RapidFort & SpaceWERX Target AI Software Supply Chain Security

The News

RapidFort, a software supply chain security company, and SpaceWERX, the innovation arm of the United States Space Force, convened a conference on October 8, 2026, at the University of Texas at San Antonio to address threats to America’s AI software supply chain. The event, grounded in an existing Cooperative Research and Development Agreement (CRADA) between the two organizations, brought together government practitioners and commercial industry leaders to examine topics ranging from AI exploit windows and agentic system security to post-quantum cryptography readiness. The conference framed software supply chain security not as a compliance exercise but as an operational imperative tied directly to mission assurance and warfighter capability.

Analyst Take

Why This Matters Beyond the Event Itself

The RapidFort-SpaceWERX convening represents something structurally unique: a CRADA-backed forum where commercial capability is being actively evaluated against operational requirements in the national security context. CRADAs are not typical vendor relationships. They signal genuine intent to co-develop and transition technology, which means RapidFort is not just pitching to the Space Force; it is working inside the acquisition and requirements process. For defense technology vendors watching from the sidelines, that distinction is significant.

The five panel themes are also telling. They range from hardening AI supply chains to preparing for post-quantum cryptography migration to managing identity and authority in agentic systems. Each of these topics has been discussed in policy circles for years. What this conference signals is a shift from discussion to implementation pressure. The Space Force, operating in a contested domain where software integrity is a prerequisite for mission execution, is pushing to operationalize these capabilities at speed.

The FedRAMP Friction Problem and Who It Favors

For any commercial vendor trying to serve this market, the compliance environment remains a serious structural barrier. According to ECI Research’s Google GovTech Survey Results, 31.8% of respondents cited “FedRAMP/compliance approval friction for AI vendors” as the single largest blocker preventing widespread AI adoption in developer workflows. That figure aligns almost perfectly with what the RapidFort-SpaceWERX agenda is trying to solve: if AI-powered software delivery tools cannot get through compliance gates quickly, mission software timelines suffer regardless of how capable the technology is.

RapidFort’s positioning here is deliberate. Its focus on near-zero CVE container images and independently malware-scanned open-source packages addresses one of the most friction-generating steps in the government software approval process: producing verifiable, auditable security evidence. That’s not a marketing differentiator; it’s a compliance accelerant. Vendors who can reduce the evidentiary burden for ATOs and FedRAMP packages have a structural advantage in this market, and RapidFort is explicitly building toward that.

The SBOM Gap Is Larger Than Agencies Want to Admit

The conference’s “From SBOM to Mission Assurance” track addresses what ECI Research data suggests is a pervasive operational gap. According to ECI Research’s Google GovTech Survey Results, 54.9% of respondents reported “Manual generation during major releases, but scanning is inconsistent” as their current approach to Software Bill of Materials (SBOM) requirements. Only 21.8% had achieved fully automated SBOM generation and security scanning for every build. That means the vast majority of government and defense-adjacent organizations are generating SBOMs reactively, not as a continuous part of the delivery pipeline.

This is a problem that compounds quickly in an AI-heavy software environment. AI-assisted code generation introduces new dependencies at a pace that manual SBOM processes simply cannot track. When agentic systems start writing and deploying code autonomously, the attack surface management challenge becomes an order of magnitude harder. RapidFort’s runtime profiling and attack surface management capabilities speak directly to this gap, and the conference framing around “evidence that actually changes risk” suggests the company understands that the credibility problem for SBOMs is as much about data quality and actionability as it is about generation.

The Agentic Enterprise Is the Next Battleground

The panel on “Securing the Agentic Enterprise: Identity, Authority, and Blast Radius Best Practices” may be the most forward-leaning track on the agenda, and arguably the one with the longest commercial tail. As AI agents take on more autonomous roles in software development and operations, the security perimeter shifts from the network edge to the identity and authorization layer of individual agents. Government organizations are only beginning to think through what that means for audit, accountability, and containment when an agent is compromised. The commercial sector is not much further ahead.

Looking Ahead

The near-term trajectory for RapidFort is one of deepening entrenchment in the national security software stack. The CRADA with SpaceWERX provides a credible pathway to broader Space Force adoption, and a successful transition there would create reference architecture that other defense components could follow. Expect to see RapidFort expand its presence across AFWERX and potentially into other service innovation organizations as the DoD’s push for accelerated mission software (grounded in DoD Instruction 8430.01) creates institutional demand for exactly the kind of verifiable, low-CVE delivery pipelines the company provides.

The quantum cryptography dimension of this conference is also worth watching on a longer horizon. Post-quantum migration is not a 2030 problem in the abstract; it is a 2026 planning problem for any system with a long operational lifespan. Organizations that begin integrating cryptographic agility into their software supply chains now will have a meaningful head start over those that wait for a formal mandate. RapidFort’s positioning on this topic suggests the company is building toward that capability set, and the vendors that credibly address quantum readiness alongside AI supply chain security will be very well positioned as federal acquisition requirements evolve over the next two to three years.

Authors

  • Paul Nashawaty

    Paul Nashawaty, Practice Leader and Lead Principal Analyst, specializes in application modernization across build, release and operations. With a wealth of expertise in digital transformation initiatives spanning front-end and back-end systems, he also possesses comprehensive knowledge of the underlying infrastructure ecosystem crucial for supporting modernization endeavors. With over 25 years of experience, Paul has a proven track record in implementing effective go-to-market strategies, including the identification of new market channels, the growth and cultivation of partner ecosystems, and the successful execution of strategic plans resulting in positive business outcomes for his clients.

    View all posts
  • With over 15 years of hands-on experience in operations roles across legal, financial, and technology sectors, Sam Weston brings deep expertise in the systems that power modern enterprises such as ERP, CRM, HCM, CX, and beyond. Her career has spanned the full spectrum of enterprise applications, from optimizing business processes and managing platforms to leading digital transformation initiatives.

    Sam has transitioned her expertise into the analyst arena, focusing on enterprise applications and the evolving role they play in business productivity and transformation. She provides independent insights that bridge technology capabilities with business outcomes, helping organizations and vendors alike navigate a changing enterprise software landscape.

    View all posts