Army all but abandons custom-built software for commercial buys
Driscoll's policy update makes commercial solutions the default acquisition path and tells cybersecurity officials to clear products faster, but the continuous ATO framework that would make that work is still in pilot.
TL;DR
Army Secretary Dan Driscoll's July 22 policy directive, published last week, orders the service to default to commercial solutions openings and other transaction authorities for software procurement, reserving custom development for cases where no commercial product meets operational needs. The memo also instructs cybersecurity officials to lean on continuous ATOs and reciprocity agreements to accelerate deployment. But the Army's continuous ATO framework (launched in pilot under CIO Leonel Garciga) hasn't yet reached production, leaving the security review model the policy depends on in an unfinished state.
The directive is Driscoll's most explicit move yet to rewire Army software acquisition around speed. Program managers are now told to consider commercial products first, then commercial products configured for Army use, and to pursue enterprise licensing deals when a product serves multiple units. "Custom development should be extremely rare," the memo says.
The contracting mechanics shift with the policy. Commercial solutions openings replace the traditional prescriptive RFP cycle, a company submits a five-page concept paper, the Army talks it through, and a demonstration or pilot follows. Greg Garcia, the Army's deputy CIO from 2018, 2021, told Federal News Network the approach cuts solicitation from over a year to days or weeks. That tempo is the point: Driscoll's memo frames the overhaul as a response to Defense Secretary Pete Hegseth's push to field software "at speed and scale."
The cybersecurity piece is where the policy's ambition runs ahead of its scaffolding. The memo tells cyber officials to ease adoption through continuous ATOs and reciprocity agreements. But the Army's continuous ATO framework, piloted under Garciga starting in 2024, remains in testing. Garciga described it in April as "almost ready to push into production." The approach accredits DevSecOps pipelines rather than individual software releases, a shift from point-in-time ATOs. Getting that into production is the difference between the memo's speed mandate being a real path or a bottleneck in waiting.
The Army has been building toward this for two years. Margaret Boatner, deputy assistant secretary for strategy and acquisition reform, told Federal News Network in 2024 that the service was retraining itself to treat software as "never done", staying in development mode rather than transitioning to sustainment, where O&M funding rules restrict updates to minor patches. The new policy gives that posture a procurement vehicle.
Garcia flagged the obvious tension: the Army will "have to rethink how we assert the cyber health and the continuous assessment of those commercial products in a way that's a little different than what we do today." The policy has the answer on paper. The production pipeline doesn't yet.
Published ·Deep Fathom