Moving from compliance activity to measurable cybersecurity outcomes
BOTTOM LINE UP FRONT
Security programs must demonstrate performance, not just produce paperwork.
Bottom-Line-Up-Front
Shifting from repetitive, document-heavy compliance processes to deterministic telemetry and risk-based vulnerability management can reduce RMF administrative costs while improving cybersecurity outcomes. Armory™ and RADAR help agencies continuously measure security posture, prioritize the risks that matter most, and redirect limited resources toward urgent mission priorities.
The paperwork tower is no longer a measure of security
Federal agencies are being asked to defend increasingly complex environments while confronting constrained budgets, workforce limitations, and an expanding list of cybersecurity mandates. Something eventually has to give.
The Office of Management & Budget (OMB) is signaling that the answer cannot simply be another funding request, or another layer of compliance reporting.
Speaking at MeriTalk’s Shift Happens event, Nick Polk, branch director for federal cybersecurity at OMB, argued that cybersecurity investments should be evaluated against the actual performance of agency security programs. OMB is increasingly emphasizing operational measures such as mission enablement and mean time to detect rather than relying primarily on checklist completion.
“You can check all the boxes … and you have a paperwork tower the size of … the Empire State Building.
— Nick Polk, OMB Federal Cybersecurity Branch Director
Polk’s larger point was not that compliance has no value. It was that compliance activity disconnected from operational outcomes can burden IT teams without materially improving security.
The Risk Management Framework remains essential for accountability, risk decisions, and authorization. The problem is the enormous amount of manual administration that has grown around it: screenshots, spreadsheets, scanner exports, rewritten implementation statements, and evidence packages that reconstruct system state long after the fact.
THE OPPORTUNITY COST
Every duplicative GRC dollar is a dollar unavailable to defend the mission.
Administrative cybersecurity spending does not occur in a vacuum. Every dollar and labor hour consumed by redundant evidence collection or overlapping Governance, Risk & Compliance (GRC) tooling is unavailable for emerging mission priorities. The pressure is becoming particularly acute.
Three priorities. One constrained workforce.
CISA BOD 26-04 requires agencies to modernize vulnerability prioritization and move beyond a primarily severity-based model. Agencies must evaluate factors such as known exploitation, public exposure, exploit automatability, reachability, and potential technical impact. The directive establishes a more operational approach to vulnerability management and gives agencies only 180 days to implement the required capabilities.
At the same time, OMB Memorandum M-26-15 requires agencies to submit post-quantum cryptography migration plans within 120 days and pursue prioritized migration with the objective of mitigating as much quantum risk as feasible by December 31, 2030. OMB recognizes that manual methods are insufficient at federal scale and encourages automation for discovery, policy enforcement, continuous monitoring, and reporting.
Agencies are also deploying AI systems that introduce new requirements for model security, data protection, supply-chain assurance, monitoring, and adversarial testing. These priorities require engineering, tooling, and skilled personnel, not merely additional documentation.
THE BUDGET QUESTION
How much of the cybersecurity budget is improving defense and how much is repeatedly describing it?
A BETTER EVIDENCE MODEL
From periodic evidence collection to deterministic telemetry
Deterministic telemetry means collecting security and compliance information directly from authoritative technical sources using repeatable, testable queries. The same defined test against the same system state should produce the same result, along with the source, timestamp, rule, and supporting evidence used to reach it.
Continuously answer the questions that matter
- Is multifactor authentication enforced for privileged access?
- Are audit logs enabled, retained, and routed to the required destination?
- Are storage services or workloads publicly accessible?
- Which vulnerabilities are exposed, reachable, exploited, or mission-critical?
- When did a control state change and was that change authorized?
- How quickly are consequential findings detected, assigned, and remediated?
This does not eliminate human judgment. Risk acceptance, mission impact, compensating controls, and authorization decisions remain human responsibilities. It allows those decisions to be based on current, traceable technical evidence instead of static documentation and institutional memory.
THE SHIFT
Stop asking, “Do we have the artifact?” Start asking, “What does the system state tell us right now?”
OPERATIONAL PRIORITIZATION
Risk-based vulnerability management puts resources where they matter
Traditional programs often treat CVSS severity as the primary driver of remediation. That approach can produce large queues of nominally critical findings without identifying which vulnerabilities present the most immediate danger to the mission.
Context changes the queue
Risk-based vulnerability management distinguishes between a theoretical vulnerability buried in an unreachable component and an exploitable weakness on a mission-critical, internet-facing system. Both may require attention, but they should not automatically compete for resources on equal terms.
That is the central logic behind BOD 26-04, and it aligns directly with OMB’s call for risk-based cybersecurity investment. Smarter spending requires smarter prioritization.
STATIC PRIORITIZATION | RISK-BASED PRIORITIZATION |
CVSS as primary signal | Exploitation + exposure + reachability |
Large undifferentiated backlog | Mission-driven remediation queue |
Periodic reporting | Continuous disposition and metrics |
THE STACKARMOR MODEL
Armory and RADAR operationalize the transition
stackArmor’s Armory and RADAR offerings are designed to connect authorization evidence with operational security performance.
SECURE FOUNDATION
ARMORY™
Purpose-built high-assurance cloud architecture with integrated security services, defined control implementations, continuous monitoring, and managed authorization support.
DETERMINISTIC TELEMETRY
RADAR
Retrieve, Analyze, Document, Assess, and Report technical evidence from cloud, identity, scanner, container, code, and security sources.
Together, they help agencies:
REDUCE duplicative security and GRC tooling. | REPLACE manual evidence collection with continuous technical validation. |
MEASURE control performance using current operational data. | PRIORITIZE vulnerabilities using exploitation, exposure, reachability, and mission impact. |
REUSE evidence across RMF, continuous monitoring, executive reporting, Post Quantum Cryptography (PQC), and AI security. | REDIRECT security personnel toward remediation and mission delivery. |
IMPORTANT
This is not about weakening RMF or checking fewer boxes. It is about reducing the cost of proving what the environment can already demonstrate and using the savings to improve the environment itself.
THE DECISION
Make compliance earn its place in the cybersecurity budget
Agencies should not have to choose between maintaining an authorization and securing AI, migrating to PQC, or meeting the aggressive requirements of BOD 26-04. Avoiding that choice requires a more efficient approach to RMF and GRC.
The future of federal cybersecurity measurement will not be another larger collection of documents. It will be a continuously updated body of technical evidence showing what is deployed, how it is configured, where risk is concentrated, and whether the security program is improving mission resilience.
FROM COMPLIANCE ACTIVITY
TO SECURITY PERFORMANCE
Make every cybersecurity dollar work harder for the mission.
Together, they help agencies:
- Which evidence-collection activities can be replaced with repeatable technical queries?
- Which overlapping GRC or security tools are producing the same information?
- Can leadership see current operational metrics or only the last reporting package?
- Does vulnerability prioritization reflect mission risk, or merely scanner severity?
- How much capacity could be redirected to BOD 26-04, PQC, and AI security?
Together, they help agencies:
- MeriTalk — OMB Cyber Branch Chief Pushes for Smarter Cyber Spending
- CVSS In Transition: CISA BOD 26-04, FedRAMP VDR, and the Rise of Risk-Based Vulnerability Management
- CISA — BOD 26-04: Prioritizing Security Updates Based on Risk
- OMB — M-26-15: Execution of the Migration to Post-Quantum Cryptography
- stackArmor — The Armory


