A FedRAMP deadline can either freeze a company or force it to get sharper. Jason LaPointe and Michael Parisi break down how Exostar cleared a moderate authorization on an accelerated timeline, built a new compliant platform without breaking its customers, and turned an audit into a growth engine for the defense supply chain.
For companies in the defense industrial base, a compliance deadline is not paperwork. It is the difference between winning contracts and watching them stall. In this Brand Feature, Jason LaPointe, Chief Technology Officer at Exostar, and Michael Parisi, Chief Growth Officer at Steel Patriot Partners, walk through what it takes to get FedRAMP ready without cutting corners.
Exostar was born out of a consortium that included Boeing and Lockheed Martin, and its FedRAMP-moderate posture lets smaller suppliers keep working on Department of War contracts. How does that work? Instead of moving every server and mailbox into a secure boundary, a supplier inherits roughly 80% of the controls from Exostar, which shrinks the scope of its own CMMC audit considerably.
The clock was real. At the time, a November transition date loomed, after which many suppliers could no longer self-attest. That specific timeline has since been paused, but the pressure to prove readiness has not gone away. Exostar needed to show it was FedRAMP-moderate and ready for an audit, and working with Steel Patriot Partners, the team pulled a January target in by nearly three months, not by skipping steps, but by moving with confidence.
Why build a new platform instead of retrofitting the old one? Jason LaPointe describes a platform first initiative: build the new compliant home, then migrate customers into it. Trying to modernize inside a live production environment would have been disruptive, so the team built alongside rather than on top, which freed them to re-architect and retool without breaking customers.
Michael Parisi frames the engagement as embedding, not staff augmentation. Steel Patriot Partners plugged directly into the product team through daily standups and leadership calls, delivered infrastructure as code and deployment pipelines, and kept the work with US citizens, a requirement once controlled unclassified information is in play.
What makes an audit go smoothly? Preparation that extends to how questions get answered. Jason LaPointe compares the audit to a deposition, where an unsolicited comment hands an assessor somewhere new to go. Michael Parisi, who spent years in the assessor's seat and ran the practice for a large C3PAO, explains why knowing the auditors and presenting information cleanly protects the outcome.
The business math is unforgiving. Miss the audit window and millions in direct contracts can be exposed, while auditors book out six to eight months. Exostar cleared it with a clean, no POA&M result, and the business is now seeing tailwinds through initiatives like Golden Dome.
The lesson Jason LaPointe offers other technology and security leaders is about temperament. Every part of the organization gets touched, from R&D to HR to finance, and the willingness to change quickly becomes the governor on success. Having a clear voice at the table for what good looks like, as Steel Patriot Partners provided, is what accelerates the decisions.
This is a Brand Feature. A Brand Feature is a ~30 minute in-depth conversation designed to go deep on a company's story, solutions, and customer success. Learn more: https://www.studioc60.com/creation#feature
GUESTS
Jason LaPointe, Chief Technology Officer, Exostar
Website: https://www.exostar.com/
LinkedIn: https://www.linkedin.com/in/jasonlapointe
Michael Parisi, Chief Growth Officer, Steel Patriot Partners
Website: https://www.steelpatriotpartners.com/
LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/
RESOURCES
Learn more about Exostar: https://www.exostar.com/
Aerospace and Defense solutions from Exostar: https://www.exostar.com/industries/aerospace-defense/
Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/
Find Your Path with Steel Patriot Partners: https://steelpatriotpartners.com/find-your-path/
Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
KEYWORDS
Jason LaPointe, Michael Parisi, Exostar, Steel Patriot Partners, Sean Martin, brand story, brand marketing, marketing podcast, brand feature, FedRAMP, FedRAMP-moderate, CMMC, CMMC 2.0, defense industrial base, DIB, controlled unclassified information, CUI, compliance inheritance, C3PAO, FedRAMP audit, platform modernization, GCC High, Department of War, defense supply chain, cybersecurity compliance
FedRAMP First: Modernizing the Defense Supply Chain Without Cutting Corners | A Brand Feature Conversation with Michael Parisi of Steel Patriot Partners and Jason LaPointe of Exostar
[00:00:20] Sean Martin: And here we are. You are about to hear a great story about taking a program from start to finish and achieving results that matter for the business, not just for the sake of getting a checkbox of compliance. I'm thrilled to have this conversation today with Jason LaPointe, CTO of Exostar, and Michael Parisi, responsible for all kinds of good things at Steel Patriot Partners, including getting programs to be successful for their clients. So gentlemen, thank you both for joining me today.
[00:01:00] Michael Parisi: Thanks for having us.
[00:01:00] Jason LaPointe: Thanks for having me.
[00:01:02] Sean Martin: So let's do this to kind of level set. Maybe tell us a bit about each of your roles, and then I'll get an overview from you, Jason. Then we'll get into all the nitty gritty stuff. First from you, Jason, what is it like to be the CTO at Exostar?
[00:01:20] Jason LaPointe: Well, it's challenging. We are FedRAMP-moderate as a result of working with Steel Patriot, and working in a compliance first atmosphere creates unique challenges for engineering companies and software companies. It requires focus and attention to emerging standards, like the CISA binding operational directive that came out recently. Staying ahead of the game requires a lot of attention and detail, and industry experts like Steel Patriot certainly make it a lot easier for me.
[00:02:13] Michael Parisi: I'm the Chief Growth Officer here at Steel Patriot Partners. As we like to say, it's a business owners first mentality, security and engineering people second, and compliance people third. To Jason's point, we enjoy those puzzles and the challenges relative to the ultimate outcome of compliance, but doing the right thing up front to ensure that we're engineering and structuring a viable cybersecurity program that not only helps achieve compliance, but results in an overall business advantage for organizations.
[00:02:48] Sean Martin: I think it's important to keep the eye on that ball, on what the outcome should be, which is difficult to do when the checkboxes are chasing after you, and those contracts are sitting there waiting for signature and you don't have everything in place yet. How do you get there quickly? Cutting corners is not the answer for long term sustainability of the business, and we'll probably get into some of that today. You don't have to cut corners if you think about this and you have experience doing it, with several customers. So Jason, can you give us an overview of what Exostar delivers as a product and service to your clients, and why compliance is so important for you and for them?
[00:03:41] Jason LaPointe: Sure. So Exostar is part of the defense industrial base, at least in terms of how the industry views us. We were born out of a consortium of owners in Boeing, Lockheed Martin, and others that really are the base of the defense industry. Exostar has deep roots in aerospace and defense, and we help companies, especially right now smaller contractors, that are doing business within the defense industrial base on contracts from the Department of War. The standards on those small suppliers are increasing in terms of the things they have to do to meet compliance so that they can participate in those contracts. Namely, CMMC 2, the cybersecurity maturity model, is driving these suppliers to seek certification so that they can continue to do business with the primes as part of contracts with the Department of War.
That's a tall hill to climb. When you think about the strategy of how one might go about that, you really can either, A, move all of your business operations into a secure FedRAMP boundary, which is massive. Think all your email, all your servers, all your machines. Or, in the case of Exostar, you can use our products, and because we are FedRAMP-moderate, many of the controls that you have to meet, the 110 controls for CMMC 2, you can inherit from Exostar. So the scope of the audit shrinks considerably. What Exostar does, the value we bring to the table, is we allow these smaller suppliers to participate in these contracts with the primes and the Department of War, and we provide an environment where they can interact with CUI, controlled unclassified information. And again, without having to lift and shift all of their operating environment, which in the MSP model is just massively expensive. They're able to inherit that position from Exostar.
[00:06:12] Sean Martin: That's a great overview of the groundwork. Clearly you're doing a lot of the heavy lifting that your customers then inherit the value from. What does your team look like to actually pull this together and run your operations on a regular basis?
[00:06:36] Jason LaPointe: Well, we have our office of the CISO, about six folks there, and the compliance team sits under our office of the CISO. They certainly work with our customers. They're on the front line of intercepting any of our AppSec scans and things of that nature, and working with architecture. But really, to run the program, it requires a village, and it requires operations discipline that spans beyond one part of the organization, in terms of how we release software, who can touch environments, and the access control for things like our infrastructure as code repositories. Every part of the organization has to adjust their operating posture so that we know we can safely walk into and out of audits.
[00:07:36] Sean Martin: I'm sure you're hearing a lot of similarities to other organizations you've worked with, Michael, and you're probably also picturing, well, that looks the same, but I've seen some weird stuff on the side from other types of organizations we've encountered as well.
[00:07:55] Michael Parisi: What's interesting about the relationship with Exostar is, as Jason already alluded to, they are critical to the DIB. The function that they play, the relationship with the primes, and the support that they provide. So when we work with Jason and his team and we look at the business outcomes that Exostar is looking to achieve, we're not just looking at Exostar as an organization. We're also understanding their clients and their customers, and what level of comfort and confidence they need from a cybersecurity, compliance, and certification perspective. What I would tell you, to your question, is that a lot of organizations don't look at it that way. They're looking at it as...
[00:08:43] Sean Martin: They don't keep it...
[00:08:44] Michael Parisi: ...as this one contractual term. What do I need to do in order to get through this, as small and as cheaply as possible? And maybe they're not thinking about what their customers and their clients and the suppliers really need. That varies depending upon the nature of the relationship. To Jason's point, when we're talking about CMMC, and the Department of War, and flow downs, and subs, you could have a ten person company that's been operating for a hundred and ten years that makes one bolt that goes into a Raptor, and they're now subject to this. It's a tremendous uphill climb, and you can have a massive manufacturer too. Exostar works with all of them. So in helping them design and operate this program, the business outcome that they need to be able to serve everyone in their community is really important. A lot of organizations aren't necessarily thinking about it that way. Some are, but some aren't. It's a big educational effort to help them understand the impact to their own business, but more importantly, what we're talking about is the DIB and the entire supply chain from a national security perspective.
[00:10:03] Sean Martin: There's Exostar's own supply chain, your customers and their customers, and your own business. You have to be FedRAMP, and then what you deliver has to be inheritable. This isn't your first rodeo, Jason. You've done this many times. So what were the challenges you were expecting to face, and how would you describe them to folks so they can understand them? And why was it so important to say, I don't want to mess with these things, I want to bring somebody in who can help me with them?
[00:10:40] Jason LaPointe: Well, the requirements for FedRAMP, in terms of what exactly you have to do, there's not a book that I can open and go to page one and follow the manual and I'm good. It's highly nuanced. There are certainly templates that you can use that will get you a long way, at least in terms of laying something down. But then, thinking about how your software operates, defining your boundary diagram and your architecture, really getting into the flows and realizing things that need to be FIPS compliant, for example, and implementing that. Going through all of that is a pain, and it's a long process if the approach is trial and error. What you really want to do is walk into that audit with a high degree of confidence that there's going to be a good result. So it's extremely helpful to have someone that has walked that walk, because instead of wondering and debating what the right approach is, you're able to move with speed. I've certainly been there and done that with a different company, and learned a lot of lessons, and it took a long time. What I really learned is that if you can take every step with confidence, you'll move a lot faster to the goal. That's really what Steel Patriot was able to do for us. It's like, here's the configuration that works for your app config. We're going to write the IaC code, we're going to move it into the boundary, and you're absolutely going to get, which we did, a very clean, no POA&M bill of health at the end. It's that certainty that helped us move extremely fast.
[00:12:37] Sean Martin: There were business opportunities, and there were some regulatory milestones heading your way that you had to meet as well. Doing it yourself could have taken X amount of time. When you first engaged the Steel Patriot team, they had some initial analysis, and I think your CEO said, can we trim that off a bit and bring it in a little faster, so we know we can hit these business targets we're trying to achieve? Talk to me a little bit about that, because a lot of people listening to that probably go back to the first thing I said, well, that means cutting corners. But that's not what I heard when I talked to you before.
[00:13:25] Jason LaPointe: No, no. What was compelling us originally, the Department of War had an effective date, I believe it was November 7th of last year, where these suppliers, the bolt for the Raptor supplier, can no longer self-attest. It's not good enough that you say you do it and put up your hand. Now you have to actually go through an audit. So we were very much aware of that looming November 7th date. Originally I think we were projected to wind up sometime in January, and yes, we worked together with Steel Patriot to pull that in almost a full three months. So yes, it loomed large in our world, the ability to say that we were ready, we were FedRAMP-moderate and could stand up to an audit, so that we could support our customers in their audit ultimately.
[00:14:29] Sean Martin: From all those vendors that have to participate and are now trying to figure out, well, what do we do? They had the same question as Jason, that we have this requirement.
[00:14:42] Michael Parisi: They did, but I think there was more denial. What's different, obviously, is the maturity of Exostar being in this space for so long, and Jason personally. They knew this one wasn't moving. CMMC is something that's been discussed for a long period of time, but to Jason's point, all these self-attestations and scores that were coming in were either overly inflated, or you had a number of individuals doing those self-attestations and assessments that really didn't dig deep enough to understand the maturity of the program. So lots of denial. You kind of had these two sides of the equation. You had some that said, well, we're going to sit and wait and see if this actually becomes real. Then you had those that were out in front of it, like Exostar, saying, we know it's real. And by the way, even if it slips a month here or a week here, it's the right thing to do for our customers, for our supply chain, and it helps to address the risk that's been exposed. If you look at this through the lens of a C3PAO and from an assessor perspective, it's important to have that experience of folks that have been through it. Jason's been through it himself. Exostar's been through it. I ran this practice for the largest C3PAO for two years, so I've kind of seen every different flavor that's out there. What you continue to hear from the street now versus six months ago is, wow, this is real. And there are a lot of organizations that are behind who can benefit from leveraging things like Exostar's solutions, because of the way they position themselves to make other suppliers successful within the marketplace.
[00:16:38] Sean Martin: So holding that business objective to heart and having a good plan, that's beautiful. Executing is another story. One could easily hand over the blueprint and say, here's the blueprint, have fun, Jason. Or you could have them step in and actually get their hands dirty, which is what Steel Patriot did. So tell me a bit about that engagement. I know the team was in standup meetings and getting hands on with code to define the scope and actually build things. Tell me what that looked like, and how it helped you manage your team and manage the status and communications upward as well.
[00:17:22] Jason LaPointe: Staff augmentation doesn't do it anywhere near the justice it deserves. It's embedding. Steel Patriot embedded themselves into the organization by way of, yes, daily standups and tracking. At the leadership level we had, I believe it was three times a week, early morning standup calls across anyone who was involved in the program. So certainly supporting at that level, and then day to day execution with the team. It wasn't through leadership, it was directly plugged into the team, with the product team, working alongside them to deliver what I would describe as DevOps work, infrastructure as code, and deployment pipelines, to make sure that we could release safely and securely into the FedRAMP environment. So it was very much a close working relationship, not unlike the one I have with employees.
[00:18:24] Sean Martin: What I want to know is your view of that in relation to other programs you've been involved with. You probably come in and say, let me help you, because their teams are floundering. They might know how to build their product, but don't know how to scope in the rest of the organization operationally to meet the requirements. So maybe tell us a little bit about the bigger picture that you see.
[00:18:52] Michael Parisi: From a success perspective, as Jason mentioned, the way we look at this is we want to be part of the team. That business owner's first mentality. We need to be invested in the success of our clients and understand what that success looks like, not only for him as an individual, and his team as individuals, but for the company overall. Organizations that may want to try and keep us at arm's length are not necessarily as successful. So those that let us in to become part of the team, that's really important relative to that success. Also, a nuance but very important within this space, is the fact that we're all US citizens. That's a really important factor, because there are many organizations that may have offshore support from an IT or security perspective, which makes sense relative to business decisions. But when you start coming in contact with very sensitive information, and when you start going through these high levels of compliance, that is in fact not allowed. So part of what we can do is augment some of those dependencies that may exist on resources that don't meet those qualification standards, and embed ourselves as part of that team to help them achieve compliance overall.
[00:20:26] Sean Martin: And Jason, so the team is helping you scope and build and deliver and bring everything to market, and then comes the audit. When I was speaking to you before, this is a very important piece of the puzzle. Again, if you guess at what you're supposed to do, you might open a can of worms that you don't want to open. So talk to me a bit about that whole experience, and why it's important to keep the embedded aspect and the knowledge driven aspect of this in place.
[00:21:09] Jason LaPointe: I think back to the audit, and I remember having a call with Amy Ford from Steel Patriot before the audit with the team, and it was something like, I'll take the lead. If there are questions asked, I'll answer them. If I need you, I'll ask for you. Don't volunteer anything. The best way I can compare it, that audit is like a deposition. Anything that comes out of your mouth that was unsolicited, that gives the auditor somewhere to go, would be unfortunate. So it's serious business, and how you represent your business and your processes, and how you answer those auditors' questions, can be the difference. The very same business, the very same set of questions answered the wrong way, can turn something into a nightmare. So certainly, trusted advisor, counsel, close partner, you name it, it was essential for a smooth audit experience. For me personally, most of those audits I made appearances. I was told when I needed to be there, and what my role was, and I attended diligently when I was told to attend. So it felt very controlled. It's a very sensitive moment for a company like ours, when it all comes together and it can all be unraveled with the wrong choice of words. So I feel like Steel Patriot was a huge asset in getting us ready and getting us through that day, or those days.
[00:22:58] Sean Martin: Anything to add there, Michael?
[00:23:00] Michael Parisi: Yeah, I was going to say, having been in the auditor's seat for over twenty years, I completely agree with Jason. What's interesting is that a lot of it is dependent upon the specific individuals that are executing those audits. So knowing who those individuals are, knowing how they view the world and what their level of interpretation is. It's kind of like being an interpreter. Understanding their language and presenting the information accurately and factually, but in a way that helps them reach their conclusions as quickly as possible without having to grasp for or ask for additional information, is really important. Candidly, in our experience, the auditors appreciate that. They don't want to sit there and try to pull additional information out. And if somebody does say something that takes you down a rabbit hole, they don't want to have to go down that rabbit hole, but now that it was said, they have to, and that's additional time on everyone's front. The other thing Jason indicated a little while ago is that the opportunity cost here is huge. If you miss that window to successfully get through your audit, not only are there millions and millions of dollars of direct contracts that could be at risk, now there are potential customers and prospects, like in the case of Exostar, that could be at risk. You're delaying your go to market motion, your solutions, and how you can help the community. And there's the scheduling element of the auditors themselves. Getting on somebody's calendar for a CMMC audit or a FedRAMP audit could take six to eight months, in terms of how far out they're booked. So that window is absolutely critical from an opportunity cost perspective. Understanding that, and making sure you're all hands on deck and super focused on getting through it as quickly as possible, is what's most important from a business perspective.
[00:25:07] Sean Martin: And talk to me, Jason, this is for you too, about the ability to present what's inheritable and the ease with which it's inherited by your customers. Because to Mike's point, they're not free from the audit. They just get to leverage what you've done, and hopefully you've done it in a way that's easy for them to demonstrate to their auditor. This is why this is good, and here's how we're using it. So can you share a little bit about that, and how working with Steel Patriot helped that become a little easier for your customers, and therefore made them happier?
[00:25:50] Jason LaPointe: Well, it's a black and white thing here. Either we do or don't have FedRAMP-moderate equivalent. That's it. And if the answer is yes, then we can provide our evidence package, and they can inherit our controls. I forget the exact count, in some situations it varies, but I think 85 plus controls. So it's just that simple. If we don't have the FedRAMP badge, then it doesn't matter what we say and what audit evidence we're ready and prepared to bring forward. It doesn't count. So for us, there is no middle ground, and certainly for our customers, there's no middle ground. They won't make it through an audit with a partner that doesn't have FedRAMP. At least they won't be able to inherit the controls. That means every control goes into the scope of the audit, and it grows it significantly.
[00:27:00] Michael Parisi: What Jason's mentioning is this concept of adoption. Because the certifications and cybersecurity standards we're talking about, whether it's FedRAMP being federal law, or CMMC as part of the DIB, it is pretty black and white. It gives you this ability to have broad adoption and acceptance within the community by achieving that bar and that standard. Anything that isn't within those laws or regulations, or, for example, the recently updated FAR, the acquisition rules that have come out, if it's not in there, there's really no negotiation, to Jason's point. So making sure that you align to what those requirements and standards are not only ensures the success of the organization, but it ensures the quick success and adoption and acceptance from an organizational perspective.
[00:28:13] Sean Martin: Which, we can't forget, is the big supply chain picture. If things start to slow down or have hiccups, government slows down even slower.
[00:28:27] Jason LaPointe: National security's at risk.
[00:28:28] Sean Martin: Exactly. We don't want that. So that's the outcome, better national security. Bring it back a notch or two, what were some of the outcomes that you experienced, operationally or otherwise, Jason?
[00:28:50] Jason LaPointe: Well, I'll start with one, operationally. A program getting ready for a FedRAMP audit, and thinking about FedRAMP, is a commitment to a strong AppSec, OpSec, and vulnerability management practice. So number one, you go from the minor leagues to the big leagues real fast. From an outcome perspective, it makes your operation stronger. Whether you like it or not, you'll get there. From the business, again, this wasn't a nice to have, it was a must have. And frankly, Exostar's business is growing very fast. We are certainly the gold standard for identity access management, security, and collaboration within the defense industrial base. Looking at initiatives like Golden Dome and our participation in that project, it's created a tremendous opportunity for us, and the business is experiencing a lot of tailwinds.
[00:30:04] Sean Martin: Which is great, congratulations. That means you stop and pay attention to what's coming, to what's next for you from an innovation and delivery perspective. What's important to you for your own programs and development processes, what's next for you, and does Steel Patriot play into some of those plans?
[00:30:28] Jason LaPointe: Our products are all ultimately destined to operate in the FedRAMP ecosystem. That is the basis of our compliance posture. The new products we're bringing to market, we start with FedRAMP. Over the last several months, we've added to our boundary there, working with Steel Patriot. So the answer is, we continue. We continue to innovate in the supply chain, we continue to innovate in collaboration and in identity access management, and we do it FedRAMP first. Certainly having a valued partner like Steel Patriot sitting at the table with us and in the trenches working with us makes that a lot easier than it would be otherwise.
[00:31:23] Michael Parisi: Sean, executive sponsors like Jason, who understand that and are willing to make the investment in embedding it as part of the culture of the organization, make it a lot easier. Because as Jason mentioned, now the organization is already held to a very high standard from a cybersecurity and compliance perspective. So it becomes easier to add into that boundary, and to what you've already established foundationally, as additional products come to market. Scalability becomes a lot easier. But if you don't have that tone at the top to say, this is the bar that we're held to, this is the bar that we will maintain, and these are the reasons why, it becomes harder to scale and add additional products that meet that same data classification and cybersecurity standard.
[00:32:16] Sean Martin: I love it. You guys are both naturals. You answered a question before I even asked it, giving some tips. I'm going to give you the final word, Jason. Was there something that came out of the program you didn't expect, that you think your fellow CTOs or security leaders would value? Putting you on the spot here.
[00:32:43] Jason LaPointe: It's tough. I think, again, perhaps the message is where we started, which is that there's a lot of risk inherent in the program, in terms of technical risk. Obviously, your product is going to change to operate in a highly compliant environment. You've got internal processes that need to change. The way you were keeping tickets before, it won't work. Every part of the system, of your organization, not just the R&D and DevOps product, but HR and finance, they're all touched. So the ability and the willingness to move fast and change anything fast will ultimately be the governor on how quickly, or if, you can be successful. Because going down that road kicking and screaming, and trying to rationalize why a particular system isn't part of the boundary, or something like that, is a losing battle. And every moment, as we talked about, the timelines are tight. You miss that window, and now you're back to waiting in line again. So the advice would be, don't fight it. Certainly having someone like Steel Patriot at the table, who is a clear voice of what works well, helps accelerate many of those decisions. Here's what good looks like, we can tell you that, and you make the decision within those boundaries. Yeah, that's creative, and that's a great explanation, but you don't want to bring that to an audit. So again, the ability to change, and to rapidly change, is your friend.
[00:34:54] Sean Martin: I could talk for hours about this story. We did spend quite a bit of time together before. Jason, I'm going to force you to say one more thing, because there was a very critical decision that I think was instrumental in this program's success, which is not trying to build on top of what was there, but building alongside it.
[00:35:12] Jason LaPointe: Sure.
[00:35:12] Sean Martin: A quick word about that? Because I think it's super important.
[00:35:15] Jason LaPointe: Yeah, and I'm a big believer in a platform first initiative, which is that you build the new home. We had software running in gov, we were already in a gov subscription in GCC High. But we actually had to change the software to meet the FedRAMP compliant communication standards and configuration, and we wanted to modernize along the way. Trying to do that in a production environment would have been extremely disruptive to our customers and to the business. So instead we built that new home, the new platform, if you will, the FedRAMP platform, through a platform first initiative, and then we migrated customers to it. That proved to be, and it's a strategy that I've certainly done before, but for us it allows us to move rapidly without the constraint of worrying about breaking customers. You can take massive steps in terms of re-architecting, redesigning, and retooling when you don't have to worry about bringing your customers with you. So yeah, that was a big advantage for us.
[00:36:37] Jason LaPointe: Yes.
[00:36:39] Sean Martin: And not disrupt them too much. I won't force you to say any more. I think the story is super cool, and I'm an operations nerd anyway, so all of this stuff excites me. I'm glad to hear it from you, Jason. And Michael, congratulations on another successful program with Steel Patriot. I know there are many more out there. So Jason and Michael, I'm sure you're both open to chatting with folks and sharing tips and tidbits as they have their own questions on how to take their own programs to that next level, FedRAMP, CMMC, or otherwise. Thank you both, and congratulations.
[00:37:27] Michael Parisi: Thank you.
[00:37:28] Jason LaPointe: Thanks, Sean. I appreciate your time.