acquired this managed service provider that was just focused on doing this for Adobe for those specific applications four years ago to get my prior company FedRamp because believe it or not, the fastest way, not the cheapest,

**[25:34]** but the fastest way for me to get that company FedRamp was to acquire a company that was already FedRamp, which is obviously not a scalable way to, you know, my circle of friends is not extremely diverse in that it is all, you know, kind of tech, you know, CEOs and leaders and so on. And so, you know, at some lunch or dinner, it invariably came up that we achieved FedRamp really fast at class.com and everyone asked me how I did it and I said, oh, I had to buy a company. And that immediately shut down the conversation because, you know, okay, well, that's not, it's not very helpful for anyone else. But what it opened my eyes

**[26:10]** to and my co-founder, CTO and chief architect, all three of us who were the chief architect and CTO of the company that I acquired was that this is obviously useful for others and, you know, we should build these additional floors on top of this already valuable base and foundation. And so two years after I acquired that company into class.com, my prior company, we spun out Knox as a standalone entity along with the core infrastructure and boundary and so on. So that is how we do what we do, metaphorically speaking. And just one line specifically on, you know, how it is we do kind of from a technology perspective. Again,

**[26:51]** we're a managed cloud. So we sit across AWS, Azure and GCP and we deploy every single customer as a single tenant sub account inside of AWS, Azure, GCP or hybrid. However, they're already architected. So what that means is A, they get to inherit our sponsors. B, they get to come as they are. They bring it their own CI/CD pipeline. They bring their own application performance monitoring stack. They don't need to change everything about how they've already built their application. You know, the majority of our customers, they're not teeny tiny, you know, 1, 2, 3, 5 million error companies. They're established multi hundred million

**[27:26]** revenue SaaS companies that have done extremely well commercially. They're extremely established and now they're making the investment in government. Certainly we hope to shift that left in terms of, you know, early and earlier. But the reality is, you know, when you think about the government, you know, your minimum deployment size is like a hundred thousand people within the government for like even, you know, a small agency. Typically the government is going to want to do business with folks and rely on tools that have already proven themselves in the commercial space and they can, you know, therefore reliably count on in the in

**[28:04]** the government space. So long story short, you know, these technologies are pretty established. They're architectures. They're actual, you know, the guts on the of the of the applications are pretty established. Having to be told to containerize or change anything about how they're already deploying, running, fixing, patching their application is, you know, that's like, you know, nails on a chalkboard to a CTO or a CISO. We don't require that because we say, hey, everyone has different furniture. We understand that. You're just moving into, you know, an unfurnished apartment. You tell me which hyperscaler you're going into. You

### 28:40 — 'I had to buy a company': the Adobe origin story

**[28:41]** tell me which FedRAMP baseline you're going into. And you move your furniture into into that particular type of unit. And that's why I think we've seen so much traction and so much success because, you know, we're really meeting the customer where they are and ultimately delivering on that 90 day. I mean, at the end of the day, that's the whole point, right? We want to be able to move folks through this process very fast because at the end of the day, I mean, certainly we've seen even with the moves that the administration, the government today is making, they want to move fast. I mean, literally yesterday, Pete Hexeth, Defense

**[29:14]** Secretary appointed Mark Andreessen to the Defense Policy Board. Basically, you know, a handful of advisors, you know, two dozen or so advisors to the Defense Secretary from industry on technology, on innovation, on, you know, making sure we're using the latest and greatest to compete around the globe. And, you know, it just kind of goes to show, you know, I don't think there's ever been a venture capitalist on that board. I think it's generally been, you know, the CEOs of Lockheed and Raytheon, you know, those types of companies represented. And the fact that, you know, they're really pushing into know

**[29:51]** we want more nimble, more cutting edge, you know, newer stacks is phenomenal. But the main thing is we want it faster. And so 90 days is critical to be able to deliver on that. Yeah. And I'm, I'm curious, what's the smallest company that you have seen successfully go through this process? I think the smallest is actually probably a 50, 75 person company. So, you know, generally when we're working with a company that that early, I will say, it's because they are a defense tech company. Their entire, you know, focus is to serve missions that are and their primary go to market motion is all around US government. Typically, the DOW, it is not

**[30:42]** we're going to go build a very healthy business commercially, and then we're going to open up the government market. So in those cases, obviously, those folks need FedRAMP from basically from day one, we've certainly worked with folks like that. But I would say the vast majority if they're not a defense tech company, right? Yeah, let's use the one that maybe started commercially and then is trying to make the move over. Yeah, I would say probably in that kind of 200 person range. So they're probably just kind of off the top of my head, they're probably they're in and around, you know, 50 million

**[31:13]** in revenue, maybe a little bit shy of that, but not orders of magnitude smaller. And again, I think it's because if you are not a defense tech company, you know, you're not going to go after, you know, DARPA money or you know, the sibber process and so on, which are all processes with if you're not familiar, for those listening, they're all designed to basically take something out of a lab, kind of science experiment, if you will, and help mature it into commercially viable for the usually the DoD, DoW. If that is not, you know, your mission vision value proposition of your company, and you are a commercial solution for, again,

**[31:53]** pick whatever category of software you'd like, the government is just very big, you got to understand the federal government is very big, state governments, especially big states tend to be very big. And so when they're buying, they're not buying for 10 people, they're not buying for 1000 people, they're buying for 10,000 people, or 100,000 people, they're buying at scale, because if the government tried to buy stuff for, you know, 10 at a time, they would, you know, they would just be even more inefficient than it is today. And so they have to buy in these, you know, bigger, bigger chunks. Now, sometimes it takes

**[32:27]** time to build up to that, you know, I'm not saying you walk in the door and six months later you have a, you know, a $10 million contract. But you know, kind of the rule of thumb, I would say is, on average, it is very hard for the US government to buy anything for less than $1 million, just like straight, straight out of the gate, like, if it's, it's, you know, it's kind of like trying to buy, you know, trying to use pennies for us regular folks with, you know, regular wallets, like, what am I going to do with this penny, you know what I mean, I can't, it doesn't even make sense for me to carry it around. Same

**[32:57]** concept, it is so much work to do a transaction, to do the contracting process, and so on, that if you're going, if you're, you know, if you're buying something for a smaller amount than that, it just, it's actually a waste of money, is how it's viewed, at least. So, so all that to say, when you're operating at that scale, typically you're going to operate, you know, we're talking about 10,000 users, you know, plus. And so typically, what you're going to see is, they're just, they're going to look for folks who have already proven themselves to be able to operate and deliver at that scale, commercially. It doesn't necessarily

**[33:36]** have to be with a bank, it doesn't necessarily have to be with a large hospital system or whatnot, but it's got to be with an enterprise they've heard of, if you will, you know, a brand they've heard of, maybe it's Coca-Cola that you've served, or Procter and Gamble, or, you know, something like that, that there's an understanding that, okay, this is a mature organization at scale. You've probably run up against all of the same types of bureaucracy, all of the same type of, you know, just deployment specificity that comes with serving that type of, that type of customer. And if you haven't, you're going to have a very hard time doing

### 33:40 — The smallest company that can pull this off

**[34:11]** the quals, as they're called, which is basically when you respond to an RFP for the government, you, which is, you know, part of the, you know, required contracting process more often than not, basically you have to tell them, well, why should I choose you? What qualifies you to do this? And tell me who else you've done it for. And if you can't list some, you know, some pretty hefty logos with some pretty hefty scale, I think it's not impossible by any means, right? You got to start somewhere, but, but I think more often than not, they're going to, as everyone says in every industry, not just the government, no one gets fired

**[34:45]** for choosing Salesforce, or it used to be no one gets fired for choosing IBM, right? Like that mentality is still going to hold back to your question of, you know, what's the size of the commercial guys? Again, you know, probably not too much smaller than kind of that $50 million range. Well, and if we can go a little deeper on that self-assessment checklist. So if a CEO is thinking, Hey, should I even start flirting with the idea that I should do FedRAMP or even start going into selling into the US government, a couple of check boxes, like, okay, are we at the size of 50 plus people or 200 plus people if it's

**[35:25]** commercially built first, 50 million in revenue, couple enterprise logos under your belt where you can prove that you can deliver at enterprise scale, what else should they be self assessing and checking the box before they call Knox and say, Hey, I'm ready to go sell to the US government? I would say that that's the, I mean, that's the main one, right? Like, have you done this commercially? Everything else you can spin up, right? And, and certainly I encourage everyone to the way to think about FedRAMP is really twofold. One is it obviously unlocks your ability to do business with the federal government and the DOW. It is the requirement. It's,

**[36:06]** you know, you can't even get on the road without a driver's license. It's the same thing here. You can't even bid on these opportunities. If you don't have FedRAMP, you'll hear this all the time with, you know, federal sales leaders or even just sales leaders who are having their first conversation with someone in the government, whatever, 20 minutes in, they asked me if, if we were FedRAMP, I said no. And they said, honestly, we're wasting our time to having this conversation. Cause if you're not FedRAMP, you know, it's just going to be a waste of time. The other way to think about FedRAMP is what it does for

**[36:34]** other regulated industries and kind of how, what light it paints you in. And what I mean by that is, you know, very much like, you know, there's a difference between, you know, a high school degree and a college degree and a PhD. And, and you could think of FedRAMP as kind of the PhD of, of security and, and compliance. You know, the point is it sets you above, right? You are in a very, very small club, even with all the traction Knox is having and so on, you know, we're still literally thousands of applications away from being anywhere close to what industry has access to. And so what we've seen over and

**[37:10]** over again across our customer base is they achieve FedRAMP. They put out with Knox, they put out a press release, because of course they want to share with the whole world. It's a massive accomplishment for, for business. The first call they get is actually not from a government agency. It might be, but oftentimes it's actually not. It's from an existing commercial customer who says, Hey, I saw your FedRAMP announcement. And by the way, it's typically a financial services or healthcare customer or other kind of heavily regulated treasury. They say, Hey, sorry, FedRAMP announcement. That's awesome. Didn't know you guys were

**[37:44]** working on that. That's fantastic. I would love to understand how we get, how we can move over, you know, our deployment into, into that, because it's, it's very simple. It, FedRAMP is viewed as a pre-diligenced environment that the US Air Force and the army and the DHS and the treasury have all already signed off on. So you as the head of security, whether it's CISO, CIO, again, it doesn't matter of a financial institution of a hospital system, of a large enterprise, you know, when you're looking across your risk assessment profile, across all of the applications that you've put your data into,

**[38:26]** all else equal, right? Price, deployment, you know, everything else equal. Of course you would want to sit in a pre-diligenced environment, even if you don't believe it's more secure, by the way, because, you know, certainly the security community has this debate all the time, or I should say that the intersection of the security and the compliance, you know, federal community has this, you know, debate all the time. Okay, FedRAMP is hard, but is it actually more secure? You know, and I'm happy to, to, to at least provide my perspective on that. But more importantly, even if you don't believe it's more secure,

**[38:57]** that's not the point. The point is, it is a CYA mechanism, right? Because in the absolute worst case scenario event of a breach, you, as that CISO, can say, well, hold on, you know, I, I bought Salesforce, or I, you know, I bought the, the thing that literally the US government is using. So, so I, I did my diligence. All that to say, what, what FedRAMP unlocks more holistically, what we see across the board, is it just sets our customers apart in their go-to-market approaches within financial services, within healthcare, and, and just across the board, right? But especially in those regulated markets, especially in the

**[39:39]** adjacent markets, industrials, you see this, obviously pharma is part of healthcare, you see this over and over again. So, so, so that's kind of how to think about, you know, when, when folks are doing self-assessment of, you know, is this a worthwhile conversation for me to be having, I would think about it in two ways, but certainly on the, am I ready to sell to government? Revert back to the, the prior points around, you know, have you proven yourself in industry so that government can really get comfortable with the fact that, okay, this is a player that knows what they're doing, and they're going to be around for,

**[40:13]** you know, the next 10 years. Because the other thing to understand, and again, I know folks know this, is, you know, yes, government is hard, but there's a reason folks continue to do business with government. They've good about big contracts that are very long-term, you know, it's, it's, it's, it's very, very sticky. And so, that's a pro and a con. The pro is, once you're in, you're in, the con is, if there is any concern that you're, you as a company are not going to be around for the next 10 years, like, you know, you've already lost. So you want to be able to completely put that conversation to bed with, well, here's

**[40:51]** why that's not even a, a real risk. In your opinion, is it potentially beneficial? Let's, let's use a company that operates in highly regulated environments, healthcare, financial. Could it potentially be beneficial to go through that process, even if you don't end up selling to a single government agency? Absolutely. I mean, I saw it firsthand, you know, when the, kind of the origin story of Knox was, as I mentioned, I bought this managed service provider to, to get FedRAMP for my prior company, class.com, where I was co-founder and chief operating officer. And I will tell you, you know, FedRAMP specifically, just getting FedRAMP

**[41:34]** for class.com unlocked $20 million of additional ARR. We, we were at 20 when we acquired, we were 20, we were 40, two years later, all that growth of, of the additional 20 came from getting FedRAMP. And specifically five of that 20, incremental, was selling to the government, straight up Air Force, then we want Army TRADOC, then we want a bunch of other agencies. So the other 15 was financial services and healthcare. And then a few enterprise clients that serve those, you know, they're like BCG and Coca-Cola's, folks that, again, I'd put in the kind of Fortune 500 and Adjacent Club, who have basically the same standards

**[42:22]** that, even if they're not officially required to, they basically hold the same standards that, that the financial services and healthcare hold. You know, again, kind of, it's, it's, it is a massive differentiator because, again, so few companies have it, it's understood how hard it is. It may not be understood exactly what you have to do, you know, not everyone who you're talking to might have done it, but everyone, very much like a PhD, right? It's like, I know that's hard. I don't need to have gotten a PhD to know that's hard. And to, you know, just kind of inherently respect folks who have gone through that because

### 42:30 — The halo effect + the $20M ARR unlock

**[42:57]** of just how notoriously hard it is. So absolutely. I mean, I do think, I would not say, and again, I don't want to like, oversell it in the sense that I would not say, you know, all of Knox, you know, majority of Knox customers don't even, you know, work with the government. They're, they're just doing it to, you know, be more competitive on, on, on all the other industries. No, I mean, they are obviously going after government and so on. But the halo effect as I call it, the FedRAMP halo effect is very real. And, and, you know, again, you can really ask any, certainly ask any one of my customers, but certainly ask anyone

**[43:34]** who's gotten FedRAMP, does it help on that front? Yes. So if, if government is even, you know, maybe a year out, two years out, for all the other reasons that we talked about as a go to market motion. But, you know, these other highly regulated industries are just industries that really care about cyber, over index on caring about cyber and compliance. I don't think it's a bad thing to consider it, consider FedRAMP now, because you're basically gonna, you know, you're doing extra credit to stand out today. Yeah, I think for a lot of startups, that SOC 2 threshold tends to open up quite a bit

**[44:11]** and just make things easier to close deals. So this feels like it could be the super SOC 2 for some companies, and they can leverage it that way. And I know more companies have gone through that process and felt the benefits. That's a big unlock that I think a lot of people don't realize, like, yes, of course, opening up the opportunity to sell to the government, amazing in and of itself, but also the tailwind you'll get on the commercial side and industry side. That's, that adds a whole new vector to the equation. And you know, it's interesting with SOC 2, I think we've all seen it over the last, I

**[44:47]** mean, I remember it wasn't really that long ago. I mean, I think even I would argue like six, seven, certainly 10 years ago, and I would argue as recently as five, six, seven years ago, SOC 2 is still kind of this like, maybe I have to, maybe I don't, to fast forward to today. It's the, you know, don't even call me if you don't have it type of, you know, face line. You know, do I think FedRAMP is gonna be that ubiquitous kind of across the board? No, because I do think it's, it would be, there is, there's a happy medium, right? But do I think that more and more is again, especially for serving the true enterprise,

**[45:25]** you know, your customers are deploying, you know, 10,000 plus end users of your solution on their, for their deployment, that flavor of buyer is, you know, do I see a world in which, you know, maybe in five or 10 years, FedRAMP or a FedRAMP equivalency is, is just the default. And it's like, don't even call me if you don't have it. I don't think it's too far fetched, truly. And it goes back to what we talked about with, you know, AI has really changed the landscape, you know, if something that took 45 days on average from entry to, to exploit is now down to, you know, under a minute, certainly under an hour. That's

**[46:11]** today, you know, and, and AI isn't even really that old in the, in the sense of, you know, folks, some folks would argue, well, you know, we've had AI in many ways for many years, sure, but we haven't had mythos, and we haven't had fable, and we haven't had deep seek, and we haven't had kimmy, and we have, you know, quen, and so on and so forth. I mean, we've barely had them for, you know, a few months, some of those models, right? So it's, it's only the beginning. I'm not saying FedRAMP is the solution to be all end all if you're FedRAMP, you'll never, no one will ever promise you and can or should promise you no, no breach,

**[46:51]** no incidents, but it is no question that there's an understanding that there is a widening, or I should say a rapidly rising risk across any enterprise with any sensitive data, and you need ways to, to control for that. I mean, just, that's just the reality. I agree with the same trend. I think we're gonna see a huge rise in the pushback companies are gonna give to these companies and make sure that they're built in a secure manner, and the government's gonna have to move faster with, especially a lot of the solutions they need would be cybersecurity solutions, so they're gonna need to get those through the

**[47:30]** door quicker in order to combat that environment as well. I have one question. Just to maybe illustrate what's possible, what is the biggest software check you have seen the US government write? I'll just give you one in the most, I'll time bound it because it's, you know, we could, we would be here all day with big numbers, but single biggest check for a single provider just in the last 60 days, 30 days, Oracle just won a hundred million dollar RFP, a hundred million dollar contract, rather, for HRIS, HR systems, for the Office of Management and Budget. Basically, the very quick backstory

**[48:30]** is if you all remember a year ago, year plus ago, the Doge guys came in and they were like, okay, we're gonna, you know, streamline the workforce, and so on. They called the Office of Management and Budget, which is supposed to hold a lot of like HR records, and they're like, so who works here anyway? Like, where's the list? Where's the HR system? And you know, the answer they got was unsatisfactory. It was like, well, there's this system that was built in the 80s, and it's on life support, and we spend like literally hundreds of millions of dollars a year just to like, basically print out pieces of paper, fax them over.

**[49:04]** I mean, it was like a disaster. And so rightfully so. They were like, well, that's insane. We should probably like, get this into, you know, an HRIS system, which is how the modern world has been operating its HR departments for, I don't know, 20 years now, certainly in the last 10 years. And, and they, last year, they put out an RFP. And this is another scenario where you have a duopoly. So you had Workday, and you had Oracle. That's it. Those were the options. I don't know that any doge guy would stand up here and be like, Oracle, the most modern technology on the planet or Workday, the most modern technology, you know, I don't,

**[49:48]** just realistically, I don't think they would say that. And yet, significant, both significantly better than the status quo. So long story short, that RFP finally concluded in the last few weeks here and was awarded to Oracle, $100 million over three years. So then it'll be, you know, another hundred million. But but my understanding is that's a per year award. And, and the idea is that that is consolidating all of these disparate, many extremely legacy and on prem and sometimes even not even fully digitized systems across the government. So that's just one in a very non, you know, dare I say non sexy use case, right, like HRIS

### 50:00 — FedRAMP as the new SOC 2

**[50:29]** is not the most sexy use case. It's certainly not the one that you know, the government's going to spend, you know, F $35 on. And yet, that's $100 million right there. You know, so just to put the scale and perspective of what we're talking about, it's, it's mind blowing what those opportunities would be. I think that would, for almost any company, $100 million contract fundamentally changes what, what you're doing and who you are in the market. So I think that's where if you're doing the benefit analysis, if you're doing the risk analysis and expected rate and benefit of either decision of to go down FedRAMP,

**[51:13]** maybe get some of those, I mean, having opportunities to get checks that size completely can make it worth it and worth it while and you know, it, you know, even if you know, someone pushes back and says, well, you know, that's the outlier, right? Because you asked the biggest and again, I that's, that is not the biggest ever by any means, that's just literally in the last 30 days. But the reality is, you know, go back to, you know, what, what I mentioned earlier, which is, you know, on average, they're not even going to bother with a contract that's less than a million a year. And so even that for many enterprise, you know, you know, many

**[51:51]** SaaS companies are not their AC, their average contract value is not necessarily a million, it might be, you know, 100,000, maybe 150,000, you know, and those would be a big enterprise deal. And that would be a big enterprise deal, right, you know, kind of if they're, you know, standard package, if you will, is around that 40k 50k. And then, you know, for a much larger, for a larger deal, it's in the low hundreds of thousands, maybe pushes up to half a million. We're literally talking in order or to a magnitude difference for what we're, you know, just the floor. So that's the that's the scope and scale of what we're talking about. And

**[52:29]** I think the other big piece of it is, is it's not a, it's not a one year, like they inherently are signing up for a multi year deployment, because look, at that scale, it's going to take a year or two or three to even fully deploy, train, you know, all of the change management that comes with that. These are these are huge customers. Absolutely. Irena, this has been really, really mind opening for me, I think everything that you laid out from the process of going through FedRAMP, why Knox is positioned to take a three year process and condense it into a 90 day process. I think the need for the US

**[53:09]** government to have access to these technologies is just continuing to grow. I think there's so many things in the environment in the market that are going to push that acceleration further as well. And I really, really appreciate the mission that you're on to help these companies serve the US government. And also, I hope anyone listening to this realizes the opportunity that's at hand the size of deployments and the size of checks that the government can write that simply a lot of industry companies cannot is pretty eye opening, pretty mind blowing. And I hope that it encourages companies that have a really good product that can serve

**[53:53]** our government really well to go through the process and get the benefits on the other industries that they're serving as well. So I just really appreciate it. Thank you for walking through everything. Thank you for sharing the vision of everything. And if anybody's listening and they're interested, what's the best way to get in touch with you? Absolutely. It's either Google Knox FedRAMP or go to KnoxSystems.com. Reach out to us. We would love to have a conversation. And Anthony, thank you for having me. This was a ton of fun. Thank you, Irena.


---

_LeanScale Podcast Knowledge Hub. Free to quote and cite with attribution to The LeanScale Podcast (https://www.leanscale.team)._
