The Software That Runs Federal Buildings Needs Its Own Security Path

Published on Sep 12, 2026

By Etrit Demaj

When we began pursuing FedRAMP High authorization, we assumed the biggest challenge would be proving our platform was secure enough for the federal government.

We were wrong. The hard part wasn’t cybersecurity. It was access.

FedRAMP, the Federal Risk and Authorization Management Program, is the security review a cloud product has to pass before a federal agency can buy it. High is the top tier, reserved for systems where a breach would cause severe damage. Most software at that level stores or analyzes sensitive information. Ours runs buildings. KODE OS ties together the heating, lighting, metering and access systems inside a building, which normally sit on separate platforms that can’t talk to each other, so one team can run a whole portfolio from one screen.

We rarely debated whether our technology could meet the requirements. The challenge was finding a path to prove it and this summer, KODE OS achieved FedRAMP High through Palantir’s FedStart program.

But the experience revealed something much larger than our own authorization. It offered a window into how innovative technology increasingly reaches the federal government, and why the next challenge isn’t strengthening security standards but ensuring the path to meeting them remains open to the companies building the next generation of government technology.

FedRAMP has evolved significantly over the past year. For years, authorization was associated with lengthy timelines, extensive documentation, and the need for an agency sponsor before many companies could even begin the process. The problem wasn’t only the time involved. Many innovative software companies, especially those without long-standing federal relationships, never had the opportunity to compete.

Recent modernization efforts are beginning to change that.

By shifting toward machine-readable evidence, continuous validation, and a less burdensome authorization process for many cloud services, FedRAMP is demonstrating that security and speed do not have to be opposing goals.

This is even better news for the government. The more innovative companies that can compete without compromising security, the more choice agencies have when solving increasingly complex operational challenges.

The highest-impact systems, however, still follow a different path.

A scheduling tool going offline is an inconvenience. A building losing ventilation or power is not. Software in that second category relies on the traditional authorization process: agency sponsorship, extensive documentation, and timelines that can stretch well beyond a year.

That line matters more today than it did even a few years ago.

Agencies are increasingly adopting platforms that operate buildings, manage energy systems, monitor physical infrastructure, automate industrial processes, and support AI-powered operations.

These systems don’t hold a record of how infrastructure performs. They determine it.

That is exactly where KODE Labs operates.

We didn’t pursue FedRAMP High to earn another certification. We pursued it because government facilities deserve the same modern, cloud-native operating platforms transforming commercial real estate. If software can help federal teams operate buildings more efficiently, securely, and intelligently, it should meet the highest security standard. We welcomed that challenge.

Through our work with the General Services Administration’s Public Buildings Service, KODE OS helps teams manage operations across more than 150 federal buildings in the National Capital Region. By bringing together systems that historically operated in isolation, the platform provides a unified operational view and enables portfolio-wide management rather than building-by-building operations.

Software capable of remotely monitoring and controlling critical building infrastructure should be held to the highest security standard. The opportunity is not to lower the bar, but to modernize how companies demonstrate they can clear it.

Our experience highlighted an unintended consequence.

Today, a company building high-impact operational technology has two realistic paths. It can invest years and significant resources pursuing traditional authorization before earning meaningful federal revenue, or it can work through an environment that has already been authorized. FedStart is one. Palantir took its own cloud environment through FedRAMP High, so software deployed inside it inherits the controls already assessed at the infrastructure level, leaving only the application itself to review. We weren’t given an easier test. We were given a smaller portion of the same one, and it made our authorization possible.

Programs like FedStart play an important role. They get secure technology to agencies faster without loosening the standard. But they also reveal a broader reality: at the highest security tier, access itself is becoming a competitive advantage. Neither a company’s balance sheet nor its route to an authorized environment tells you how secure its software is, or whether it delivers better outcomes for the agency buying it. Yet both increasingly decide which companies can realistically compete.

That isn’t a criticism of FedRAMP.

If anything, it highlights how successful the program has been in raising the security standard across government. FedRAMP deserves enormous credit for modernizing one of the government’s most important security frameworks while maintaining existing authorizations and reducing years of accumulated backlog.

The challenge now is ensuring that modernization reaches the technologies increasingly responsible for operating the nation’s critical infrastructure.

Three practical steps would make a meaningful difference.

First, the Office of Management and Budget, which sets the federal cloud security policy FedRAMP operates under, should publish a clear roadmap for modernizing authorization for high-impact operational systems. Companies building for federal infrastructure are making long-term investment decisions today, and predictability is often as valuable as speed.

Second, continue expanding the principles behind FedRAMP’s modernization. Continuous validation and machine-readable evidence provide a more accurate picture of an organization’s security posture than static documentation. Those principles should extend to the systems where resilience matters most.

Finally, recognize that operational technology is fundamentally different from traditional cloud software. Building operating systems, industrial controls, energy platforms, and physical infrastructure present unique security considerations that future authorization frameworks should reflect from the outset.

None of these recommendations lower the security bar. Quite the opposite. They build on the progress FedRAMP has already made by helping the government identify, validate, and adopt secure technologies more efficiently, particularly in the areas where operational resilience is most critical.

When we started this journey, we thought the destination was earning FedRAMP High.

Looking back, it was really the beginning of a much bigger conversation.

It gave us a deeper appreciation for the work FedRAMP is doing to modernize government security while reinforcing the value of programs like FedStart. It also showed us there is still an opportunity to ensure the highest-impact operational technologies benefit from that same spirit of modernization.

I expect that, over time, programs like FedStart become accelerators rather than necessities. That companies building the next generation of government technology have multiple paths to demonstrate they meet the highest security standards, without compromising the rigor those standards demand.

Because in the end, the companies solving government’s most important challenges should be distinguished by the strength of their security and the quality of their technology, not by how difficult it was to reach the starting line.

Etrit Demaj is the Co-Founder of KODE Labs.