
For more than a decade, modernization in enterprise technology circles largely meant one thing: move legacy systems to the cloud. And to be fair, that shift solved many real problems. Elastic compute replaced hardware constraints, distributed storage improved resilience, and infrastructure provisioning became dramatically faster.
But as agencies increasingly operate across complex ecosystems of cloud services, data platforms, analytics engines, and mission applications, something interesting has started to happen. Teams are realizing that simply moving systems to the cloud doesn’t automatically free them from the architectural gravity of the past. Many systems that migrated successfully still behave like they did when they lived in data centers, rigid, tightly coupled, and surprisingly difficult to evolve.
Read on LinkedIn

ASSYST will be exhibiting at AFCEA Belvoir Industry Days, May 5-7, 2026 (ABID 2026), a premier defense and technology event hosted at the Hilton Alexandria Mark Center, 5000 Seminary Rd, Alexandria, VA 22311.
https://www.afceabelvoirindustrydays.com/event/c4f8035c-4584-4af1-b668-af3c23d6e854/agenda
The event brings together leaders from the Department of War, the U.S. Army, federal agencies, and industry to discuss mission priorities, technology modernization, cybersecurity, data analytics, and artificial intelligence solutions that support national security.
Representing ASSYST at the event will be Loren Gray, Program Manager, and William Earp, General Manager of G-14C, ASSYST’s joint venture partner.

LOREN GRAY, Program Manager, DoW/Army Programs | LinkedIn

WILLIAM EARP, General Manager, G-14C, LLC | LinkedIn
With more than three decades of experience supporting federal civilian, defense, and public-sector missions, ASSYST continues to invest in advanced capabilities, including AI-enabled software engineering, secure data platforms, and mission-ready cybersecurity solutions.
ASSYST looks forward to meeting with program leaders, technology partners, and mission stakeholders attending AFCEA Belvoir Industry Days 2026.

The Breach That Logs In: Joe Anderson and William Earp discuss Insider Threat, AI-Ready Architecture, and the Science of Behavioral Risk.

ASSYST's Loren Gray and Sneha Belur, MSIST, CSM, CSPO discuss going from Low/No Code to AI Code, and how Delivery is Now a Team Sport.
Continue reading on LinkedIn
On Sunday, February 8, the ASSYST team gathered to serve lunch at SOME (So Others Might Eat) at the Father John Adams Resource Center in Washington, D.C.

The day started early, but the energy was unmistakable. Instead of spending the weekend at home or catching up on personal plans, our team chose to show up for others, standing shoulder to shoulder in a fast-moving kitchen and dining space, helping prepare and serve lunch to individuals and families in need.
At SOME, every meal is more than food. It’s dignity. It’s care. It’s a reminder that someone still sees you.
As our volunteers moved through the lunch service, setting up the tables, serving food, and supporting the SOME staff, something powerful happened: the day became less about volunteering and more about connection. Beyond the satisfaction of contributing to the community, our team gained an even deeper respect for the SOME staff. Witnessing their dedication firsthand was a powerful reminder of the care required for the mission every day.
ASSYST Together is about carrying our shared momentum into something that matters. Seeing our team serve with such kindness and teamwork reminded me that our culture is strongest when it’s lived, not just celebrated. This was a beautiful way to start the year.

To everyone who participated, thank you for representing ASSYST with compassion, humility, and purpose.
This was just the first step in what we hope will be a year of continued service, connection, and community impact.
ASSYST's Khalil Zebdi, Vinay Shirke, Jessica Hayden, and Christopher T. David will attend the CMS Industry Forum on February 19th, 2026.
Make sure to stop by and meet us!

For more details



ASSYST is pleased to announce it was awarded a contract/s for the Missile Defense Agency Scalable Homeland Innovative Enterprise Layered Defense (SHIELD) indefinite-delivery/indefinite-quantity (IDIQ) contract with a ceiling of $151B. This contract encompasses a broad range of work areas that enable rapid delivery of innovative capabilities to the warfighter, with increased speed and agility. cyber resilience, data exploitation, secure cloud engineering, continuous modernization, and intelligence-driven capabilities.
ASSYST MDA SHIELD Contract Vehicle: https://www.assyst.net/contracts/mda-shield-idiq
ASSYST #DefenseTech Capabilities: Click Here
Contact: Eugene Goldlust | egoldlust@assyst.net | LinkedIn

As part of our Post-Quantum Cryptography (PQC) thought leadership series, we continue the conversation with Vijay Narasimhan, CTO of ASSYST, to explore how PQC is moving from future planning into present-day authorization. Over the next several weeks, we will cover broad areas, including Agile Infrastructure & Platforms, Quantum-Safe Compute and the Software Supply Chain, Quantum Resilient Identity, Access & Trust, Post-Quantum Data Protection and Cryptographic Resilience, and PQC Governance, Risk & Continuous Authorization.
With new legislation like the GENIUS Act shaping external crypto oversight and CISA and NIST defining quantum-safe standards, agencies now face a dual mandate: govern digital assets with confidence while modernizing their own cryptographic foundations. In this segment, we examine how PQC is becoming an enforceable control within the Risk Management Framework (RMF), turning quantum-safe encryption into a pass/fail requirement for every Authority to Operate (ATO) and every cybersecurity role across the federal enterprise.
Eugene: Vijay, in our last conversation, we discussed crypto governance from regulatory and market trust perspectives. Let’s bring this inside the federal enterprise. With CISA’s new Post-Quantum Cryptography product guidance and NIST finalizing standards, how does PQC actually show up in day-to-day RMF and ATO decisions?
Vijay Narasimhan: This is where things become very real. PQC stops being an abstract “future risk” and becomes an authorization requirement. RMF is the machinery agencies already trust; it’s how they categorize systems, select controls, assess risk, and grant Authority to Operate. What PQC does is insert a new, non-negotiable cryptographic checkpoint into that machinery.
In simple terms: if your system uses encryption, identity, digital signatures, VPNs, or key management, then the CISO will soon have to ask, “Is this quantum-safe, or at least on a defined migration path?” If the answer is no, that becomes an ATO risk finding, just like missing MFA or logging.

Eugene: So PQC becomes a pass/fail gate, not just a roadmap slide?
Vijay: Exactly. Think of it like TLS in the early 2000s. At first, it was “nice to have.” Then it became “recommended.” Eventually, it became “no TLS, no production.” PQC will follow the same arc, but faster, because the threat model is already known: harvest-now, decrypt-later.
CISA’s product category guidance is important because it first specifies its scope: cloud services, network security, identity systems, HSMs, PKI, and secure communications. These are the same components that RMF already treats as foundational controls. Now they also have to be crypto-agile and PQC-ready.
Eugene: Walk us through how this lands in the RMF lifecycle.
Vijay: During Prepare and Categorize, we are still operating squarely within the Risk Management Framework that agencies have used for decades, not a newly coined construct. RMF already requires agencies to identify mission systems, data sensitivity, and threat exposure. What changes with PQC is the lens: agencies must now classify which systems rely on quantum-vulnerable cryptography and which protect long-lived data, financial records, health data, and mission telemetry that must remain confidential for decades. These become the first candidates for PQC prioritization and migration planning.
During Select and Implement, instead of simply stating “use approved encryption,” the control language will evolve to say “use NIST-approved post-quantum or hybrid algorithms, or document an approved transition plan.” Procurement will reference CISA’s PQC-ready product categories the same way it references FedRAMP today.
During Assess, auditors won’t just test whether encryption exists. They’ll test what algorithms, what key sizes, what libraries, what hardware roots of trust, and whether the cryptographic bill of materials includes quantum-vulnerable components.
During Authorize, the Authorizing Official will be making a risk decision that explicitly includes quantum exposure. A system may be fully compliant with today’s controls, yet still receive conditions or a limited ATO if it cannot demonstrate crypto-agility.

Eugene: That’s a big shift in mindset for ISSOs and program managers.
Vijay: It is. That’s why we say PQC is not a science project; it’s a governance transformation. ISSOs become cryptographic assurance officers. Program managers have to plan PQC transitions as funded milestones. Enterprise architects must design for algorithm swap-ability the same way they design for cloud portability.
This is where platforms like ComplySyncATO and Athena Agentic AI come into play. Standards-ready compliance automation means that when NIST or CISA updates cryptographic requirements, those controls can be ingested, mapped to RMF, and continuously evaluated, rather than waiting for the next three-year ATO cycle.
Eugene: How does this play out in continuous authorization and monitoring?
Vijay: Some agencies have already matured enough to implement Continuous Authorization for select systems, particularly High-Value Assets (HVAs). Many others are actively striving toward this model. This is where the final Monitor step becomes critical. PQC readiness must be baked into continuous assessment reporting, tracking algorithm usage, certificate lifecycles, crypto modules, and migration progress as living risk indicators. In this future state, systems are not only Zero Trust by design, but quantum-aware by design, with cryptographic posture continuously measured and attested.

Eugene: And where should agencies start from a technology standpoint?
Vijay: As CISA highlighted this week, the transition to PQC can begin with widely adopted layers such as Cloud Platform-as-a-Service (PaaS) and Infrastructure-as-a-Service (IaaS), where encryption, identity, and key management are centralized. At the same time, agencies still operating on-premises datacenters should view cloud migration and PQC transition as converging imperatives. There is no time to waste; quantum readiness must now be evaluated across on-prem, hybrid, and cloud environments at every RMF step.
Eugene: So the message for agencies is: PQC is not a parallel effort, it’s an RMF evolution.
Vijay: Exactly. You don’t “do PQC” separately. You embed it into how you authorize, operate, and modernize systems. RMF is the process. PQC is now part of the required math inside that process. And the strategic point is this: If the GENIUS Act tells us cryptography is now a matter of national economic trust, then PQC + RMF tells us cryptography is also a matter of operational mission trust. Every ATO, every cloud migration, every Zero Trust rollout, every identity system refresh must now be quantum-aware by design.
Eugene: What’s the forward look for this series?
Vijay: The next frontier is people. Technology and policy can move only as fast as the workforce that operates them. We’ll explore how agencies must upskill ISSOs, architects, program managers, and auditors to become crypto-agile, ready to validate PQC, govern cryptographic risk, and sustain quantum-safe operations. Workforce readiness will be the final pillar of true cryptographic resilience.

ASSYST, Inc., a leading provider of cybersecurity, cloud, and compliance automation solutions for the U.S. Federal Government, today announced its selection as an official participant in the FedRAMP® 20x Phase 2 Pilot, managed by the US General Services Administration (GSA). The pilot is designed to modernize the Federal Risk and Authorization Management Program by validating automated security assessment methods and machine-readable authorization packages.
As a member of Cohort 2, ASSYST is among a select group of 13 cloud service providers chosen to help pioneer a faster, more transparent, and automation-driven path to federal cloud authorization. ASSYST is participating with its ComplySyncATO (https://www.assyst.net/ComplySyncAI) platform, an AI-enabled Governance, Risk, and Compliance (GRC) automation solution purpose-built to support continuous authorization and persistent assessment. The Phase 2 pilot focuses on three key modernization areas:
“Selection for the FedRAMP 20x Phase 2 Pilot validates ASSYST’s long-standing investment in Cybersecurity and AI-driven compliance automation and continuous risk management,” said Vijay Narasimhan, CTO, ASSYST. “With ComplySyncATO, we are helping agencies move beyond document-centric compliance, point-in-time compliance to a real-time, automated and machine-verifiable toward real-time, machine-verifiable security assurance.” he added.
The Phase 2 pilot will conclude around March 31, 2026, informing the broader rollout of the FedRAMP 20x operating model in Phase 3 and accelerating adoption of automated authorization and continuous monitoring across the federal cloud ecosystem.
Read more on GSA FedRAMP.Gov - https://www.fedramp.gov/20x/phase-two/participate/
About ASSYST
ASSYST is the One Point Source for mission-grade cybersecurity and digital solutions, delivering CMMI Level 3 and ISO 27001/20000/9001 certified excellence across National Security, Defense Technology, Healthcare IT, Regulatory, and State and Local Government domains. Through offerings such as ISSO-as-a-Service, Cyber Risk Assessment (CRA)-as-a-Service, and the AI-powered ComplySyncATO platform, ASSYST automates compliance, enables continuous Authorization to Operate (cATO), and provides real-time, data-driven risk visibility. Powered by the Security Data Lake (SDL) and Security Data Fabric (SDF), ASSYST integrates and analyzes enterprise security telemetry to support persistent monitoring, Zero Trust, and resilient cyber operations—demonstrating an unwavering commitment to protecting our nation’s most critical systems and data. For more details - www.assyst.net/cyber