Secure Software Delivery for Federal Environments Module 6 · Toward Continuous

The Rollout

Last reviewed · content updated

Advanced

What you'll learn

~18 min
  • Sequence a program's journey from document-driven to structured to continuous in fundable stages
  • Plan around assessor capacity and reciprocity reality instead of policy paper
  • Run the program with expiring exceptions and measured gates - then close the training
ℹLeadership brief

What it is: a five-stage program plan - honest measurement, structured source, evidence machinery, the pipeline wire, cadence negotiation - run first on one application, then scaled.

What it buys: a path from Word-document compliance to a self-updating package with measured exit gates, assessor conversations ahead of every change, and no double-funded reviews.

What to fund: Stage 0 cannot be bought; fund it first. Then stages in order, a buy-or-build decision judged on exit portability, and an owner for the exception register.

Twenty lessons, one program plan

Everything this training built now needs a deployment plan of its own — because the gap between a Word-document compliance program and Module 6’s wired package is organizational, and organizations move in funded, reviewable stages or not at all. The sequence below is the reference field’s revealed path (every mature program this training drew on walked some version of it), with the traps marked.

STAGE 0 BASELINE HONESTY the gap statement (6.1) + coverage
(weeks) accounting (3.1) + clause-stack audit
(4.4) - you cannot sequence what you
have not measured. Cheap, unglamorous,
and the stage most programs skip
straight past into tool procurement.
BUYS: a funding plan built on measured
gaps, not on a vendor demo.
STAGE 1 STRUCTURE THE SOURCE catalog as data (2.1), statements
(a quarter-ish) migrated with evolution matrices (2.2),
deterministic exports (2.3) - Word
becomes an OUTPUT. The package looks
the same to consumers; its source of
truth changed underneath.
BUYS: package changes reviewable as
diffs; no more binder rewrites.
STAGE 2 EVIDENCE MACHINERY collectors + verdicts (3.1), the
(quarters, honestly) defensible store (3.2), generated
docs (3.3) - coverage grows control
by control, the accounting table
is the roadmap.
BUYS: evidence that arrives by itself;
assessor hours spent on deltas only.
STAGE 3 WIRE AND NAME the pipeline wire, one control at a
(a quarter after 2) time (6.2); the framework mapping
(6.3) - the package starts updating
itself; the program becomes legible
to every external evaluator at once.
BUYS: questionnaires answered from one
page; evidence-to-package lag in hours.
STAGE 4 CADENCE NEGOTIATION with the AO: from quarterly ritual
(the long pole) toward event-driven re-acceptance -
the PEOPLE leg (6.1), and the stage
that is mostly not an engineering
problem. BUYS: re-authorization as a
stream of small reviewed diffs instead
of a quarterly surge - the calendar
cost of every change collapses.

Read the stages as a dependency order, not a waterfall: you do not finish every layer for the whole estate before starting the next. Carry one representative application through all five stages — measure what each one bought — and only then scale sideways. The vertical slice finds the surprises while they are cheap.

And the funding decision leadership will actually face — buy or build? Buying a compliance platform accelerates Stages 1 and 2 (structured catalog, collectors, exports) only if you can leave it with your implementation statements, your evidence links, and your history intact — if those are locked inside the product, you have bought a second binder. Stage 0 (honest measurement) cannot be bought from anyone; Stage 4 is a negotiation, not a purchase. The evidence-endpoint choice — a GRC platform (governance, risk, and compliance: the commercial tool category that tracks controls and evidence), OSCAL-shaped bundles for federal consumers, or Module 3’s append-only store as the floor — is the same decision seen from the budget side.

Two planning honesties keep this real. Assessor capacity is a program constraint, not background weather (1.3, final appearance): every stage that changes what assessors see — new package formats in Stage 1, machine verdicts in Stage 2, streaming diffs in Stage 4 — lands only as fast as scarce assessor-hours can absorb it. Engage the assessing side before each stage ships its output; a package format your assessor meets for the first time at assessment is a delay you invoiced yourself. And reciprocity is default-on-paper, lagging-in-practice: plan for the receiving program that accepts your predecessor’s authorization evidence, and for the one that re-reviews everything anyway — sequencing money against paper reciprocity is how programs end up funding the same review twice, angrily.

Run-state: exceptions that expire

The mature program’s steady state borrows the Zero Trust training’s rollout discipline (its closer teaches this at length): every deviation — a control below target, a collector not yet built, a manual step not yet wired — lives as an exception with an owner and an expiry date, reviewed on a cadence, escalating when it lapses. No permanent waivers; no unowned gaps. The gap statement (6.1) evolves from a document into a queue: each line either has a funded stage, an expiring exception, or a decision to accept it — signed by someone entitled to accept it (1.1, one last time: risk acceptance has a name attached).

Prompt first: your program, sequenced

From our gap statement, coverage table, and clause-stack audit, draft
the rollout plan:
1) map each gap line to a stage (0-4); flag anything we are doing out
of order (building Stage 3 wiring atop Stage 0 measurement debt is
the classic) with the cost of the inversion;
2) per stage: the exit gate as a MEASURED criterion (coverage count,
evidence-to-package lag, export byte-equality streak) - no
'substantially complete' language permitted;
3) the assessor-engagement calendar: which stage outputs change what
assessors see, and the conversation that precedes each;
4) the exception register, seeded: every gap without a funded stage
becomes an exception with owner + expiry, or an acceptance line
awaiting a named signature. Nothing uncategorized survives.
💬The closing argument

This training began with a contract and a promise: federal delivery is a system you can engineer, not a fog you endure. Twenty lessons later, the claim has hands: a catalog that is data, statements that survive skeptics, evidence a stranger can verify, documents that generate themselves, delivery paths read with clear eyes, packages that cross guarded boundaries intact, and a program that says exactly what it is while becoming something better. The habits underneath were constant: pin your versions, close your vocabularies, name your gaps, let structure enforce what intentions cannot, and spend trust like the currency it is. Meridian’s software is running on the high side (the classified-side enclave it was delivered into). Yours is next.

KNOWLEDGE CHECK

A program with a Word-based package and no coverage accounting gets budget for one year and proposes: spend it standing up the full pipeline wire (Stage 3) immediately, since the self-updating package is the end state anyway and the intermediate stages are scaffolding. What does the sequencing lesson predict?

Practice status — among mature regulated delivery programs, commercial and federal

(a few rows carry a more specific status - principle, canon, suspended - where one of the five would mislead)

PracticeStatusAlso called
staged rollout in dependency ordercommon baselinecapability roadmap
vertical slice firstcommon baselinethin-slice / pilot application
expiring exception registerstrong optional (commercial); federal programs pair it with the required POA&M (Plan of Action and Milestones) - related, not the same: the POA&M tracks remediation plans; the register records accepted risk with an owner and an expiry—
assessor-engagement calendarstrong optional no surprise package formats at assessment—
buy-vs-build on exit portabilitydecision buying helps Stages 1-2 only if your data leaves with you—

Scale: required | common baseline | strong optional | reference-shop (seen only at organizations that publish their own practice) | emerging

Key takeaway

Sequence the journey in dependency order — honesty, structure, machinery, wiring and naming, cadence — with measured exit gates, assessor conversations ahead of every output change, reciprocity planned as it behaves rather than as it reads, and every gap owned, expiring, or signed for. That is the whole training compressed: engineer the system, calibrate the claims, and let the package earn the trust its signature spends. The sequence ends here; the delivery is yours.

LEADERSHIP DECISION fund the stages in dependency order with measured exit
gates, decide buy-vs-build on exit portability, and sign
the exception register's acceptances yourself (or route
them to the AO, the authorizing official, where a
federal authorization is in play)
PRACTITIONER ACTION sequence from the gap statement, run one application
through all five stages first, keep an assessor-
engagement calendar, seed the exception register
SUCCESS MEASURE each stage exits on a measured criterion by a dated
calendar; zero assessor-side surprises when a package
format changes; every gap owned, expiring, or signed for
Search lessons