The Defense Innovation Unit has run over 600 prototypes. That gave them a front-row seat to a frustrating pattern: commercial technology that works, stalling out before it ever reaches the warfighter.
The reason usually isn't the tech but the machinery around it, where facility clearances stretch across months, ATO processes still run on early-2000s tooling, and test timelines are measured in quarters instead of minutes.
Sarah Pearson, Director of Strategy at DIU, joined the Mission Matters Podcast to break down The Bridge, DIU's new initiative built to systematically tear those barriers down.
As always, please reach out if you or anyone you know is building at the intersection of technology and national security. And, if you’re interested in working at a Shield Capital portfolio company or another national security focused startup, please fill out this form to "Work in Defense Tech!"
You can listen to the podcast on Spotify, Apple, YouTube, the Shield Capital website, or right here on Substack.
Transcript
Maggie 00:36
On this episode of the Techquisition Edition of the Mission Matters podcast, we sit down with our next guest who’s spent the last several years at the Defense Innovation Unit bridging the military and Silicon Valley. Sarah Pearson is currently the director of strategy and recently launched DIU’s latest initiative called The Bridge out of stealth. The Bridge is built to tear down the barriers that keep commercial technology from ever reaching the warfighter, things like access to classified spaces, access to military networks, and access to military test ranges. Before her current role at DIU, Sarah spent the preceding five years as DIU’s commercial engagement lead, helping the organization source companies to participate on DIU solicitations.
David 01:21
Sarah represents a new model of government leadership. She started at the United States Naval Academy, and upon graduation, spent five years as a surface warfare officer. After separating, Sarah joined the private sector, first as a senior product manager at General Electric and then at Google, working on Google Assistant, before getting the itch once more for public service. Sarah, thank you so much for joining us on the Mission Matters podcast. Welcome.
Sarah 01:47
Thanks for having me. This is exactly where I wanted to sit down and share what we’re building within DIU. So I appreciate the time.
David 01:55
It is super exciting, and I think it cannot be understated some of the boogeymen that you are tackling with this Bridge initiative. but as we were sort of prepping a little bit ahead of this, like, actual recording, you know, you made it clear that this has been in the works for some time. But before we get into the exactly what’s happening, maybe just spend a little bit of time breaking down the three initiatives in your words for our listeners.
Sarah 02:27
Happy to. I think, I know you guys have an awesome pool of listeners, and I think a lot of them are the very people that frankly I wanna reach, DIU tries to reach, right? We try to find the builders, the operators that want to disrupt the system. They look at the modern battlefield, and they see their technology there, or at least they have the vision for where and how their technology can fit, but they’re facing this numerous walls, numerous barriers to try to drive those capabilities to scale. So yeah, I’m excited to be sharing this all with you. We, as Maggie shared, came out of stealth a couple weeks ago to share this new strategic pillar for DIU. Truthfully, we feel that this is akin to the CSO. When you go back a decade ago, 11 years. DIU just celebrated its, 11th birthday. It’s Owen reminded us all maybe the week before last When you go back and you look at the origin story and what you all were trying—I say you, I’m looking at David, what our early, our early folks who are leaders were doing at DIU, and then the evolution from connecting technologists to the government With investors in the mix, how do we contract? How do we prototype? And how do we wash, rinse and repeat that over and over? That took us about a decade, right? From when we had OT authority to running, I think we’ve now ran over 600 prototypes.
David 03:58
And Sarah, just to interject really quickly. So you’re talking about the CSO, the commercial solutions opening, the primary mechanism that DIU leverages to issue solicitations around projects and programs critical to various department customers, whether it be in the Army and Marine Corps, the combatant commanders. And then just to, for the audience, OTs other transaction, that’s the legislative authority for the contracting pathway that the CSO resides under. So just wanted to get our audience up to, up to date. But yes, I agree with you that what this portends to be, the Bridge, is probably just as revolutionary as what the CSO was to, you know, contracting pathways for the department.
Sarah 04:46
Thank you for defining this. David’s my go-to acquisition SME in so many ways. I appreciate that. Look, at the end of the day, I believe DIU has been engineered and is operated to break barriers. It is to look at a problem, whether it’s a problem that resides with a mission partner or a customer, in our, in our language, in commercial speak. With a customer who thinks they can only solve that problem the way that the machine, the institution has taught them to, right? DIU shows up and says, “Actually, hold on. There’s capability that exists that doesn’t leverage the resources, government-derived resources. It actually leverages private capital, and the technology matures at a rate that we don’t see within the department. Let’s go look there first and see if there’s something that we can tap into.” I mean, that culture of thinking differently and being comfortable in measuring risk, in taking on risk, that has informed what the Bridge is. So what is the Bridge? The Bridge is a platform to systemically bring down the barriers that are inhibiting our ability to scale commercial tech inside the department. Through 600 programs that DIU has run, we have had a front row seat to exactly where and why and how prototypes stop. Whether they stop at month nine because we’ve determined now we should clear the vendor, issue an FCL, a PCL clearances for the company and the people within it Or if it comes to a pause because we determined we should accredit, do some cybersecurity accreditation on the hardware or software stack, it’s inhibiting our ability to move quickly and get commercial technology validated in the hands of a war fighter and then ultimately scaled. So that is what Bridge wants to do. There’s one key thing I want to call out here, though. There’s a way to solve those problems with Band-Aid solutions There’s a way to throw money at a problem, to artificially juice a system. That’s not what we’re doing. What Bridge is driving is, yes, reducing barriers, and we’ll get into the areas, but how do we do that with institutionalization in mind? How do I ensure there is staying power to the approaches and the solutions that we bring online to reduce these barriers?
David 07:23
So Sarah, if I’m understanding, you know, after 10 years of operating, 10 years or more of operating a myriad of different projects, 600 plus, the systemic issues that are inhibiting companies from moving from the prototype phase to scaled wide adoption across the operational enterprise, you all have deduced it’s likely access to classified information, so fixation on the facility clearance process, FCL. And then the access to networks, whether they’re classified or unclassified through the authority to operate, procedures under risk management framework. And then also then the test ranges, or how do we test and evaluate technology to ensure that it meets whatever military standards that it has to. Is that correct, those three things?
Sarah 08:21
It’s correct, but I’m gonna elaborate even more.
David 08:24
Perfect.
Sarah 08:25
About a year, year and a half ago, when we were looking at this space and we said, “Hey, if we are serious about driving change and true adoption of commercial technology, it goes far beyond a success memo. It goes far beyond us validating that the commercial tech could solve a government problem. We have to test and clear and accredit.” As we were making this list of challenges, it’s long. I mean, I think our total list was around 30, 35 things were inhibiting dual use or defense tech founders from prototyping and ultimately transitioning their capability. Then as we began to quantify some of those things, like where does that really hit the pockets and the capabilities for the war fighter? And we rallied around three central themes. Theme number one, and therefore initiative number one, is not just how do we efficiently clear companies within the innovation base. Like thing one, we need to clear more companies. The bench has to be deeper. We have to have a bias to clear companies and the key personnel there sooner in the process. The second theme within the, this first bucket is then access to classified infrastructure. I mean, we’ve watched time and time again, we sign a prototype OT contract with two, three vendors for a specific program. We’ll attach DD 254s, forms that say there’s a need to know and we’re gonna take you through the clearance process We then walk the vendors through it. We’ve been giving them services, free services to help them navigate that. that, I mean, on the fast end, I think we’ve gotten one through around six weeks from when they were given 254 to when they had a full FCL TS level, I believe for that, this vendor I’m thinking of. But then we came across the challenge of, sorry, where do I, where do I actually put your engineers? Where do I have a SCIF available for you to pop in there and work? Spoiler alert, it’s not the DIU SCIF in a Conex container in Mountain View. So where and how do I put our portfolio companies to work? so a key element of this first category is changing the model for classified infrastructure, which we’ll get into more. But how do I physically put companies to work? How do I get them in the collateral, the SEI spaces, the SAP spaces, or unclass? Okay. Not overlook that. How do I get them in a space so they can be fingers on keyboard and actually deliver the capabilities that we’re buying instead of waiting 12 months to maybe slide into somebody else’s SCIF?
Maggie 11:15
Okay. So category one is really focused on helping companies get their facilities clearance or FCL faster, helping them get access to SCIFs, really just helping accelerate the process of getting access to some of this classified infrastructure that companies need to do business with the department. Next, can you turn and tell us a little bit more about category two, which with my understanding is really focused on reforming some of the key IT security processes the department has in place, like the Risk Management Framework, or RMF, and Authority to Operate, ATO processes.
Sarah 11:48
Category two, the ATO. There’s so many headlines. Google ATO. Gemini probably has a better perspective on how the, you know, we should fix the ATO process. it’s always—there’s always been a lot of talk. Hey, does it actually render cyber resilience? What is the value to the companies that are assessing and embedding mitigations to these controls that are outlined in the RMF Risk Management Framework process? But the piece that DIU is really interested in driving forward is looking at the instructions, of where and how we do that, and then how do I weave AI into that? It’s a very, very manpower-heavy process today. Can tell you, I just staffed a whole, a brand-new AO shop within DIU. It is hard to find these people, by the way. They’re brilliant cyber folks, but a lot of their time is spent in systems, maybe one in particular, the eMass system, and there’s a lot of manual entry, and there’s just you know, it reminds me of what software looked like in the early 2000s, early twenty—you know. You’re like, “Wow, we’re still doing this. Hold on. we’ve progressed past this.” So agentifying, if I can—I don’t know if that’s a word or not. David would know better than me. But like, how do I agentify RMF one through six in a way that in some ways is more robust than the manual way? And still deliver an opportunity to an AO or whoever they designate to assess risk on behalf of the government and certify it or not When you do that right, you can handle much greater throughput than we have available today. So that’s category two.
Maggie 13:33
Okay. So it really sounds like category two is focused on finding ways to speed up and automate the ATO and RMF processes to really help companies get their cybersecurity accreditations more quickly. Next, can you tell us a little bit more about category three, working to improve the department’s test and evaluation infrastructure for startups?
Sarah 13:54
Test is, first of all, a beast that I did not fully appreciate a few years ago. I think I appreciated it, or I know I appreciated it from industry, from kind of playing, you know, different product and program roles in AI world. But then you enter the test apparatus, which is the Department of War, and this is a very different, this is a very different game. You know, DIU, when we were prototype, we are. We prototype commercial capabilities, right? Typically, these are higher TRL capabilities. Something exists. Many founders that show up on DIU’s front step say, “Oh, my thing’s, you know, in production for Bank of America. I think it can solve these problems for you guys. I see you’re, you’ve got a solicitation out here. I think it’s in the same space,” right? This is technology in production. However, for the department to really field these capabilities, there’s a whole slew of developmental and operational tests that needs to happen. In pockets at DIU, our customers, the mission partners, would bring their test teams to the table, and they would help design the test and execute it and capture the data, so we had very clear performance artifacts that support how the capability delivered. So that was happening, but not enough. We did not have that approach really scaled, first of all, one. Two, it, in those instances, relied it on the mission partner, right? Relied on the Navy to come forward with those things, to tap into their test ranges, to tap into their, you know, all of their awesome capabilities in that space. However, we knew not every mission partner can come to the table with that. So that’s—So we began to assess where does DIU need to step up in this world of commercial tech, not tech derived inside the government or, you know, anywhere else. Where does DIU need to come up and at the very beginning start designing test plans? Because we know that drone is going to need to go through DT and, developmental tests and operational tests before it can get fielded with the Army. Got it. Let’s front-load. And by the way, let’s do that as effectively and as efficiently as it’s possible. Let’s leverage all of the capabilities that we have. Are those government ranges, commercial ranges, public lands, all of it? Yes. How do I book it? How do I book it easily? Great. I’m now shaving days, weeks off of someone’s many people’s jobs inside the department. So test, really the end state of what we’re trying to do is we’re trying to bring test left, make sure it is part of prototyping when we’re prototyping commercial capabilities, because at the end of the day, we will produce more buyable products. Also don’t know that this is a word, but actually give the PEOs and PAEs something they can buy and field immediately
Maggie 16:45
Sarah, that was great. I mean, it’s clear that you guys have thought extremely deeply about where some of these bottlenecks are for adopting this next generation of technology and have thought really hard about the best way to try and solve those bottlenecks. You know, one of the questions that comes to me, it sounds like you’ve already done a lot of really hard and great work. You know, will these concepts stay within DIU, or will the outcomes of what you learn and these processes move to some of these other legacy organizations traditionally responsible for things like RMF, FCL, test, et cetera?
Sarah 17:19
It’s funny you ask that, Maggie. look, all of these solutions, all the solutions that nest within the problems we just talked about, the way we’re devising the solutions are generally a blend of four inputs. There’s only four inputs, and I’m kind of toggling these up and down based on the scenario. Input number one, commercial tech. Where is there a tool I can use to fix part of this problem? Input number two, cultural. What is the cultural barrier that I have to overcome to drive change inside the department? Mostly that’s inside the department, but there’s some scenarios where it’s outside the department. Three, where do I need to lean on policy? Some of our efforts, we’re changing policy. We have to, right? or you need to clarify policy, or do you need an exception to policy, et cetera. And then the fourth lever that I lean on here is procedural. Where is there a process? You know, process engineering, where when we look at something like a SKIF accreditation workflow, okay? A lot of that’s pretty detailed and it’s clearly prescribed what that looks like. But what about the areas that I don’t? How do I kind of tweak the procedural aspects of these barriers or bottlenecks? because those are the key four inputs for all of them, the transition pathway, it varies. At the end of the day, DIU, again, I believe, DIU is meant to break barriers, think differently, have a bias for speed, and do everything with commercial cost in the center of our minds, right? We don’t own FCLs. That’s, that’s not my metric. That is, amazing leader, Joe Tonon, the director of DCSA, love what he’s doing over there. that’s his metric to own, though. But am I able to show up as a teammate, and partner with him and his organization to help get the best technology in? Yes, and that’s what we’re doing. So in some scenarios, nope, the owner resides with who owns the mission set. In other scenarios, as I mentioned, classified infrastructure is hard, right? It’s hard for us to get our companies... Any kind of dual use defense tech company, there is a bottleneck around getting into classified spaces. as part of that, DIU’s sponsoring a dozen plus, probably more, classified WeWorks, if you will. In fact, just use an easy term that folks understand. Will we own dozens of classified WeWorks? No. Are we the sponsor today? Yes, because that’s what was needed to go prototype a new model, a model where classified infrastructure doesn’t need to sit on the government’s balance sheet. Shift it. Let somebody else carry that asset. I just wanna pay for usage. I wanna help you get the thing operational as quick as possible so a company can get in, book a SIPR terminal, sit down and do their work on Mondays every week that they’re doing for the government. Great. The way we institutionalize the, institutionalize these different solutions that we’re trying will depend on the solution set, on where the mission sits today, and frankly, what will set us up for the greatest degree of success in the long term.
David 20:34
So Sarah, this is amazing work, and I agree, you know, institutionalizing, whether it’s a process change, an instruction change to help showcase that things can be done differently. You’re saying that these things are in motion, right? ‘Cause you’re coming out of stealth. So maybe just walk us back over the last year, 18 months. Like, what are the things that DIU has put in place today, and where can companies or people that are interested get access to these, I guess, call them services, if you will?
Sarah 21:10
So I’m actually gonna take the second part of that first, kinda who can utilize, right? So big picture up and out, I always tell the team, right? We’ve got a phenomenal team, by the way. Over and over, I keep telling them, “We will or we will succeed based on people,” 100%, and I believe we have a winning team. we’re really now just getting all the right folks in the right seats. That took a few months, which I understand in defense time, that’s actually rather quick. But, and to your, to your point, your question on what services, who can benefit. So the up and out piece, like I said, I wanna show the department there’s a new way to do ATOs, and there’s a way to do it on commercial timelines and at commercial price points. And when I say commercial price points, I’m talking about the burden we place on companies, right, that are maintaining infrastructure pending an ATO, and it’s costing them millions of dollars a year. That needs to come down, so that’s what I mean when I say commercial price points. look, us showing the department a new, there’s a new approach here, and working with all of the forward-leaning, brilliant AOs in the department, and they’re watching. “Okay, this is how DIU is gonna play with the model and see what they can do and how they can change it.” That type of up and out leadership, my hope is folks emulate, frankly, the way... Not my hope. We are sowing the seeds so folks then can follow the playbook the way they have with the CSO. To emulate that is that is a massive win, and that goes back to every single person that’s worked at DIU, every mission partner that has trusted us, every company that has signed up, taken money, and delivered to give you light. So that’s phenomenal. I think that can be akin to some of the work in the RMF space, for example. Let’s do that for RMF. Let’s show people there’s a different way, and maybe we blink one year from now, two years from now, people are all doing ATOs in weeks, and we’re not sacrificing any cyber resilience in the process. That’s the up and out piece, and just a silly, you know, one example with RMF. The down and in, ‘cause I get this question a lot since it came out of South a few weeks ago. A lot of folks are landing on our website. We do now have a capture mechanism there, by the way. So you can go there. If you have a cool technology that you think can help us solve some of these problems, ‘cause I mentioned commercial tech is one of the four inputs to the solutions. If you’ve got tech in that area, hit our website, go through it. It populates obviously on our side. We diligence those, and we’ll reach out. So, thank you for that. Quick side note. But for the companies that are reaching out saying, “Hold on, I need an FCL. can you get me an FCL in weeks? I need an ATO. My ATO’s been stalled with so and so for one and a half years My answer to them so far is we are bringing these services online for DIU portfolio companies to start. That is my test pool. DIU maintains about 100, 100-ish, let’s say, active portfolio companies at any given time. Portfolio companies, by the way, to us, just companies that are actively performing on a contract. Just, talked about classified infrastructure. the vendors we’ve—Some of our, performers have gone public, that they’ve won a segment of the business for this. They’re not creating those spots just for DIU portfolio companies. No, that’s for, that’s for anybody, right? So, as those sites come online, that’s a B2B play that luckily no need for government interference on that at all. Companies can go book spaces and utilize those classified WeWorks. so that would be maybe an exception to anybody can really leverage that, pool.
David 24:53
So maybe just to switch from the facilities and access to classified spaces, let’s move to the networking side. ‘cause I’ll be honest, I polled all of my, like, sweat equity participants, and asked them of these, like, three pillars under the bridge, which one do they think would resonate the most with, you know, the emerging non-traditional companies? Yeah. And about 70%, ranked the kind of networking side of it as number one and then facilities number two, test ranges number three. But maybe they’re all just a bunch of software developers and they’re super biased. But for my sweaties out there, can you maybe highlight what are the things you have in motion going on with the networks today?
Sarah 25:42
Yeah. Isn’t that funny? I wouldn’t have anticipated that actually. Do you know... Hold on. Question to your question. Do we know which areas? Like, are they looking for more, you know, government networks and environments to drop their code in to leverage to tap into operational data sooner for validation? Like, do we know, when they talk about the networking piece, which elements of that they’re really trying to get after?
David 26:11
So for some of them it’s, “Hey, my technology can perform a function for you at the open source level.”
Sarah 26:20
Yep.
David 26:21
And because I can do that, the government is less likely to give me an ATO for fear that they’ll no longer get access to publicly available information on, like, potentially dirty networks or, non-NIPR, non-SIPR.” Others have just highlighted a real challenge in getting access to data to train their models absent of going through the RMF process, and it taking a really long time to get sponsorship and some authorizing official to approve it. And then I’d say there’s a third bucket who’ve maybe been successful in receiving an authority to operate from one entity, but then not getting the reciprocity to join a different program and getting on their network, without having to go through the whole process. So, you know, I would say at the end it’s this, there’s just a huge schism in getting commercially developed software or commercially developed models access to information and insights, or getting operators to use it, as part of their workflow.
Sarah 27:31
To me, there’s a few things. I think, maybe I ought to break this up into, The RMF piece we’ve, we’ve dwelled on for a second here on... The DOD is really clear on what needs to happen when. eMASS of all the controls, you know, the assessment of which ones apply to this specific technology, you can automate a lot of that, and we’re gonna do that. So I think that gets after at least the pieces of we don’t have enough manpower. There’s a manpower problem inside the department for the people that work within kind of the RMF framework. That’s a true thing. There’s a reason everyone’s beg, borrowing, and stealing access to AOs. Since we, DIU, brought in, a second AO. So there’s a, there’s a shortage of people, first of all, across all the levels, the ISMS, the ISOs, the SKAs, the A... Like all the way up. so fixing that process and automating it, that’s gonna help with some of the throughput problems that the department’s seeing for the people that choose to adopt these different approaches. And of course, we’re designing the contracts with the vendors that are helping us do this in a way that’s highly scalable. The reciprocity piece, my hunch, and I totally could be wrong, I’m not a cyber person, but as we drive a degree of standardization in how we assess for risk and therefore mitigate risk against the controls that apply, if we’re automating that to a really large degree, and then these eMASS records start to look a bit more similar, I actually think that’s going to drive trust across the AO community in a way that I don’t know is there today. I’m not an AO, I’m not an AO by background. but here’s an example. If I hop into eMASS and I look at an ATO package for, I look at someone’s record for a comp—you know, some, doesn’t matter, defense tech company, and you see that it was initially accredited at the Air Force. And say I’m the new AO looking at that, and maybe the ask is for the DIU AO to take on that. You look through and there’s a lot of gaps, right? There’s a lot of just differences across the two different AOs of, “Hmm, why is this empty and this empty?” And that answer doesn’t address that. What... You know. So there’s variation, and I think it’s, it’s some of that variation that leads to a degree of the lack of reciprocity. Now, to the point on networks, how do I get access to operational data sooner? Here’s something I witnessed firsthand. when I first joined—When I first left Google, I came to DIU, was leading commercial for AI. So, you know, three, four thousand companies a year met over. We curated probably a dozen we were generally curating a dozen projects a year. Our bias at that point, this is early COVID days, our bias was to do everything unclass, right? We would even take a classified use case, obfuscate it with an unclassified narrative, and our bias was to then buy unclass data, make dummy data if we needed to, but like prove the thing works without ever having to touch government data. One of the things we learned in that process, though, was by kicking the can down the road, it didn’t actually make our products any more buyable, because at the end of the day, when you go back to the DoD or IC and say, “Hey, look, I have this knowledge graph. It can do all the things for you.” One of the first things they say is, “Sorry, is it ATO’d?” Like, “Can I use this now?” And we’d say, “No, no, but we validated it unclass.” And they’d be like, “I don’t have time. That’s 18 months, 24 months. Not interested. Thank you, bye.” So part of our hypothesis and what we’ve put into practice is, no, no, we’re gonna credit the software sooner because we can do it faster. Let’s do that sooner so the company can see how their system performs in a true operational environment or with operational data at least, with government data, and now we have something to really iterate and improve upon. giving access to DIU portfolio companies to networks to be able to do that, maybe spots they inherit some controls, to condense that timeline even further or not, right? but creating those environments for DIU portcos to be able to move quickly and implement their tech in is another key aspect of our second, a second team around accreditation.
Maggie 32:00
Yeah, Sarah, I also wanted to dive just a little bit more into how you all are thinking about the physical testing of systems as well. I mean, I have friends who work at drone companies or otherwise, they’re constantly, you know, dragging all their kit out to the middle of the desert in order to, you know, do testing in a place where they’re allowed to do it. Obviously, even, when you’re in the middle of the desert, in the middle of nowhere, but not on a military base, there’s still certain kinds of testing you’re not able to do anywhere but on a military base. So just would love to hear a little bit more of the details of how you all are thinking about accelerating the testing process for a lot of these vendors.
Sarah 32:37
So some of this, I’m gonna sound a little like a broken record because frankly, some of these changes that you implement in pillar one for classified infrastructure, they translate to the other ones because at the end of the day, these are systems, these are processes that have been developed decades ago in some instances. first I think it’s moving test and test planning left. Thing number one, I already made this point, so I’m not gonna get into it a ton, but how do I ensure that I have test engineers, test planners, and test managers here at DIU from the moment we curate a program? It’s that the Air Force comes to us and says, “We wanna do X, Y, Z. What do you think, DIU? Is there commercial tech available? Is it on commercial timelines and commercial price points, and does it drive lethality, i.e. align to DIU’s mission?” Those are yeses, and we’re gonna be taking on this program jointly. I need a, I need a test expert in the loop right away to be looking at that program plan that we’re developing before we ever even go to market to solicit and look for capabilities. I need to have a test plan for developmental and operational tests right alongside. so I think that’s, that’s number one, just a process change. That’s in category of kind of process changes. there’s some work in there too that bumps into the authorities that we have at DIU or authorities we can lean on to do that. So that’s a, let’s call that a paperwork exercise with, memorandums, with agreements and understandings and all these things. So making sure we can tackle the, authority piece to be able to do things in a legitimate manner. Another element, when we look at the infrastructure around test, to the example you just shared, Maggie, of like people go out in the middle of the desert. it’s astounding how manual the tooling is and process. but there’s some really awesome companies in the venture-backed space that have reimagined what test can look like, for digital and physical environments and are helping us really bring that infrastructure into the 21st century. I think that’s a very important piece. How can I design a test plan, in, you know, minutes, in a very short period of time relative to the months, nine, 12 months that historically for some types of capabilities and technologies it takes to develop a test plan? How do I, how do I condense that and bring the goodness of AI and other things to the table? I think that’s a key piece. And then another theme, we’ve got a lot of test ranges. We’ve got a lot of test environments open. You know, I was just down in Austin, Texas for Fed Supernova and had the privilege of going out to a ranch private citizen, who’s been a key, an avid supporter of the DoW and other, other services or branches as well, departments as well, You know, the authorities that we bring, the authorities, we bring the capabilities, and they’re—and the environment is there. We’ve done everything in accordance with FCC, FAA, all the, you know, all the other branches or departments that are important. great. There’s another example of kind of private lands that we can lean it, lean on.
Maggie 35:55
In a year or two from now, what do you want success to look like for The Bridge? You know, what kinds of success stories do you want people to be telling right here on the Mission Matters podcast?
Sarah 36:06
you guys, again, have such an awesome collection of founders, builders. I would love for those people to have access, to have had one of these things fixed for them. And like, you know what? Before, I could have never dreamed of getting my company and my people cleared so we can apply for classified solicitations. I’d love for them to be able to do that. I’d love for them to be able to book, space within a classified facility to deliver on a contract they’re already on. I’d love for them to be actual practitioners and users of the solutions that we’re implementing right now in the department. In some of these ways, I think I shared earlier, the timeline to build a SCIF, that timeline is still, like, over four years from A contract being let to full operational capability. The, I’m trying to bring that to a year. But I think, yeah, make your listeners practitioners. That’s, that’s, probably the win within 12 months.
David 37:10
Well, Sarah, you’ve been super generous with our time. I’m sure your email inbox is probably just nonstop with different requests, but maybe just to build off of that last call to action, what else can we be doing here in the community? You know, the, all the listeners of the “Mission Matters” podcasts and our friends and allies across the venture ecosystem. You know, how do we help you at The Bridge be successful in implementing these much-needed and much-appreciated changes?
Sarah 37:41
You know, the solution will always, like success will always reside right at the intersection of the builders, you know, the operators, the people, those of you building companies and capability, the policymakers, the investors that are making that building feasible, and then the buyers, the government utilizing it all. Each of us, and many of us, have worn hats and we kinda rotate, right? We’re all obsessed. We have the North Star. We wanna see democracy persevere, so we hop, and wear different hats at different times in this ecosystem. but it really will take all of those working in concert to overcome even one of these barriers. I would say if you’re, if you’re on the builder side of that and you’re working with a PM within government, you’re on contract, and you listen to this on your commute, ask your PM. You know, “Hey, we’re, we haven’t talked at all about ATOs, but I’m building software. When...” Like, applies to both software, hardware, but like, “When are, when are we gonna go through the cyber things? What do I need to be baking into my system now so that I can satisfy those controls? Do you have an AO? Do we not? what’s my test plan? What about a clearance? I hear some cool kids at DIU are trying to, you know, change the way we do these things. Can I connect you with them? Can I...” Like, it really, I think, will be a little bit of a foot soldier exercise to start with, and it needs to come from all sides. That’s for the operator side. The policymakers, man, they were out ahead, right? It was Congress that first put Section 874 and the ‘25 NDAA, forcing the department to think about what classified infrastructure as a service would look like. So hats off to them. They continue to be phenomenal supporters, I just, I couldn’t ask for better partners on that side, so I would say we stay the course there. The investors, it’s you guys that are taking a chance on these things. You guys, it, and it’ll be even more critical. Talk about FCLs, as we bring investors to the table, and we start to clear them in a concerted way, which I’m really excited. Stand by for some news in that area in the next week or two. you guys are critical. You need to know what the demand signal is. What are the things the department needs to solve now, so you can efficiently direct capital, do what you guys do best. And then on the buy side, on the government side, do what our leaders have said. Have a bias for commercial tech. Have a bias to move quickly. Use flexible contracting mechanisms. and just be as impatient as we are, because we don’t have the time. We don’t have 10 years to show everyone how to use an OTA and actually adopt it. We have, far less time, you know, to really drive these commercial capabilities into adoption, so.
David 40:33
Well, Sarah, thank you so much for coming onto the podcast. We’re excited for The Bridge coming out of stealth, and look forward to its success in slaying these bureaucratic dragons, right? And unleashing American innovation across the operational, workforce.












