---
title: "Why Only 500 Apps Can Sell to the U.S. Government"
episode: 94
podcast: "The LeanScale Podcast"
publisher: "LeanScale"
guest: "Irina Denisenko"
guest_title: "CEO, Knox Systems"
date_published: 2026-07-17
date_modified: 2026-07-22
duration: 00:54:34
word_count: 9482
topics: ["enterprise-sales", "gtm-strategy", "mergers-acquisitions", "pricing-packaging", "brand-positioning"]
canonical_url: https://leanscale-knowledge-hub.netlify.app/podcast/irina-denisenko-knox-selling-to-government/
source: "LeanScale Podcast Knowledge Hub — https://leanscale-knowledge-hub.netlify.app"
license: "Free to quote and cite with attribution to The LeanScale Podcast."
---

# Why Only 500 Apps Can Sell to the U.S. Government — Full Transcript

> Episode 94 of The LeanScale Podcast, with Irina Denisenko.
> Published July 17, 2026 · 00:54:34 · 9,482 words.
> Machine-transcribed and **not diarized** — speaker attribution is inferred, so verify
> attribution against the audio before quoting a specific person.
> Structured breakdown: https://leanscale-knowledge-hub.netlify.app/podcast/irina-denisenko-knox-selling-to-government/

## 00:00 — Cold open + intro

**[0:00]** Today, we're meeting with Irina Denesenko, CEO and co-founder of Knox, the company unlocking the U.S. federal market for modern Saas at speeds nobody thought possible. After living through the FedRAMP gauntlet at a prior company, Irina did something almost nobody else has. She acquired a 15-year-old managed service provider that already had a FedRAMP boundary serving Adobe, then built on top of it to create what she calls a luxury condo in the most exclusive zip code in software. Today, Knox runs the federal infrastructure for Adobe as its anchor tenant, plus 50-plus customers including ClickHouse, Sierra AI, Armas, Salonis,

**[0:44]** and Big ID. And a process that traditionally takes three years and three million dollars now takes only 90 days. In this conversation, Irina breaks down the real economics of selling into the U.S. government, the qualification framework every GTM leader needs before they spend a dollar on federal, and why this is the most under-built $150 billion market in software. Irina, thank you so much for being here. This is a huge topic and thing that companies are wrestling with that is really, really difficult to navigate through. I'd really like to kick off, I think anyone listening, very few know exactly what it takes to get through that

**[1:27]** FedRAMP process, and I would love if you could just walk us through the reality of what it means to be able to sell to the federal government. Yeah, well first off, Anthony, thank you for having me. Very excited to be here. And yeah, let's get into it. So at the high level, in order to serve the U.S. government, if you're a technology company, you're going to need to secure that technology to a very high standard, and that is what FedRAMP is fundamentally. It is a set of security and compliance standards that controls, as they're called in this space, that you have to meet as a tech company, as

## 01:40 — What FedRAMP actually is (and the 425 controls)

**[2:04]** a SaaS company, in order for the government to be allowed to put government data into your system, to do whatever your system does, be it something in the AI data infra space, be it HRIS, ERP, business productivity tooling, be it health IT, legal IT, doesn't matter. If you're a SaaS product, you are going to have to achieve FedRAMP. And indeed, there's less than 500 applications that have it today, because it is so challenging, just to give you a flavor of what it takes to achieve FedRAMP really quickly. Again, it's a security standard. So what that means is you're going to have to take your application, your commercial

**[2:43]** application as it stands today, carve it out into a totally separate enclave within probably AWS Azure, GCP, wherever you're already running that application, so meaning a separate instance. And then you're going to have to bring in a third party assessor. So there are about 30 companies that are accredited to do this. Coldfire and Shellman are the two biggest, but there's a number of others, Fortrium, A-Line, and so on. And you are going to have to very much like a tax audit, they're going to have to assess your application against the FedRAMP controls. And a lot of those controls have to do with how are you encrypting, how

**[3:18]** are you protecting government data in transit and at rest, and where it, you know, specifically you are going to have to turn on all sorts of encryption that you probably don't have. You're going to have to be very, very limited in your subprocessor choice for your application, because if your subprocessor is meeting your other services that you're leveraging above and beyond, you know, native hyperscaler services, if they're not FedRAMP as well, then you can't use them anymore, and so on and so forth. So, you know, there's a long list of technical controls, it's technical security controls that you have to meet, as well as a handful

**[4:00]** of controls that are going to feel very familiar to folks who have done SOC 2 around disaster recovery, and so on. Those are, I would argue, the easiest piece of this entire process, because again, most folks have done this because they've gone through SOC 2. To put in perspective, SOC 2 has about 95 controls, and FedRAMP High, which is, you know, where most folks want to be, has 425. So it is a much bigger, much more involved process. And the last thing I'll say is, so you're bringing a third-party assessor, they assess you once, then you have to go get a federal sponsor, a CISO or CIO within the federal government or the Department

**[4:39]** of War, to underwrite your risk, your cyber risk. That's called getting a sponsor and an authorization to operate. That's easily the hardest part, if the first part wasn't even hard enough. And then, by the way, once you achieve FedRAMP, which typically takes multiple years and multiple millions of dollars, you're then going to have to basically do that process every single year forever to maintain FedRAMP, because it is an annually audited standard, and it is a very rigorously annually audited standard. Plus, so you're going to spend another at least half a million to a million dollars a year just maintaining

**[5:14]** it annually. Plus, you will have to do something called continuous monitoring, which is a monthly check-in with the government, where you're going through all of your CVEs, all of your misconfigurations, basically the security posture of your entire environment, and the agencies that are leveraging your application are going to hold you accountable to remediating all of those findings within very strict SLAs, 30 days for high criticality, 90 days for medium, so on and so forth. All that to say, that's why I often describe getting FedRAMP as moving into a very exclusive zip code, as you mentioned, and building your own house

## 05:30 — Continuous monitoring and the forever-audit

**[5:57]** in that zip code. For anyone that's ever built their own house or even moved into an existing house and had to do any fixing up, but certainly anyone that's ever broken ground and built their own house on a piece of property, you know it's very challenging. Everything from getting the permitting to finding the architects to getting the supplies, to getting it ultimately inspected and deemed safe to live in, and then constantly having to do that cycle over and over again every year. It is not for the faint of heart. It's not unlike doing that to get FedRAMP. I want to pull on something really interesting that you said, because this sounds very, very

**[6:33]** involved. One, making updates to your product, making sure it's meeting certain standards, having the 400 plus controls, but you said arguably the hardest part is getting the executive sponsor or getting the federal sponsor to essentially sign off on your FedRAMP process. Why is that the most difficult part and what does it take to get a sponsor? Great question. When you are getting a sponsor, what you're asking, a CISO or CIO, it depends on the agency if it's the CISO or CIO, but basically what you're asking this very senior level official to do is underwrite your cybersecurity risk. You are asking them to evaluate your

## 07:00 — Why the federal sponsor is the hardest part

**[7:16]** vouch for the fact that yes, I'm going to put very sensitive, let's say DHS data or IRS data or Army data, whatever agency department we're talking about. I am vouching as the CISO or CIO of that department, of that agency. I'm vouching for the fact that we're going to put sensitive data into the system. It's not going to get popped, and if it does get popped, of course we're going to fire that vendor and there will be action against that vendor. But more importantly for me, the CISO or CIO, it's my reputation on the line and frankly it's my job on the line and I'm going to be more likely than not, depending on the

**[7:52]** severity of the breach or the incident, I'll be sitting in front of a House and Senate subcommittee being grilled on what happened and then there's usually consequences thereafter. Namely, I'm usually not the CISO or CIO for much longer of that department after an incident like that. All that to say, it's not dissimilar from when the CISO or CIO of JP Morgan signs off on a very large technical, especially institution-wide technology transformation and bringing in lots of different tooling. It's not unlike the stakes that they take on but as you can appreciate, it's arguably even higher because in the government you

**[8:36]** have folks that are, you know, they could go get way higher paying jobs elsewhere but they actively choose to serve the mission and they make a big sacrifice to do it, especially in the IT security world. There's no shortage of high paying industry jobs that would hire them but they actively choose to serve the government and the people of the United States. All that to say, you know, the last thing they want to do is take risk that they don't fully understand and they can't justify is worth it. So coming back to why are there so few applications, you know, it's not like the CISOs and CIOs are anti-innovation and

**[9:18]** anti-technology by no means but they are wrestling with the fact that you've got, you know, highly sensitive data and everyone would love for the opportunity to be able to take a bite out of, you know, frankly, let's be honest, the government has a lot of money to spend. Because it doesn't feel like it because it's hard to, you know, navigate it and so on but, you know, it's, as you mentioned at the beginning, it's $150 billion annually of spend, you know, that's bigger than any single and that's just the IT spend, you know, there's tons of other dollars that is spent. About half of that is cyber tooling kind of is and cousin tools,

**[9:58]** you know, data tools, etcetera. So it's a massive, massive addressable market for many applications for many companies but it's understandable why getting the sponsor or getting that signature from a CISO, CIO is hard. And typically, how would people go about doing that? Is that a networking exercise? It is a bottom-up pressure from the team pressuring that CISO to go look for certain applications? How would a company typically make that happen? You know, what's interesting is I often joke that, you know, I described that whole FedRAMP process of you've got to go get a third-party, you got to, you know, kind of rebuild your

**[10:40]** app in a way, got to get a third-party assessor, all of that stuff, right? And I often joke, you know, pretty much every part of FedRAMP you could throw money at because, you know, at the end of the day, with enough money and resource and time, you can accomplish any of those things. The one piece of this entire process that you literally are not allowed to throw money at is getting the sponsor because that's called bribing the government and that's illegal. And so how do people get sponsors? Well, typically the way it works is you've got a mission owner, so it could be a program manager, it could be, you know, there is a funded program, project,

## 11:00 — How you actually get a sponsor — and why you can't buy one

**[11:19]** whatever it might be within, let's say, the Treasury, right? Let's say the IRS is doing a big modernization effort and it's got a number of work streams that it's firing on and you have found the budget owner and the program owner and the mission owner and so on that's holding the decision of what tools are we going to use. You are one of the tools they want to use. Once they have established that, okay, we want to use this, you know, MDR tool. If you are not FedRAMP, what you're going to have to do is go with that program owner, mission owner, to the CIO of that agency and say, hey, we'd like to use this. This

**[11:56]** is why nothing else that is FedRAMP will work. This is why nothing that's legacy that we're already using will work. Here's why I need this specific tool. And oh, by the way, now I am asking you, CISO or CIO, to sponsor this tool. So now they're going to have to go and do this massive security review, which comes back to what we were just talking about, which is they're going to inherently want to push back because again, it's enlarging their risk area. So how do you get to a yes? Well, you get to a yes indeed through networking, indeed through pressure from both that mission owner or having multiple missions that really, really

**[12:35]** want your tool. You know, certainly this is where, you know, being plugged into the political appointees, not many of the IT leadership across the government is not politically appointed their career government folks. But particularly in this, in the current administration, the CIO role has switched from a career role to a political role. And so being plugged in to either that role or into the secretary role, which is obviously politically appointed. So the cabinet level positions, basically, you know, as with any organization, if you can come in from the top down, and from the bottom up, you're always going to have a better

**[13:11]** shot. But suffice it to say, you know, it is a, it is a process that can take years, often takes years. And there is no guarantee of success, because you are, you are, people leave, priorities change, budget, budgets change, etc, etc. By the time you finish a process that you started three years ago, you know, the program might not even be around anymore. There's so much of that happens so often that it's, it, again, it just, it is yet another nail in the coffin, if you will, of us being able to have a truly flourishing marketplace of solutions. And, and there is no, you know, step one, do this, step two,

**[13:56]** do this, it's very much a you've got to work the system. Yeah, which probably explains something that you mentioned earlier that there's 500 applications approved, which to me is mind boggling, because I'm pretty sure I have more than 500 apps on my iPhone. So for there to only be 500 apps to choose from, I'm thinking there's so many jobs to be done within the government that we probably take for granted the software we have access to, that a lot of people in the government just simply don't have access to. I'm assuming that's due to this process as well as a sensitive nature, but also that

**[14:32]** sounds like a big opportunity and makes going through what you're describing really, really worthwhile. What do you think? No doubt. I mean, listen, there's for the folks that have FedRAMP, I mean, they are operating in basically monopoly conditions, and I'll give you or duopoly conditions and I'll give you a perfect example. Pretty much any institution, certainly any large institution on the planet needs to have a help desk tool, right? And ITSM, you got to be able to make tickets, track tickets, resolve tickets, sometimes forget about tickets, you know, that process

**[15:10]** exists no matter if you are running the army, the IRS, the VA, everywhere. Today, there are two solutions that provide ITSM. One is called ServiceNow and one is called Salesforce that are FedRAMP. Now, obviously on the commercial marketplace, you have, I don't even know the exact number, at least 50. I mean, just, you know, if you Google help desk, there's at least 50, there's, you know, certainly at least 10 off the top of my head that I could rattle off that are enterprise grade serving banks and hospital systems and so on. And then a super, super long tail of folks who serve the kind of SMBs and so on. The challenge,

## 15:20 — 500 apps, $150B: the most underbuilt market in software

**[15:54]** as you might imagine, this is not Salesforce's or ServiceNow's fault by any means, so this is not throwing stones at them. But the reality is when you have a duopoly in a market where every single part of the US government needs a help desk and they only have two to choose from and that's, by the way, a good scenario. In most cases, the government has, you know, either one or zero to choose from. But in this case, they have two to choose from. What do you think happens to the pricing and the quality of the product and the service that those guys receive? It's a, you know, multi years behind their commercial offering because

## 16:00 — The ServiceNow / Salesforce duopoly

**[16:26]** on the commercial side, they compete with, you know, 50 competitors and in this space, they compete with one other competitor. You know, you want to talk about, you know, certainly there's, especially last year, but you know, even this year, there's still so much talk across the government around efficiency and hey, you know, why are we spending $10 on something that should cost us 50 cents and, you know, all of that kind of stuff. I mean, here's a perfect example, right? The outcome of this setup is exactly what you would expect it to be, right? And it's everyone is just acting in their own best interest with the

**[16:56]** setup that, you know, is in front of them. And so absolutely, there's this massive, massive opportunity to not just introduce more competition in place in software categories where there are at least one or two entrants, but to massively unlock the 80 plus percent of that $150 billion that is still stuck in legacy on-prem, you know, cobalt and all scripts and, you know, all sorts of, you know, Lotus Notes and all sorts of stuff that, you know, again, on the commercial side, we haven't heard about in decades. And yet the reality is there's still decent sized, in some cases, large chunks of our government that are running these systems,

**[17:40]** which, you know, not to be alarmist, but very quickly become national security risks, because I can tell you, you know, one thing those systems are not is secure. They are sitting duck systems that have all sorts of known vulnerabilities, that have been known for decades, that, you know, are very easy to exploit. So it's critical that we move fast, especially in, you know, the age of AI where, you know, the, I think the meantime from access to a system to actually exploiting a system, you know, on average used to be something like 45 days, again, give or take, you know, just across all the research from CrowdStrike

**[18:25]** and Kaspersky and McCoffee, and et cetera, et cetera. Just in the last year that's gone down to, I think the last research that I read was under a minute, because you have, you know, unlimited agents, unlimited, you know, basically unlimited resources to just hit every, just brute force through everything, because now you have, you know, thinking black hat agent hackers that are at infinite supply. All of that to say, it only becomes more critical for us to harden our systems, the way you typically harden the system as you move into something that's, you know, more modern, and most of that is SAS. So to bring it around

**[19:03]** full circle on why the opportunity is both, it's a financial one, it's also a security one. Yeah, and I want my government, of course, to have security, but also to have levels of productivity that are seen on the commercial side as well, and want them to be able to operate efficiently, not just the efficiency, but also just the quality of work too. And I know this impacts all areas. It impacts the healthcare system, the VA, and impacts all of the areas that really make a difference day to day to the lives of the citizens. So I think it's a really, really worthy cause to help companies get their products government ready, get the

**[19:48]** products in a position where the government can trust them, and then give them the opportunities to leverage those to help our nation better. And not to mention, you know, the perhaps the most ironic part of all of this is literally the country that, you know, invented AI, you know, invented the internet, and not just invented it, you know, you might argue, well, it's, you know, kind of, it had moments everywhere, at the very least, to commercialize these technologies into the massive scale that they are today, or becoming the massive scale that they are today. And that's just two examples

## 19:50 — 45 days to under a minute: why AI makes this urgent

**[20:24]** of, you know, we could go on and on. The irony is that the environment and the government that, you know, certainly had something to do with the fact that, you know, this continues to be the nation of innovation, and where the entire world still wants to come and do their, you know, very best work and build their biggest companies here, not anywhere else on the planet. It is extra insulting that literally the folks in that government, whether it's federal employees, whether it's the warfighter, don't have access to a lot of this technology. And indeed, and that's why, you know, we're so honored to serve,

**[21:02]** you know, most recently, one of the applications that we just announced very recently that achieved FedRAMP high with high baseline with Knox is Sierra AI, you know, and Sierra AI, I mean, I can't think of a more kind of no, first of all, innovative, you know, team, right, Brett Taylor and Clay, and that whole team is just absolutely impeccable in terms of cutting edge AI technology. But two, it's such a no brainer use case, right? I mean, what are they ultimately doing? They're creating AI agents that can talk to you and take you through, you know, an airline rebooking when you are invariably stranded by, you know,

**[21:40]** pick your airline or, you know, ultimately, you know, you have a problem with your taxes, call in, you're a veteran and you're dealing with the VA system, you know, have someone that can be a lot more helpful than, you know, a typical operator guide you through something. I mean, the sky's the limit in terms of, you know, thinking, reasoning agents that can get on the phone with you or on a text with you or whatever, and actually be incredibly helpful and take action and so on and so forth. Yeah, I mean, talk about unlocking great productivity and just user experience for everyone all around. What's not to love, you know? Yeah,

**[22:18]** and you made a claim earlier that I really want to dig into the how and go into the nuts and bolts. So the way you laid out the process, typically it's a three year $3 million hope you get a sponsor project might get shut down before you even have a chance to do it type of process. Yeah, but you've been able to get people through this in 90 days. How is Knox able to do that? Yeah, great question. So to build on the real estate analogy that we talked about, so if going at it alone and doing FedRAMP on your own is like trying to move into pick your most exclusive zip code in whatever part of the country you live in

**[22:58]** for anyone listening, you know, thinking through what's it going to take for me to get the permit to break ground, you know, build my own house there and continue to live there. What Knox does is we run the luxury condo building on Main Street in that zip code and our customers move into a floor of that ever-growing skyscraper and inherit. It's very important. We talked about sponsors and how hard they are to get and so on. It's very important about how Knox works is our customers inherit all of our sponsors. So we hold 16 sponsorships today and by the end of the year it'll be 20 across all of the major departments and

**[23:39]** agencies that spend the most amount of money on technology and IT across the government. So all of the main departments within the DoW, DoD, so that's Army, Air Force, Navy as well as the DHS, the VA, Treasury, Commerce and a whole long tail of other agencies. So specifically, you know, we're a managed cloud. We're that luxury condo building and by allowing our customers to inherit both the sponsors as well as the underlying infrastructure, right? When you think about the difference between building your own house and moving into a condo, when you move into a condo, you obviously don't have to break ground.

**[24:14]** You don't have to put in the plumbing and put in the electric and get, you know, build the structure. You're just moving into a unit and you bring your own furniture and there you go. That's exactly what you're doing with Knox. So you're inheriting, I mentioned FedRampi has about 425 controls, you're inheriting 80% of those from Knox right out of the gate because we're ensuring that you're secured to and compliant against those controls. And there's the very quick one-liner and you mentioned this in your opening, so this is just to build on something you said there, you know, how did Knox get such valuable real estate? You

## 24:50 — The luxury condo: FedRAMP in 90 days

**[24:53]** don't just wake up one morning and want to run the largest FedRamp managed cloud. And that's it. How did this come to be? Well, indeed, Knox in its initial incarnation was only serving Adobe for the first 15 years of its life. Adobe Connect, Adobe Learning Manager, ACMS, and kind of a long tail of Adobe applications have been sitting in this environment for the last 15 years and I actually acquired this managed service provider that was just focused on doing this for Adobe for those specific applications four years ago to get my prior company FedRamp because believe it or not, the fastest way, not the cheapest,

**[25:34]** but the fastest way for me to get that company FedRamp was to acquire a company that was already FedRamp, which is obviously not a scalable way to, you know, my circle of friends is not extremely diverse in that it is all, you know, kind of tech, you know, CEOs and leaders and so on. And so, you know, at some lunch or dinner, it invariably came up that we achieved FedRamp really fast at class.com and everyone asked me how I did it and I said, oh, I had to buy a company. And that immediately shut down the conversation because, you know, okay, well, that's not, it's not very helpful for anyone else. But what it opened my eyes

**[26:10]** to and my co-founder, CTO and chief architect, all three of us who were the chief architect and CTO of the company that I acquired was that this is obviously useful for others and, you know, we should build these additional floors on top of this already valuable base and foundation. And so two years after I acquired that company into class.com, my prior company, we spun out Knox as a standalone entity along with the core infrastructure and boundary and so on. So that is how we do what we do, metaphorically speaking. And just one line specifically on, you know, how it is we do kind of from a technology perspective. Again,

**[26:51]** we're a managed cloud. So we sit across AWS, Azure and GCP and we deploy every single customer as a single tenant sub account inside of AWS, Azure, GCP or hybrid. However, they're already architected. So what that means is A, they get to inherit our sponsors. B, they get to come as they are. They bring it their own CI/CD pipeline. They bring their own application performance monitoring stack. They don't need to change everything about how they've already built their application. You know, the majority of our customers, they're not teeny tiny, you know, 1, 2, 3, 5 million error companies. They're established multi hundred million

**[27:26]** revenue SaaS companies that have done extremely well commercially. They're extremely established and now they're making the investment in government. Certainly we hope to shift that left in terms of, you know, early and earlier. But the reality is, you know, when you think about the government, you know, your minimum deployment size is like a hundred thousand people within the government for like even, you know, a small agency. Typically the government is going to want to do business with folks and rely on tools that have already proven themselves in the commercial space and they can, you know, therefore reliably count on in the in

**[28:04]** the government space. So long story short, you know, these technologies are pretty established. They're architectures. They're actual, you know, the guts on the of the of the applications are pretty established. Having to be told to containerize or change anything about how they're already deploying, running, fixing, patching their application is, you know, that's like, you know, nails on a chalkboard to a CTO or a CISO. We don't require that because we say, hey, everyone has different furniture. We understand that. You're just moving into, you know, an unfurnished apartment. You tell me which hyperscaler you're going into. You

## 28:40 — 'I had to buy a company': the Adobe origin story

**[28:41]** tell me which FedRAMP baseline you're going into. And you move your furniture into into that particular type of unit. And that's why I think we've seen so much traction and so much success because, you know, we're really meeting the customer where they are and ultimately delivering on that 90 day. I mean, at the end of the day, that's the whole point, right? We want to be able to move folks through this process very fast because at the end of the day, I mean, certainly we've seen even with the moves that the administration, the government today is making, they want to move fast. I mean, literally yesterday, Pete Hexeth, Defense

**[29:14]** Secretary appointed Mark Andreessen to the Defense Policy Board. Basically, you know, a handful of advisors, you know, two dozen or so advisors to the Defense Secretary from industry on technology, on innovation, on, you know, making sure we're using the latest and greatest to compete around the globe. And, you know, it just kind of goes to show, you know, I don't think there's ever been a venture capitalist on that board. I think it's generally been, you know, the CEOs of Lockheed and Raytheon, you know, those types of companies represented. And the fact that, you know, they're really pushing into know

**[29:51]** we want more nimble, more cutting edge, you know, newer stacks is phenomenal. But the main thing is we want it faster. And so 90 days is critical to be able to deliver on that. Yeah. And I'm, I'm curious, what's the smallest company that you have seen successfully go through this process? I think the smallest is actually probably a 50, 75 person company. So, you know, generally when we're working with a company that that early, I will say, it's because they are a defense tech company. Their entire, you know, focus is to serve missions that are and their primary go to market motion is all around US government. Typically, the DOW, it is not

**[30:42]** we're going to go build a very healthy business commercially, and then we're going to open up the government market. So in those cases, obviously, those folks need FedRAMP from basically from day one, we've certainly worked with folks like that. But I would say the vast majority if they're not a defense tech company, right? Yeah, let's use the one that maybe started commercially and then is trying to make the move over. Yeah, I would say probably in that kind of 200 person range. So they're probably just kind of off the top of my head, they're probably they're in and around, you know, 50 million

**[31:13]** in revenue, maybe a little bit shy of that, but not orders of magnitude smaller. And again, I think it's because if you are not a defense tech company, you know, you're not going to go after, you know, DARPA money or you know, the sibber process and so on, which are all processes with if you're not familiar, for those listening, they're all designed to basically take something out of a lab, kind of science experiment, if you will, and help mature it into commercially viable for the usually the DoD, DoW. If that is not, you know, your mission vision value proposition of your company, and you are a commercial solution for, again,

**[31:53]** pick whatever category of software you'd like, the government is just very big, you got to understand the federal government is very big, state governments, especially big states tend to be very big. And so when they're buying, they're not buying for 10 people, they're not buying for 1000 people, they're buying for 10,000 people, or 100,000 people, they're buying at scale, because if the government tried to buy stuff for, you know, 10 at a time, they would, you know, they would just be even more inefficient than it is today. And so they have to buy in these, you know, bigger, bigger chunks. Now, sometimes it takes

**[32:27]** time to build up to that, you know, I'm not saying you walk in the door and six months later you have a, you know, a $10 million contract. But you know, kind of the rule of thumb, I would say is, on average, it is very hard for the US government to buy anything for less than $1 million, just like straight, straight out of the gate, like, if it's, it's, you know, it's kind of like trying to buy, you know, trying to use pennies for us regular folks with, you know, regular wallets, like, what am I going to do with this penny, you know what I mean, I can't, it doesn't even make sense for me to carry it around. Same

**[32:57]** concept, it is so much work to do a transaction, to do the contracting process, and so on, that if you're going, if you're, you know, if you're buying something for a smaller amount than that, it just, it's actually a waste of money, is how it's viewed, at least. So, so all that to say, when you're operating at that scale, typically you're going to operate, you know, we're talking about 10,000 users, you know, plus. And so typically, what you're going to see is, they're just, they're going to look for folks who have already proven themselves to be able to operate and deliver at that scale, commercially. It doesn't necessarily

**[33:36]** have to be with a bank, it doesn't necessarily have to be with a large hospital system or whatnot, but it's got to be with an enterprise they've heard of, if you will, you know, a brand they've heard of, maybe it's Coca-Cola that you've served, or Procter and Gamble, or, you know, something like that, that there's an understanding that, okay, this is a mature organization at scale. You've probably run up against all of the same types of bureaucracy, all of the same type of, you know, just deployment specificity that comes with serving that type of, that type of customer. And if you haven't, you're going to have a very hard time doing

## 33:40 — The smallest company that can pull this off

**[34:11]** the quals, as they're called, which is basically when you respond to an RFP for the government, you, which is, you know, part of the, you know, required contracting process more often than not, basically you have to tell them, well, why should I choose you? What qualifies you to do this? And tell me who else you've done it for. And if you can't list some, you know, some pretty hefty logos with some pretty hefty scale, I think it's not impossible by any means, right? You got to start somewhere, but, but I think more often than not, they're going to, as everyone says in every industry, not just the government, no one gets fired

**[34:45]** for choosing Salesforce, or it used to be no one gets fired for choosing IBM, right? Like that mentality is still going to hold back to your question of, you know, what's the size of the commercial guys? Again, you know, probably not too much smaller than kind of that $50 million range. Well, and if we can go a little deeper on that self-assessment checklist. So if a CEO is thinking, Hey, should I even start flirting with the idea that I should do FedRAMP or even start going into selling into the US government, a couple of check boxes, like, okay, are we at the size of 50 plus people or 200 plus people if it's

**[35:25]** commercially built first, 50 million in revenue, couple enterprise logos under your belt where you can prove that you can deliver at enterprise scale, what else should they be self assessing and checking the box before they call Knox and say, Hey, I'm ready to go sell to the US government? I would say that that's the, I mean, that's the main one, right? Like, have you done this commercially? Everything else you can spin up, right? And, and certainly I encourage everyone to the way to think about FedRAMP is really twofold. One is it obviously unlocks your ability to do business with the federal government and the DOW. It is the requirement. It's,

**[36:06]** you know, you can't even get on the road without a driver's license. It's the same thing here. You can't even bid on these opportunities. If you don't have FedRAMP, you'll hear this all the time with, you know, federal sales leaders or even just sales leaders who are having their first conversation with someone in the government, whatever, 20 minutes in, they asked me if, if we were FedRAMP, I said no. And they said, honestly, we're wasting our time to having this conversation. Cause if you're not FedRAMP, you know, it's just going to be a waste of time. The other way to think about FedRAMP is what it does for

**[36:34]** other regulated industries and kind of how, what light it paints you in. And what I mean by that is, you know, very much like, you know, there's a difference between, you know, a high school degree and a college degree and a PhD. And, and you could think of FedRAMP as kind of the PhD of, of security and, and compliance. You know, the point is it sets you above, right? You are in a very, very small club, even with all the traction Knox is having and so on, you know, we're still literally thousands of applications away from being anywhere close to what industry has access to. And so what we've seen over and

**[37:10]** over again across our customer base is they achieve FedRAMP. They put out with Knox, they put out a press release, because of course they want to share with the whole world. It's a massive accomplishment for, for business. The first call they get is actually not from a government agency. It might be, but oftentimes it's actually not. It's from an existing commercial customer who says, Hey, I saw your FedRAMP announcement. And by the way, it's typically a financial services or healthcare customer or other kind of heavily regulated treasury. They say, Hey, sorry, FedRAMP announcement. That's awesome. Didn't know you guys were

**[37:44]** working on that. That's fantastic. I would love to understand how we get, how we can move over, you know, our deployment into, into that, because it's, it's very simple. It, FedRAMP is viewed as a pre-diligenced environment that the US Air Force and the army and the DHS and the treasury have all already signed off on. So you as the head of security, whether it's CISO, CIO, again, it doesn't matter of a financial institution of a hospital system, of a large enterprise, you know, when you're looking across your risk assessment profile, across all of the applications that you've put your data into,

**[38:26]** all else equal, right? Price, deployment, you know, everything else equal. Of course you would want to sit in a pre-diligenced environment, even if you don't believe it's more secure, by the way, because, you know, certainly the security community has this debate all the time, or I should say that the intersection of the security and the compliance, you know, federal community has this, you know, debate all the time. Okay, FedRAMP is hard, but is it actually more secure? You know, and I'm happy to, to, to at least provide my perspective on that. But more importantly, even if you don't believe it's more secure,

**[38:57]** that's not the point. The point is, it is a CYA mechanism, right? Because in the absolute worst case scenario event of a breach, you, as that CISO, can say, well, hold on, you know, I, I bought Salesforce, or I, you know, I bought the, the thing that literally the US government is using. So, so I, I did my diligence. All that to say, what, what FedRAMP unlocks more holistically, what we see across the board, is it just sets our customers apart in their go-to-market approaches within financial services, within healthcare, and, and just across the board, right? But especially in those regulated markets, especially in the

**[39:39]** adjacent markets, industrials, you see this, obviously pharma is part of healthcare, you see this over and over again. So, so, so that's kind of how to think about, you know, when, when folks are doing self-assessment of, you know, is this a worthwhile conversation for me to be having, I would think about it in two ways, but certainly on the, am I ready to sell to government? Revert back to the, the prior points around, you know, have you proven yourself in industry so that government can really get comfortable with the fact that, okay, this is a player that knows what they're doing, and they're going to be around for,

**[40:13]** you know, the next 10 years. Because the other thing to understand, and again, I know folks know this, is, you know, yes, government is hard, but there's a reason folks continue to do business with government. They've good about big contracts that are very long-term, you know, it's, it's, it's, it's very, very sticky. And so, that's a pro and a con. The pro is, once you're in, you're in, the con is, if there is any concern that you're, you as a company are not going to be around for the next 10 years, like, you know, you've already lost. So you want to be able to completely put that conversation to bed with, well, here's

**[40:51]** why that's not even a, a real risk. In your opinion, is it potentially beneficial? Let's, let's use a company that operates in highly regulated environments, healthcare, financial. Could it potentially be beneficial to go through that process, even if you don't end up selling to a single government agency? Absolutely. I mean, I saw it firsthand, you know, when the, kind of the origin story of Knox was, as I mentioned, I bought this managed service provider to, to get FedRAMP for my prior company, class.com, where I was co-founder and chief operating officer. And I will tell you, you know, FedRAMP specifically, just getting FedRAMP

**[41:34]** for class.com unlocked $20 million of additional ARR. We, we were at 20 when we acquired, we were 20, we were 40, two years later, all that growth of, of the additional 20 came from getting FedRAMP. And specifically five of that 20, incremental, was selling to the government, straight up Air Force, then we want Army TRADOC, then we want a bunch of other agencies. So the other 15 was financial services and healthcare. And then a few enterprise clients that serve those, you know, they're like BCG and Coca-Cola's, folks that, again, I'd put in the kind of Fortune 500 and Adjacent Club, who have basically the same standards

**[42:22]** that, even if they're not officially required to, they basically hold the same standards that, that the financial services and healthcare hold. You know, again, kind of, it's, it's, it is a massive differentiator because, again, so few companies have it, it's understood how hard it is. It may not be understood exactly what you have to do, you know, not everyone who you're talking to might have done it, but everyone, very much like a PhD, right? It's like, I know that's hard. I don't need to have gotten a PhD to know that's hard. And to, you know, just kind of inherently respect folks who have gone through that because

## 42:30 — The halo effect + the $20M ARR unlock

**[42:57]** of just how notoriously hard it is. So absolutely. I mean, I do think, I would not say, and again, I don't want to like, oversell it in the sense that I would not say, you know, all of Knox, you know, majority of Knox customers don't even, you know, work with the government. They're, they're just doing it to, you know, be more competitive on, on, on all the other industries. No, I mean, they are obviously going after government and so on. But the halo effect as I call it, the FedRAMP halo effect is very real. And, and, you know, again, you can really ask any, certainly ask any one of my customers, but certainly ask anyone

**[43:34]** who's gotten FedRAMP, does it help on that front? Yes. So if, if government is even, you know, maybe a year out, two years out, for all the other reasons that we talked about as a go to market motion. But, you know, these other highly regulated industries are just industries that really care about cyber, over index on caring about cyber and compliance. I don't think it's a bad thing to consider it, consider FedRAMP now, because you're basically gonna, you know, you're doing extra credit to stand out today. Yeah, I think for a lot of startups, that SOC 2 threshold tends to open up quite a bit

**[44:11]** and just make things easier to close deals. So this feels like it could be the super SOC 2 for some companies, and they can leverage it that way. And I know more companies have gone through that process and felt the benefits. That's a big unlock that I think a lot of people don't realize, like, yes, of course, opening up the opportunity to sell to the government, amazing in and of itself, but also the tailwind you'll get on the commercial side and industry side. That's, that adds a whole new vector to the equation. And you know, it's interesting with SOC 2, I think we've all seen it over the last, I

**[44:47]** mean, I remember it wasn't really that long ago. I mean, I think even I would argue like six, seven, certainly 10 years ago, and I would argue as recently as five, six, seven years ago, SOC 2 is still kind of this like, maybe I have to, maybe I don't, to fast forward to today. It's the, you know, don't even call me if you don't have it type of, you know, face line. You know, do I think FedRAMP is gonna be that ubiquitous kind of across the board? No, because I do think it's, it would be, there is, there's a happy medium, right? But do I think that more and more is again, especially for serving the true enterprise,

**[45:25]** you know, your customers are deploying, you know, 10,000 plus end users of your solution on their, for their deployment, that flavor of buyer is, you know, do I see a world in which, you know, maybe in five or 10 years, FedRAMP or a FedRAMP equivalency is, is just the default. And it's like, don't even call me if you don't have it. I don't think it's too far fetched, truly. And it goes back to what we talked about with, you know, AI has really changed the landscape, you know, if something that took 45 days on average from entry to, to exploit is now down to, you know, under a minute, certainly under an hour. That's

**[46:11]** today, you know, and, and AI isn't even really that old in the, in the sense of, you know, folks, some folks would argue, well, you know, we've had AI in many ways for many years, sure, but we haven't had mythos, and we haven't had fable, and we haven't had deep seek, and we haven't had kimmy, and we have, you know, quen, and so on and so forth. I mean, we've barely had them for, you know, a few months, some of those models, right? So it's, it's only the beginning. I'm not saying FedRAMP is the solution to be all end all if you're FedRAMP, you'll never, no one will ever promise you and can or should promise you no, no breach,

**[46:51]** no incidents, but it is no question that there's an understanding that there is a widening, or I should say a rapidly rising risk across any enterprise with any sensitive data, and you need ways to, to control for that. I mean, just, that's just the reality. I agree with the same trend. I think we're gonna see a huge rise in the pushback companies are gonna give to these companies and make sure that they're built in a secure manner, and the government's gonna have to move faster with, especially a lot of the solutions they need would be cybersecurity solutions, so they're gonna need to get those through the

**[47:30]** door quicker in order to combat that environment as well. I have one question. Just to maybe illustrate what's possible, what is the biggest software check you have seen the US government write? I'll just give you one in the most, I'll time bound it because it's, you know, we could, we would be here all day with big numbers, but single biggest check for a single provider just in the last 60 days, 30 days, Oracle just won a hundred million dollar RFP, a hundred million dollar contract, rather, for HRIS, HR systems, for the Office of Management and Budget. Basically, the very quick backstory

**[48:30]** is if you all remember a year ago, year plus ago, the Doge guys came in and they were like, okay, we're gonna, you know, streamline the workforce, and so on. They called the Office of Management and Budget, which is supposed to hold a lot of like HR records, and they're like, so who works here anyway? Like, where's the list? Where's the HR system? And you know, the answer they got was unsatisfactory. It was like, well, there's this system that was built in the 80s, and it's on life support, and we spend like literally hundreds of millions of dollars a year just to like, basically print out pieces of paper, fax them over.

**[49:04]** I mean, it was like a disaster. And so rightfully so. They were like, well, that's insane. We should probably like, get this into, you know, an HRIS system, which is how the modern world has been operating its HR departments for, I don't know, 20 years now, certainly in the last 10 years. And, and they, last year, they put out an RFP. And this is another scenario where you have a duopoly. So you had Workday, and you had Oracle. That's it. Those were the options. I don't know that any doge guy would stand up here and be like, Oracle, the most modern technology on the planet or Workday, the most modern technology, you know, I don't,

**[49:48]** just realistically, I don't think they would say that. And yet, significant, both significantly better than the status quo. So long story short, that RFP finally concluded in the last few weeks here and was awarded to Oracle, $100 million over three years. So then it'll be, you know, another hundred million. But but my understanding is that's a per year award. And, and the idea is that that is consolidating all of these disparate, many extremely legacy and on prem and sometimes even not even fully digitized systems across the government. So that's just one in a very non, you know, dare I say non sexy use case, right, like HRIS

## 50:00 — FedRAMP as the new SOC 2

**[50:29]** is not the most sexy use case. It's certainly not the one that you know, the government's going to spend, you know, F $35 on. And yet, that's $100 million right there. You know, so just to put the scale and perspective of what we're talking about, it's, it's mind blowing what those opportunities would be. I think that would, for almost any company, $100 million contract fundamentally changes what, what you're doing and who you are in the market. So I think that's where if you're doing the benefit analysis, if you're doing the risk analysis and expected rate and benefit of either decision of to go down FedRAMP,

**[51:13]** maybe get some of those, I mean, having opportunities to get checks that size completely can make it worth it and worth it while and you know, it, you know, even if you know, someone pushes back and says, well, you know, that's the outlier, right? Because you asked the biggest and again, I that's, that is not the biggest ever by any means, that's just literally in the last 30 days. But the reality is, you know, go back to, you know, what, what I mentioned earlier, which is, you know, on average, they're not even going to bother with a contract that's less than a million a year. And so even that for many enterprise, you know, you know, many

**[51:51]** SaaS companies are not their AC, their average contract value is not necessarily a million, it might be, you know, 100,000, maybe 150,000, you know, and those would be a big enterprise deal. And that would be a big enterprise deal, right, you know, kind of if they're, you know, standard package, if you will, is around that 40k 50k. And then, you know, for a much larger, for a larger deal, it's in the low hundreds of thousands, maybe pushes up to half a million. We're literally talking in order or to a magnitude difference for what we're, you know, just the floor. So that's the that's the scope and scale of what we're talking about. And

**[52:29]** I think the other big piece of it is, is it's not a, it's not a one year, like they inherently are signing up for a multi year deployment, because look, at that scale, it's going to take a year or two or three to even fully deploy, train, you know, all of the change management that comes with that. These are these are huge customers. Absolutely. Irena, this has been really, really mind opening for me, I think everything that you laid out from the process of going through FedRAMP, why Knox is positioned to take a three year process and condense it into a 90 day process. I think the need for the US

**[53:09]** government to have access to these technologies is just continuing to grow. I think there's so many things in the environment in the market that are going to push that acceleration further as well. And I really, really appreciate the mission that you're on to help these companies serve the US government. And also, I hope anyone listening to this realizes the opportunity that's at hand the size of deployments and the size of checks that the government can write that simply a lot of industry companies cannot is pretty eye opening, pretty mind blowing. And I hope that it encourages companies that have a really good product that can serve

**[53:53]** our government really well to go through the process and get the benefits on the other industries that they're serving as well. So I just really appreciate it. Thank you for walking through everything. Thank you for sharing the vision of everything. And if anybody's listening and they're interested, what's the best way to get in touch with you? Absolutely. It's either Google Knox FedRAMP or go to KnoxSystems.com. Reach out to us. We would love to have a conversation. And Anthony, thank you for having me. This was a ton of fun. Thank you, Irena.
