Secure Software Delivery for Federal Environments
Translate compliance into engineering — the authorization lifecycle as data, evidence you can defend, machine-readable packages in two competing formats, the real federal delivery paths, and software that crosses classified boundaries intact.
6 modules · 20 lessons · ~5.7 hours · Federal program teams, ISSOs, DevSecOps teams
Chapter 4 in the Meridian sequence · 9 live so far · builds on Zero Trust Implementation and Modern DevSecOps Foundations · continues in Building Trustworthy Data Products
The fictional Meridian Utilities just won a state-federal interconnect contract — and for the first time, its software must be delivered into a federal environment: with an authorization package, evidence a stranger can verify, and a copy that crosses an air gap. Grounded in the live 2026 landscape (800-53 Release 5.2.0, FedRAMP's rewritten Certification Classes, the DoD continuous-authorization triad, the CMMC suspension), this training walks the authorization lifecycle end to end: the control catalog as data, implementation statements that survive assessment, defensible evidence stores, machine-readable packages in two competing formats, the real delivery paths, and cross-domain transfer mechanics. You'll change seats along the way — vendor, evaluator, contractor — because federal delivery is a multi-seat world, and Lesson 1.1 tells you why. Every lesson uses AI CLI tools to do the real work. No prior Meridian knowledge needed.
The Curriculum
The Map
RMF without the mythology
How federal authorization actually works, the control catalog as versioned software, and the three speeds of getting to production
Controls Into Code
Assessor thinking, encoded
The control catalog as schema-gated data, implementation statements that survive assessment, and the two machine-readable package worlds
Evidence and Assessment
Proof you can defend
Plugin collectors with honest verdicts, an evidence store whose trust model is documented rather than assumed, and audit documents generated deterministically
The Delivery Paths
Four roads into production
FedRAMP after the rewrite, the DoD continuous-authorization triad, inheritance platforms with quantified gates, and the contractor floor that never paused
Across the Boundary
Deliver into the enclave
Vendoring for the air gap, transfer lifecycles that make tampering structural rather than trusted, and deployment where nobody can SSH in to fix it
Toward Continuous
Close the gap honestly
The distance between conmon machinery and continuous authorization, the pipeline wired to the package, the frameworks you already practice, and a rollout that respects assessor capacity
New to AI CLI tools?
This training assumes you can drive an AI CLI (Claude Code, Codex CLI, Antigravity CLI, or Copilot CLI). If that's new, these modules from our AI-Powered Development training are the fastest preparation — most students need only the first one: