The Rollout
Last reviewed · content updated
AdvancedWhat you'll learn
~18 min- Sequence a program's journey from document-driven to structured to continuous in fundable stages
- Plan around assessor capacity and reciprocity reality instead of policy paper
- Run the program with expiring exceptions and measured gates - then close the training
What it is: a five-stage program plan - honest measurement, structured source, evidence machinery, the pipeline wire, cadence negotiation - run first on one application, then scaled.
What it buys: a path from Word-document compliance to a self-updating package with measured exit gates, assessor conversations ahead of every change, and no double-funded reviews.
What to fund: Stage 0 cannot be bought; fund it first. Then stages in order, a buy-or-build decision judged on exit portability, and an owner for the exception register.
Twenty lessons, one program plan
Everything this training built now needs a deployment plan of its own — because the gap between a Word-document compliance program and Module 6’s wired package is organizational, and organizations move in funded, reviewable stages or not at all. The sequence below is the reference field’s revealed path (every mature program this training drew on walked some version of it), with the traps marked.
STAGE 0 BASELINE HONESTY the gap statement (6.1) + coverage (weeks) accounting (3.1) + clause-stack audit (4.4) - you cannot sequence what you have not measured. Cheap, unglamorous, and the stage most programs skip straight past into tool procurement. BUYS: a funding plan built on measured gaps, not on a vendor demo.
STAGE 1 STRUCTURE THE SOURCE catalog as data (2.1), statements (a quarter-ish) migrated with evolution matrices (2.2), deterministic exports (2.3) - Word becomes an OUTPUT. The package looks the same to consumers; its source of truth changed underneath. BUYS: package changes reviewable as diffs; no more binder rewrites.
STAGE 2 EVIDENCE MACHINERY collectors + verdicts (3.1), the (quarters, honestly) defensible store (3.2), generated docs (3.3) - coverage grows control by control, the accounting table is the roadmap. BUYS: evidence that arrives by itself; assessor hours spent on deltas only.
STAGE 3 WIRE AND NAME the pipeline wire, one control at a (a quarter after 2) time (6.2); the framework mapping (6.3) - the package starts updating itself; the program becomes legible to every external evaluator at once. BUYS: questionnaires answered from one page; evidence-to-package lag in hours.
STAGE 4 CADENCE NEGOTIATION with the AO: from quarterly ritual (the long pole) toward event-driven re-acceptance - the PEOPLE leg (6.1), and the stage that is mostly not an engineering problem. BUYS: re-authorization as a stream of small reviewed diffs instead of a quarterly surge - the calendar cost of every change collapses.Read the stages as a dependency order, not a waterfall: you do not finish every layer for the whole estate before starting the next. Carry one representative application through all five stages — measure what each one bought — and only then scale sideways. The vertical slice finds the surprises while they are cheap.
And the funding decision leadership will actually face — buy or build? Buying a compliance platform accelerates Stages 1 and 2 (structured catalog, collectors, exports) only if you can leave it with your implementation statements, your evidence links, and your history intact — if those are locked inside the product, you have bought a second binder. Stage 0 (honest measurement) cannot be bought from anyone; Stage 4 is a negotiation, not a purchase. The evidence-endpoint choice — a GRC platform (governance, risk, and compliance: the commercial tool category that tracks controls and evidence), OSCAL-shaped bundles for federal consumers, or Module 3’s append-only store as the floor — is the same decision seen from the budget side.
Two planning honesties keep this real. Assessor capacity is a program constraint, not background weather (1.3, final appearance): every stage that changes what assessors see — new package formats in Stage 1, machine verdicts in Stage 2, streaming diffs in Stage 4 — lands only as fast as scarce assessor-hours can absorb it. Engage the assessing side before each stage ships its output; a package format your assessor meets for the first time at assessment is a delay you invoiced yourself. And reciprocity is default-on-paper, lagging-in-practice: plan for the receiving program that accepts your predecessor’s authorization evidence, and for the one that re-reviews everything anyway — sequencing money against paper reciprocity is how programs end up funding the same review twice, angrily.
Run-state: exceptions that expire
The mature program’s steady state borrows the Zero Trust training’s rollout discipline (its closer teaches this at length): every deviation — a control below target, a collector not yet built, a manual step not yet wired — lives as an exception with an owner and an expiry date, reviewed on a cadence, escalating when it lapses. No permanent waivers; no unowned gaps. The gap statement (6.1) evolves from a document into a queue: each line either has a funded stage, an expiring exception, or a decision to accept it — signed by someone entitled to accept it (1.1, one last time: risk acceptance has a name attached).
Prompt first: your program, sequenced
From our gap statement, coverage table, and clause-stack audit, draftthe rollout plan:1) map each gap line to a stage (0-4); flag anything we are doing out of order (building Stage 3 wiring atop Stage 0 measurement debt is the classic) with the cost of the inversion;2) per stage: the exit gate as a MEASURED criterion (coverage count, evidence-to-package lag, export byte-equality streak) - no 'substantially complete' language permitted;3) the assessor-engagement calendar: which stage outputs change what assessors see, and the conversation that precedes each;4) the exception register, seeded: every gap without a funded stage becomes an exception with owner + expiry, or an acceptance line awaiting a named signature. Nothing uncategorized survives.This training began with a contract and a promise: federal delivery is a system you can engineer, not a fog you endure. Twenty lessons later, the claim has hands: a catalog that is data, statements that survive skeptics, evidence a stranger can verify, documents that generate themselves, delivery paths read with clear eyes, packages that cross guarded boundaries intact, and a program that says exactly what it is while becoming something better. The habits underneath were constant: pin your versions, close your vocabularies, name your gaps, let structure enforce what intentions cannot, and spend trust like the currency it is. Meridian’s software is running on the high side (the classified-side enclave it was delivered into). Yours is next.
A program with a Word-based package and no coverage accounting gets budget for one year and proposes: spend it standing up the full pipeline wire (Stage 3) immediately, since the self-updating package is the end state anyway and the intermediate stages are scaffolding. What does the sequencing lesson predict?
Practice status — among mature regulated delivery programs, commercial and federal
(a few rows carry a more specific status - principle, canon, suspended - where one of the five would mislead)
| Practice | Status | Also called |
|---|---|---|
| staged rollout in dependency order | common baseline | capability roadmap |
| vertical slice first | common baseline | thin-slice / pilot application |
| expiring exception register | strong optional (commercial); federal programs pair it with the required POA&M (Plan of Action and Milestones) - related, not the same: the POA&M tracks remediation plans; the register records accepted risk with an owner and an expiry | — |
| assessor-engagement calendar | strong optional no surprise package formats at assessment | — |
| buy-vs-build on exit portability | decision buying helps Stages 1-2 only if your data leaves with you | — |
Scale: required | common baseline | strong optional | reference-shop (seen only at organizations that publish their own practice) | emerging
Key takeaway
Sequence the journey in dependency order — honesty, structure, machinery, wiring and naming, cadence — with measured exit gates, assessor conversations ahead of every output change, reciprocity planned as it behaves rather than as it reads, and every gap owned, expiring, or signed for. That is the whole training compressed: engineer the system, calibrate the claims, and let the package earn the trust its signature spends. The sequence ends here; the delivery is yours.
LEADERSHIP DECISION fund the stages in dependency order with measured exit gates, decide buy-vs-build on exit portability, and sign the exception register's acceptances yourself (or route them to the AO, the authorizing official, where a federal authorization is in play)PRACTITIONER ACTION sequence from the gap statement, run one application through all five stages first, keep an assessor- engagement calendar, seed the exception registerSUCCESS MEASURE each stage exits on a measured criterion by a dated calendar; zero assessor-side surprises when a package format changes; every gap owned, expiring, or signed for