FedRAMP's Consolidated Rules for 2026 are live, the dates are fixed, and the first decision they force on a cloud service provider is not a technical one. Jason Ford and Michael Parisi walk through what actually changes, what the transition costs beyond the budget line, and why the right answer is sometimes to walk away from it entirely.
FedRAMP has changed before. What makes the Consolidated Rules for 2026 different is that the dates are on the calendar and the fence sitters have run out of runway. Jason Ford, Co-Founder and CEO of Steel Patriot Partners, has been inside the program since Rev 3 in 2013. Michael Parisi, Chief Growth Officer, comes at it from the business side. Together they map what changes and, more usefully, what it means for the decision in front of a provider right now.
So what actually changes? The program consolidates into two paths, 20X and Rev 5. FedRAMP Ready moves to legacy status. Class A, B, and C pipelines open across a thirty to sixty day window, mandatory adoption arrives January 1, and new Rev 5 certifications close on June 11, 2027. Authorized becomes certified. Jason Ford also points out where the rules live: fedramp.gov, hosted in GitHub, which means they move with a commit. Reading them once is not tracking them.
Why did FedRAMP need to change at all? Michael Parisi frames it as a supply problem. Agencies and primes have been working from a limited and aging set of technologies while better tools sat outside a process that was slow, rudimentary, and expensive. The action was warranted. His follow-up question gets less airtime: if the process moved faster, did responsibility move with it, and does the stakeholder now holding that due diligence know it yet?
The engineering shift is real and it is the part most teams see coming. Jason Ford describes RMF thinking giving way to continuous DevSecOps, proving compliance in real time rather than at a point in time. Vulnerability remediation is where the compression bites. CISA's updated guidance drops severity score as the driver in favor of stepped prioritization, and windows that used to run 30, 60, and 90 days now land closer to three to twenty-one.
What does this cost a business past the budget line? Time and capacity. 20X is faster than a Rev 5 process that once ran eighteen months, but faster is not instant. Retraining a couple hundred users inside a thousand-person organization is not a small endeavor, and if the transition eats half of the organization's capacity for a year, that is half as much capacity aimed at the business paying for it. Jason Ford is not arguing against the move. He is arguing that disruption belongs inside the decision.
Then there is the internal work almost nobody has started. Mapping an existing Rev 5 ATO scope into a new certification level is not clear-cut, and past the mapping, marketing and sales both need re-education. Michael Parisi describes building a translation layer for customers: here is what we provided before, here is what it is now, and this change came from the program rather than from any reduction in assurance.
Roughly half the time, Steel Patriot Partners tells organizations not to pursue certification at all. Michael Parisi treats that as one of the more valuable things the firm does. The opposite failure shows up just as often, with companies preparing to spend heavily on 20X because it sounds quicker and cheaper, when the agency or prime they are chasing expects a certification level. A lower bar only helps if the buyer accepts it.
Where should a business start? With the business conversation. Michael Parisi notes the answer does not have to be yes or no today; it can be a maybe with defined trigger points. Jason Ford closes on posture: come with an open mind, and do not hand a multi-year commitment to a language model whose guardrails and training are not built for that call. Or, shorter: don't wait, and don't go it alone. Steel Patriot Partners built a three-question starting point for that first conversation at https://www.steelpatriotpartners.com/find-your-path.
This is a Brand Story. A Brand Story is a ~35-40 minute in-depth conversation designed to tell the complete story of the guest, their company, and their vision. Learn more: https://www.studioc60.com/creation#full
GUESTS
Jason Ford, Co-Founder and Chief Executive Officer, Steel Patriot Partners
On LinkedIn: https://www.linkedin.com/in/jason-ford-5ab206/
Michael Parisi, Chief Growth Officer, Steel Patriot Partners
On LinkedIn: https://www.linkedin.com/in/michael-parisi-4009b2261/
RESOURCES
Learn more about Steel Patriot Partners: https://www.steelpatriotpartners.com/
FedRAMP's Consolidated Rules for 2026: What It Means for Cloud Providers: https://resources.steelpatriotpartners.com/fedramps-consolidated-rules-for-2026
Find Your Path, a three-question starting point for ISO, CMMC, and FedRAMP decisions: https://www.steelpatriotpartners.com/find-your-path
Complimentary ROI Workshop: https://www.steelpatriotpartners.com/roi-workshop
Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
KEYWORDS
jason ford, michael parisi, steel patriot partners, sean martin, brand story, brand marketing, marketing podcast, fedramp, fedramp consolidated rules for 2026, fedramp 20x, rev 5, fedramp certification classes, cloud service provider compliance, federal compliance, cisa vulnerability remediation, continuous monitoring, devsecops, ato, 3pao, govramp, cmmc, grc, federal marketplace, compliance roi
The Business Decision Hiding Inside FedRAMP's Consolidated Rules for 2026 | A Brand Story Conversation with Jason Ford and Michael Parisi of Steel Patriot Partners | Hosted by Sean Martin
[00:00:18] Sean Martin: Hello, everybody. Another day, another set of acronyms that, uh, that we need to follow, and new frameworks and, uh, government programs we need to adjust to. And no better than these two guys on with me today to talk about the changes with, uh, with FedRAMP coming from, uh, the US government, of course. Jason Ford, Michael Parisi from Steel Patriot Partners.
How are you guys?
[00:00:44] Michael Parisi: And how are you?
[00:00:46] Sean Martin: Doing great. Doing great. So this is... I follow this stuff, uh, because I'm a nerd. But, uh, FedRAMP has been changing, specifically the consolidated rules. And, uh, Jason, you, you put a blog together that outlines what's going on, uh, really, really well. So I'm gonna encourage folks to, to read that.
Reading is one thing. Hearing it straight from the horse's mouth, what you're hearing, what you're seeing, how it impacts your customers, how you're helping them move through that, [00:01:18] that change and, uh, presumably the challenges that come with it is, uh, is a different thing. And so I wanna talk to both of you about, uh, what you're seeing and hearing.
Uh, before we get into the topic itself, uh, maybe a quick word from each of you, your role at Steel Patriot Partners, and, uh, y- your vision for, uh, for why this is an important piece
[00:01:42] Michael Parisi: Yeah, so I can go first. I'm chief growth officer here at Steel Patriot Partners, um, responsible for everything on the sales side, strategic and, and channel partner programs as well. Um, why is this important? You know, I go back to the, I think, one of the famous lines of, "Just as I thought I was out, they pull me back in," right?
Um, we've seen this before, not just relative to FedRAMP specifically, but across a number of other frameworks and, and standards and, and expectations. [00:02:18] and I think it will continue to happen, right, from an overall industry perspective. But why it's important now is because I think this is for two reasons.
One, this is such a, quote-unquote, "significant change," no pun intended, 'cause that is actually a FedRAMP term. and, and, you know, I think we'll, we'll get into that from, from a terminology perspective. So not only is it a significant change, but also it's here. And I think over the last several months and, and, and years, you've had a lot of, um, fence sitters, right?
And they've been hearing about all these changes and all these proposed pilots, um, and many of those have now been adopted. so the reality is here, and it's time to, you know, stop questioning whether it's gonna become reality, because now it is. And now how do we deal with it? Um, very similar to I think what we [00:03:18] saw around CMMC for a number of years. And I mean, that was something that initially was gonna happen within two years, that to four, went to five, went to six. But guess what? Now it's here. And, in a similar vein, changes to the overall Fed-FedRAMP program is, is something that now needs to be addressed from a business perspective. think we'll, we'll get into that, right?
What are, what are some of the business, um, elements that, that need to occur. But Jason, I'll, I'll hand it to you
[00:03:51] Jason Ford: Yeah. So Jason Ford, um, CEO, co-founder, Steel Patriot Partners. Um, background, been doing federal compliance since late nineties, uh, with FISMA and SAS 70 back in the day for you old folks in the room, uh, that are watching this, um, and now SOC 2 and many obviously. I was early on to go through the FedRAMP program back in 2013. So, um, second platform as a service to get [00:04:18] authorized, uh, back in those days. So been dealing with FedRAMP since Rev 3, right? And, and all the trials and tribulations as a cloud service provider of trying to realize that, hey, you're the second platform as a service, and really the rules aren't really defined, uh, early on and helping define some of those, those things. That time, Matt Goodrich was, uh, obviously the, the PMO director. Um, you know, working heavily with them, understanding that as a cloud service provider, also working with the agency directly and having that experience to kinda be the, go-between or the mediator to try to deliver this, this new technology back then was, was crazy, right?
So, um, FedRAMP and the, and the program itself, you know, living through that for the last, you know, call it twelve years for me, um, has been, you know, interesting because, you know, while early adoption of Rev 3 was, was really difficult 'cause there wasn't a whole lot of example. [00:05:18] know, we had the same thing happen when we went to Rev 4 with continuous monitoring, right?
And those changes that went in with significant changes, and we had all the things that, that went associated with that. This is no different than all of those things, right? We've seen this before as an industry. We've, we've seen how this, this plays out as a pilot and then how it pushes out over time.
This one's moving faster than the pilot was for continuous monitoring. the end of the day, it's still the same process. It's still the same thing. It still needs to be written in to how these things get delivered, and then 3PA or, yeah, 3PAOs have to be told how to audit it and things of that nature.
So we've seen this happen before, right? This isn't anything new. Um, and as a cloud service provider and now doing this as an advisory service and an implementation with engineering services wrapped around it, you know, at the end of the day, it's the same, stuff. It's old hat, right? Um, it's just a different colored hat, I guess is the best way of putting it
[00:06:15] Sean Martin: Yeah. So, so [00:06:18] seeing it before specifically, um, you've seen changes in these types of programs that then impact organizations. They have to follow the change. Um, let's talk about-- a bit about what changed here so we have a sense of the scope of, of the impact. Because I think, and, and maybe if you have some insight why, why things have changed.
Um, 'cause I think there's significant adoption, right? Um, certainly some consistency in how we look at this and how we, uh, bring our programs forth and, and deliver against it. Um, so what, what... Was something failing? Uh, did the environment change in a way? I don't know. Was AI a driver? What, what were some of the reasons that, that the-- these changes came to bear?
[00:07:08] Michael Parisi: I mean, I, I can, I can start. If we think about it from, I guess if we frame what's the quote-unquote b-business issue, right? Then all of these changes [00:07:18] are, are, are driven to hopefully solve for. Um, not enough solutions, suppliers, um, in the federal marketplace that agencies, uh, that primes could leverage, right?
Very, very limited in terms of what those technologies are. Candidly, a lot of them, um, a little, as Jason says, old and crusty and, and, and archaic. So with all of the tremendous, you know, research and development that's happened, AI certainly being a factor of that, there's a number of new solutions that candidly, those operating within the federal space could benefit from leveraging. Uh, the challenge is the way the quote-unquote old process worked. it took a long time. It was very rudimentary and expensive in order for those new products to get to market. [00:08:18] So agencies and primes, and really anyone within the federal space could start leveraging those and, and, and using those. So the ten-thousand-foot view, I, I think actions needed to be taken, and it's, it's a good thing that those actions have been taken, um, in order to expand the number of tools and solutions that are available, and that drives further efficiency, et, et cetera. Now the question becomes the actions that have been proposed and have been taken, you know, it may address one challenge from a business perspective, but has it created other challenges relative to trust and transparency from a cybersecurity standpoint? And I think the most important thing is, and maybe it's almost like an indirect impact of the actions that have been taken, um, has the responsibility shifted And [00:09:18] has the responsibility shifted relative to due diligence or understanding these tools and solutions?
Has it shifted to the right stakeholder? Does that stakeholder realize that the responsibility has shifted? I think we would argue right now a lot of them do not, right? So with the speed in which the changes in the program has, has been moving, the stakeholders and their understanding of those changes and what it means from a business impact perspective is lagging behind. we kind of have this gap of some believe that the program changes have been put in place to address an, an issue, not disagreeing with that, the, the lagging of the understanding of what that means and how it addresses the issue what we're trying to deal with from, from a business perspective.
[00:10:16] Sean Martin: And what, what are you [00:10:18] hearing, yeah, Jason, as you, as you're talking to folks?
[00:10:20] Jason Ford: Yeah, it's this industry in, in general, right, has moved at glacial speed for The dawn of time, right? Nothing moves fast, right? And a lot of agencies are still in the waterfall mindset, right? Not very agile, not very much, um... And, and the FedRAMP RMF process in general um, and I'll say in the Rev 3 and the, the Rev 4 versions, certainly so, we're still in that mindset, still we're very much, um, we don't want things to be transient, right?
And state, right? Inventory just in general, right? How do you inventory a system where a container only exists for thirty seconds before it gets killed, right? And what did that container do? And transparency and visibility into that thing, right? So DevOps in general, right? DevOps didn't exist 12 years ago, right?
We didn't have... We did have GitLab, and we had things like [00:11:18] GitHub in the early stages. We did have Git, from a re- repository perspective, uh, for code, but we didn't really have pipelines per se. We used things like, you know, um, we'd find tools to do that for us, whether that was, you know, something that we're deploying with, you know, with Puppet or, or Chef or something like that to deploy the codes.
It was very, um, it was almost like someone just typing the commands, but you were just running a shell script, right, to do those commands for you automated-wise. Fast-forward all that to now, right? All that stuff exists today. you know, vibe code everything for the most part, right? A lot of people are just throwing scripts together they don't really understand, but it, it accomplishes the outcome that they're looking for. And that isn't what compliance has been, been designed for, right? Just in general, you know, regulatory compliance in general, right? So I think that's w- in past, when I reference those, those past times, the speed in which that those, those [00:12:18] things happened, the change that happened were dictated about where we were as an industry and where we were as, as dealing with change. We're not in that. We don't live in that anymore, right? We're living in, in people vibe coding something in three days and having a, a, a concept to working con... you know, working application MVP in a very short period of time, or you're using some kind of tool like Mythos to, you know, go out and see what's going on inside of, um, inside of environments, right, for vulnerabilities and, and try to do pen testing with, with language models. of that stuff existed, right? So these things are trying to, you know, these changes in, in FedRAMP have to move faster deal with where we are today, right? Or where we are maybe six to 12 months ago, right? Um, not dealing with where we were five years ago or 10 years ago, right? So the speed in which our industry is, is seeing change is, is obviously just in general, right?
Industry as in white collar, you [00:13:18] know, industry, not as in cybersecurity, regulatory compliance, that kind of thing. I mean, those are subsets of that. But just as a holistic thing- You know, it has to respond to that, right? And how do we use things like DevSec, SecOps? How do we use Dev, uh, or, uh, DevOps? How do we, you know, build stuff in with engineering platforms to have something that's continuously done by a machine instead of by human, right?
The RMF was all about human. You know, human runs a scan, human processes scan, you know, results, throws them in a C- CSV file, may or may not get imported into Jira or some tool, you know, that is FedRAMP authorized or whatever it is, not authorized now, but certified going forward, which is another thing. You know, us old and crusty people who've been around for a long time, we yelled at people nonstop for the last decade saying, "Authorized, authorized, authorized, not
[00:14:07] Sean Martin: Yeah. There's no such thing as certification. Ah
[00:14:10] Jason Ford: it's certified. You know, so it's like, you know, for, for us old hatters, it's, that's hard, right? And we, [00:14:18] we don't wanna accept... Government systems in general hate change, right? They always have hated change, right? And they will continue to hate change, right? So you have haters and you have followers, and you have people that are, are now in this new camp that are coming into it fresh and new, that may be only in this space for less than five years. You know, they don't know what FISMA, FISMA really is, right? What did it look like? They don't have the history of that. It's sort of like using an abacus versus a calculator, right? Um, if you don't understand how to use, you know, slide rule as an engineer, you won't appreciate what that calculator does for you, right?
And I'm not saying everyone has to have that history at all, right? Um, developers been taking, taking advantage of, you know, the fact that, you know, SSH just exists or a API just exists for them to use. They don't really have to understand that all the networking and all the other technology that goes into just allowing them to have that, right?
Just to have that ability and all those [00:15:18] things below that. FedRAMP is no different, right? It is, having that history there is important, but also not required, right? So think that's a big, a big thing to just note
[00:15:31] Sean Martin: So I wanna, I wanna take that and so the, the, the timeline first off. So I think was it June 30, the rules were finalized. As of last week, we're into, uh, early adoption, and, uh, I think as of tomorrow, based on this recording, conversion opens. Um, so there's a timeline there, and then there are different classes.
So there's the ready conversion, then the classes A through D that lead us down a path to fun, funness, and goodness, right? So, so there's that, which I want some insight from, from both of you. What, what does that look like? What does it mean? But I also think, kinda to your point, Jason, that some programs have existed for a decade or more, right?
So they have a lot of [00:16:18] knowledge and legacy to deal with. And then there's new stuff coming online that doesn't have to necessarily worry about the old things, and perhaps they can move forward in a way that, that, uh, is more ef-efficient for their, for their own business. So I guess what I'm asking is two parts.
What, what's the timeline like and the general impact to organizations for the timeline? And maybe a slight variance view of legacy where you have, you have to keep things, old things up and running, right? And you have a lot of knowledge in your program, a lot of policies and controls and everything built a certain way.
How does that change? And if you're starting fresh, what, what does that look like? So I know a lot to unpack there, but, uh, I think there's gonna be... That's gonna cover most of the, most of the folks listening to this in terms of how to take that next step, right?
[00:17:11] Jason Ford: Yeah, and I, I think that that's, that is important to talk about, like where we're gonna go in 2026, right? [00:17:18] 'Cause The back half of this year is where all that change happens, right? Really, at the end of the day, that's gonna be the biggest, the biggest push. So as of this recording, you know, w-we've, we've seen, you know, FedRAMP Ready got created years ago, as a step in order to get people interested in, in, in FedRAMP, get, you know, new systems in as an effort to get that in, right?
We found that while the techno, you know, FedRAMP Ready has existed, it had technical controls and a 3PAO could write you a, um, a RAR, you know, a ready assessment report that could be used to show that you're ready to go, but you didn't really have to have a system security plan, all the policies and the RMF stuff, So if we look at what th-that is and what it was trying to accomplish, did it actually accomplish anything, right? I don't know the statistics of how many systems went from ready to authorized in that timeframe, you know, now gonna be certified going forward. But, um, I don't know that that conversion rate was high, [00:18:18] right?
And while some systems that were ready were-- that was significant enough or sufficient enough for, commercial entities to use your system, um, it doesn't mean that the, you know, obviously a government agency couldn't use you directly. You had to be authorized in that state, right, now going to be certified. So how, you know, that, that all gets rolled out at the end of this month, the end of July, right? So the FedRAMP Ready program goes to legacy, right? And those n-no more ready systems are going in. Uh, the, the goal is to have everybody pushed to 20X, So if we look at the, at FedRAMP as it exists, it's gonna be the 20X program, and it's gonna be Rev 5, uh, the Rev 5 program, right?
So those are gonna be the two. If you read the consolidated rules, pretty easy to find, fedramp.gov, click at the top, consolidated rules 2026, you'll see them. Um, it'll link you out so you can go find important dates. You can find all the details inside there. But more important, they update, right?
So this [00:19:18] video is obviously being recorded in video, in point in time, right? This is all being hosted inside of, um, inside of GitHub. So with anything with a GitHub, it's obviously a commit, you know, someone could change that at any time. So that's where you wanna go look for any kind of up, up-to-date information, right?
So you know, the, the pipelines for Class A, Class B, Class C kinda roll out over a period of thirty to sixty days, um, and then as of January 1st, really, it's mandatory adoption for all stakeholders. so really at the end of this year, right, is what you have to kinda target for. And, you know, really any new Rev 5 certifications that are going out, current timeline is June 11th of 2027. there won't be any more Rev 5 certifications. It'll all be 20X. So what does that mean to businesses, right? So this is a, a big shift from an RMF mindset To a continuous [00:20:18] DevSecOps, DevOps motion prove compliance in real time over time, right? So instead of it being a human doing all these things, now a machine has to do it, And if you don't have a mature process or a mature engineering team that can actually do that work, legacy systems that have been around for 10 years are gonna have a really hard time adopting those things because vulnerability remediation has been the bane of everyone's existence, right? CISA came out with new guidelines, uh, as of a couple weeks ago stating, you know, now, you know, severity score isn't a thing you should be doing, um, from a federal system perspective.
Now there's a, you know, a step process that you then prioritize the, the vulnerability to based upon different factors in which that, um, that flowchart tells you to do. instead of the, you know, fourteen, thirty, sixty, ninety, one-twenty day thing, we're moving three to twenty-one days, right? [00:21:18] that's making people's heads, heads explode, especially on systems that, you know, traditionally we've been given ninety to a hundred and twenty days to fix something. But again, going back to where the industry is, not surprising that that is-- that's gonna be a change. So, you know, when you have language models now doing pen testing doing that in real time, that's where this 20X program and, and where FedRAMP is trying to go and, and is going to go, not trying to go, but is going to go, you know, having those things in place so that a human who is slow and error-prone, not doing something, but how something's repeatable and twenty-four by seven. Mike, what do you, you think?
[00:22:03] Michael Parisi: Yeah. I-- so com-completely agree in thinking about this through a little bit of a different lens, 'cause Sean, you, you, you, you brought this up in terms of, where, where is an organization on [00:22:18] their journey and what does that mean to them? Uh, Jason just stepped through, right, what's the timeline? What are all the changes?
What, what, what's gonna happen? Uh, it is, I think, clearly outlined, um, or maybe as clear as mud, depending upon, you know, who, who you are and what your background is
[00:22:35] Sean Martin: It's, it's documented anyway.
[00:22:37] Michael Parisi: It's documented, right. But if I look at this as not being an overly technical guy, but more of a business guy, if I look at it through, through that lens, okay, what does that mean to, to, to me?
Um, you know, if I currently have a, a program, gonna be a level of education. You need to understand-- You need to map what you currently have into the new classifications and certifications. Now, that may sound kinda simple. It's not that clear-cut, right? So understanding what the scope of maybe your old Rev 5 ATO was and understanding how does that translate into a new level of certification. [00:23:18] Think about it internally. You gotta re-educate everyone. You gotta re-educate marketing. You gotta re-educate sales. You gotta understand what the go-to-market motion is. And remember, you know, these organizations that maybe have traditionally interacted, um, directly with agencies or, or, or primes, if they're not up to speed on what these changes are, and if they've buried their heads in the sand, the onus is now on you, right, as, as the supplier and, and the vendor to do that level of education. So in our experience so far, nobody's done that, right? They, they understand what the timeline is, and they've heard there's gonna be changes, but nobody's really dug in. You know, it's kinda like the procrastination of you know something's gonna change, and you've heard about it, and you've read about it, but you don't wanna deal with it, so you kinda put it in the corner or, or look the other way. but-- And what, what we're advising organizations to do and what we're helping organizations [00:24:18] to do from a business perspective is don't wait to do that. Be ready. Be out in front. Um, have a translation layer to say, "This is what we've traditionally provided. This is what it's gonna be now." Um, make sure you have a, a clear communication path to say, "Not it.
Not our fault," right? Changes to the program. not trying to do anything in terms of downgrading our assurance, et, et cetera. that level of education for organizations that have had a traditional program needs to occur. Um, the second piece is For those folks that have been on the sidelines or fence sitters for a number of months to say, "Well, do we really wanna make this investment from an ROI perspective? Seems like there's gonna be a lot of changes. We should wait until these shake out." Again, they're here, now you need to make a business decision in terms of where do you enter the [00:25:18] ecosystem, right? So in, in the past, right, as Jason mentioned, there was really only two things. You either had an ATO or you had FedRAMP ready. It was easier, I think, from a business perspective, determine, are we gonna make an investment to be ready and get listed so we can get some eyes on us, hopefully we get a prom date, which would then trigger the decision to go for ATO. Now, this is a lot different. Where do you enter? Do you start with 20X?
Is that relevant for you? Do you start with a different certification level? what does that mean and how does that align to the business opportunities and the expectations from potential customer and client perspective? motion, business decision. So more options that are available relative to entering this ecosystem now. However, with anything, right, it's like a kid that you give too many choices to, um, it [00:26:18] becomes more confusing and harder to, to make a decision. So through some of the things that we're doing around ROI workshops, right, um, uh, office hours, everything that we're doing complimentary because we're geeks when it comes to this stuff, wanna help, um, organizations get educated sure that they enter the ecosystem at the right spot
[00:26:40] Jason Ford: And I would, I would dovetail off of that and say it doesn't matter if we're talking about consolidated rules for 2026, if we're talking about the next thing that FedRAMP moves to, or CMMC or GovRAMP or SOC 2 or ISO or whatever it is, it doesn't matter from a regulatory perspective or a maturity level of your security operations practice or your security engineering, It's the same motion that we do, that, that you should be doing, right? As a, as a business owner, maybe you don't have time to do it, maybe you don't think to do it, maybe it isn't something that's important until it becomes important because some external factor causes [00:27:18] you to do it. but it's something you should be thinking about, especially if you're a C-level, a VP, someone who's in charge of something that is tied to revenue, tied to ROI on these objectives, and, uh, the business will feel pain if they don't have them, right?
So that's-- uh, should be doing that as a planning exercise regardless
[00:27:41] Sean Martin: Well, it's, it's so easy to see this is coming down the track, hand this project off to my team, what's the impact gonna be? And what's the team gonna look at? They're gonna look at how does this change my current infrastructure? How does it change my dev process? How does it change my auditing? Does this impact my team?
And then, oh, oh, by the way, there's the business, right? It... How does this change how we do business? Right to your point, how do we... how do I actually deliver what we're providing? How do we actually market it? How do we actually build it? The whole up and down the stack. [00:28:18] And so I'm wondering if you can share with me some, I don't know, I'm sure you've had a lot of conversations on this already, where, yeah, starting off looking at it from the business, um, are any aha moments when you start at that moment that say you can, you can ch-ch- or take this path and find a way to your, your objective much more cleanly and certainly with more certainty, um, because you'd looked at the business first.
Any stories to, to share on that front?
[00:28:54] Michael Parisi: Yeah, I think we have several. Um, i-it's-- So I, I think we always bring it back to c-communication, right? And, and, and understanding what the expectations are from a stakeholder perspective. that's internal and that's external, right? So to your point, you're making a lot of references, I think, to [00:29:18] maybe an engineering, uh-- at the end of the day, we're talking about engineering.
And when I say engineering, yes, there's engineering in building a system, but there's also engineering of processes. There's engineering of the business. There's engineering of go-to-market. There's engineering of understanding what your stakeholders e-expect. so at the end of the day, communication and, and clarity is really where, where we focus. And we have a number of different examples where, um, candidly, where I think one of the best value-added things that we do every day is to tell people not to pursue this it doesn't align with their business needs, right? so one of the very first things that we do is say, "Look, this might be a bright, shiny object, if you will. You may think it may unlock additional ROI. You may think you [00:30:18] understand, uh, what those expectations and requirements are. may think you understand what the cost is associated with this." if we bring that back to, is this gonna benefit the business today or even six months from now? Uh, fifty percent of the time, we lead organizations in the direction of, "No, don't go down that path.
I wouldn't if I were you." And in our own businesses throughout the years, we've had to make those very decisions as well. That doesn't mean that it isn't gonna change, um, but communication and understanding that impact is oftentimes will lead a, a horse to a different bucket of water, um, which is this doesn't make sense for you to pursue at, at, at this point in time, right? In the other vein, um, we have a number of organizations that have come to us that are going down the wrong path, right? Um, lots of organizations [00:31:18] have come to us to say, "Hey, we've heard about this new 20X thing. This sounds great. we hear that it's quicker and cheaper and faster and, you know, less dependent upon, um, purpose-built systems and heavy engineering, and we could just use a platform off the shelf."
Although all of that may be true If the requirement that you have from a potential prospect, whether that's an agency or whether that's even a, a sub or, or a prime contractor, if that requirement doesn't explicitly say they're going to accept 20X as an example, they expect more than that, don't think that you're gonna get away with a lower bar from a business perspective. So like we just had one of these conversations yesterday where an organization was ready to pour all these resources and all this money in- in- into 20X because they thought it was a stepping stone relative to where they needed to be with their client. [00:32:18] said, "Why are you gonna do that? Like, you, you have to go for a certification level, right?
Which is effectively the old ATO process. Like, that is what you're gonna have to go for. Don't waste your money trying to go through something that isn't gonna align to your prospect's expectations." So a lot of our conversations is should you be doing any of these at all? it make sense? are you doing the right one in order to meet the expectations of your prospects and, and customers?
And we have those conversations, daily
[00:32:57] Jason Ford: Yeah, and there's, there's an additional thing. Agree with everything you just said, right? And, and that's the, the other thing to think about here, it's not only just dollars, right? It is also organizational disruption. regardless who you're talking about, you hear there's, there's a lot of people talk-- A lot of organizations will talk about 20X, it's easier, it's cheaper, it's faster, whatever. [00:33:18] That is true. Remember that the Rev 5 process took eighteen months at one point, right? So it-- Is it faster? Yes. Is it immediate and instant? No, it is not, right? So think about organizational change. Think about how fast things have to, have to take place, and is your organization built to take that change on, right?
So if you're a large organization, anything over five hundred employees, a thousand employees, maybe there's a couple hundred, hundred, uh, users in your organization that's in your system, that is not a small endeavor to retrain a hundred people or a couple hundred people to deal with that, So it doesn't matter if the controls themselves and the audit processes is quicker, right? I think, Sean, you said this earlier, is, is it, it really comes down to total piece of this and that disruption, right? So how that impacts you is not-- You can't just focus on [00:34:18] dollar and cents here, right? And that's a lot of times why we lead with, um, or we talk to someone about this, they back away from it or into it with better vision, that, you know, that's something that's always overlooked, right?
It's if it, if it's just a budgetary number, a number on a, on a spreadsheet, then that's one conversation. But if you're looking at it from a holistic perspective, like it's gonna take fifty percent of my organization, fifty percent of their time over the next year the applications, the infrastructure and everything else in a place where it can actually do KSIs for 20X, that's a whole another problem, And I'm not saying that you shouldn't think about that or you shouldn't do that, but you have to think about it, right? And you have to, have to plan for it. And those are the, the little nuggets that people get tripped up on, right? And they get into the process, it's too late, right? You're, you're in the mess at that point.
You've already made a, made an [00:35:18] effort, a motion. Now it's harder to get out
[00:35:22] Sean Martin: Yeah, and so many decisions, uh, I'm sure you've seen them all as well. Uh, different environments bring different challenges, different ways something has been built from a stack perspective brings different challenges. Whether you're using partners and third parties to help deliver some of these things, you're riding on a cloud service provider and, and trying to inherit things.
And how you, how you put all that together in terms of an architecture, uh, matters. How you staff and build your team. Do you do it all in-house? To your point, if it's gonna take fifty percent, that's probably fifty percent less you're doing on your current business, right? And, and do you do that in parallel or are you, are you disrupting the current-- not just moving forward, but disrupting current business as well, um, because of the changes you're making?
A lot of that stuff you have to take into account. And again, I think you guys have seen it and had, have had the conversations and have helped companies move from A to [00:36:18] Z in a purposeful manner. And I think that's the key. Other... Too many stories, and I don't think that I necessarily need to share any here, but I'm sure you've seen a gazillion stories where things go off the rails because of one, one decision up front that just throws everything off, and it's hard to get it back on.
And you can certainly bring people in, and I know you, you have teams that, that you can actually bring on-site to help organizations. Um, what, what kind of people do you need? Do they need to be US employees for that matter, right? And, uh, where can you find those folks? And I think you, you guys have a, a lot of the answers just because you've seen it and been there.
And Mike, to your point, it may not always be the answer is move forward right now. It might be wait six months or, or get your other part of the business working to help, help fund or whatever it is. So I'll leave it there because I think w-we're kind of running out on time here. I wanna maybe give you a second to maybe chew on what I just said [00:37:18] and maybe provide some feedback to folks listening to where to start.
What's that first step, um, in connecting with you to, to, uh, get a better assessment of where they are?
[00:37:30] Michael Parisi: Yeah. I mean, I think, um, back to communication, right? That the first step is, at least for, for us, um, again, we're, we're here to help to have that business conversation. That's where we're gonna start. We can certainly, you know, dive deep into the technical and, and engineering elements, but that would be, I think, doing anybody a disjustice, right?
And so you should really start with, with, with the business conversation. I think to, to your point, it's not just getting to a decision today if it's a yes or a no. It could be a maybe if, And that's, that's kind of where we leave every conversation is un-understanding it's just like any decision that, that, that you make. What are [00:38:18] those trigger points that you need to have defined? Today you may not have that. These are the things to watch out for. If these things happen from a business perspective, it may be something that you move forward with, right? As, as, as an example. but as I mentioned, you know, we offer complimentary ROI workshops, business discussions, to anyone and everyone.
And it's not just an old term I used to use, the assessed entities, right? So not just the organizations that are looking to go through this, it's the relying parties as well. So even, even primes. I mean, we, we do a lot of work with primes to help them understand, um, how do they manage their supply chain? What should they be asking for? What should they be looking for? What are red flags? have conversations with other consulting and advisory, uh, partners and assessor firms. So we're, we're here just to really add and benefit [00:39:18] the, the community, um, in terms of addressing tho-those questions and helping organizations wherever they fit in that equation make better business decisions.
[00:39:30] Jason Ford: Yeah. And, and I would say with all of that, right, anytime you go into something like this, come with truth and, and and openness. Don't come with a closed mind, right? 'Cause it's-- if you come in with a closed mind, this is change, right? And, you know, the old book, uh, Who Moved My Cheese type, type thing, right, is, uh, echoes in the back of my mind, right?
Is, is that, you know, if you're already coming with a closed mind, you've already said no, right? You've already not, uh, embraced the fact that this is a change that's gonna happen regardless if you want it to or not. A change is gonna happen. Doesn't mean it's this one, doesn't mean it's the next one. It m- this one may not impact you as much.
You might already be set up for all of this, right? [00:40:18] But the difference here is, is that, you know, coming to these things and just having conversations, that's, that's the first step, right? And, and almost, um, looking for that assistance and trying to figure that stuff out and, and going this stuff alone, relying on language models to provide you information or may not get you where you wanna be.
Most likely it will not, because, you know, while things are... You know, language models are only as good as the guardrails that are put up around it, right? And the training in which it is given. Um, certainly say language models in the current state of, of this recording are not where they should be to give that kind of advisory to you to how to run your business for the next how many years that you're gonna have this.
This isn't a one or two-year thing. This is a long-haul thing if, if you choose to go down this path, right? And it's not like even 20X is not just a short, you know, one-day, [00:41:18] two-day thing, right? It's, it's not like, "Oh, I'm gonna create a new workflow," and all at once we're here, right? I'm ready for assessment, and that's, that's not the case, right?
So having those, those, um, almost those as guardrails for yourself is key
[00:41:45] Michael Parisi: I think you're on mute, Sean
[00:41:47] Sean Martin: Look at that. Uh,
[00:41:49] Michael Parisi: There you go
[00:41:49] Sean Martin: all right. I was gonna say something. Oh, nice edit here. There we go. All right. Uh, I always have fun editing. Um, so Michael, I'll give you the, the final word, but I think my, my takeaway here is, uh, to your point, Jason, it, it's not coming with a closed mind. It's coming with an open mind, with a view for what you want to achieve from a business perspective.
And in doing so, [00:42:18] picking the right partner that you can trust to help guide you down that path. Whether you started marching and you're held up, or you headed down the wrong path, or you haven't started marching at all, and you need some guidance on where to take those first steps. Um, I've heard lots of stories where you've helped organizations in both of those scenarios.
Um, so Michael, final word from you, uh, connecting with folks. I know you're at a lot of events in a lot of locations, um, so perhaps people can talk to you in person as well. A final word
[00:42:51] Michael Parisi: Yeah. Um, don't wait and don't go it alone. um, you know, reach out for guidance and, um, for experience that, that, that, that we've had collectively. Not just Jason and I, but we've got an entire firm behind this, all US citizens, by the way, that, that, that can speak to this, that have come from every different walk, um, within this industry. [00:43:18] auditors to engineers owners psychologists. So
[00:43:26] Sean Martin: Good stuff. Well, Jason, Michael, important topic, obviously, uh, one that's very, uh, pressing and, uh, one that requires attention and, and the support from trusted folks like yourselves and, and the rest of the Steel Patriot Partners team. So thank you both for this conversation. steelpatriotpartners.com, and, uh, connect with Jason and Michael online as well
[00:43:50] Michael Parisi: Thank you
[00:43:51] Jason Ford: Thanks.