DevSecOps Solutions for DOD Software Factories
Increasing development speed, security, and resilience for DOD software
Helping the U.S. Department of Defense on your software modernization journey by providing technology that increases agility while satisfying Zero Trust mandates.
Latest DOD Guidance on Software Modernization and DevSecOps

DOD Software Modernization Implementation Plan
View Plan Summary
DOD Enterprise DevSecOps Fundamentals v2.5
View the latest Fundamentals DocumentMerlin's DevSecOps capabilities include:

Software Development and CI/CD Tools
Increase adoption of your software development tools with agile technology that speeds up your CI/CD pipeline.

Application Security
Consolidate DOD application security tools while gaining better functionality for scanning custom apps, third party apps, and code.

Software Factory Resiliency
Expand zero trust architecture, modernize endpoint security for cloud environments, and assist the DOD on its goal of implementing continuous authorization.
Resources

Black Duck Product Overview
Take a look at Black Duck's application security solutions. This overview highlights tools for managing software risk including static and dynamic analysis, open source security, and AI-powered assistance, designed to enhance trust and security in software development.
View Product Overview
CyberArk's Centralized Secrets Management
Learn how CyberArk's centralized secrets management can help DOD software factories effectively safeguard both human and non-human identities, enhancing security and compliance in an increasingly complex and automated DevOps environment.
View White Paper
Securing Modern Web Apps and APIs
This White Paper discusses advanced strategies that could significantly enhance the security posture of the DOD's web applications and APIs. Learn about a proactive security framework, continuous vulnerability assessments, DevSecOps integratiosn, and the need for cloud-native security solutions like Qualys Web Application Scanning (WAS) to safeguard digital assets in dynamic, high-risk environments
View White Paper
Protect Mission-critical Kubernetes Apps & Data with Ease
Crucial insights into how the DOD can enhance its cybersecurity and data resilience using Veeam Kasten. This brief explains how military operations can benefit from real-time data intelligence, secure backup, and rapid recovery of Kubernetes applications across multi-cloud environments.
View Solution Brief
Solving Government IT and Hybrid Cloud Challenges Using Kubernetes
By leveraging the powerful integration of Red Hat OpenShift and Veeam Kasten, DOD software factories can enhance their IT infrastructure with seamless scalability, superior data protection, and automated compliance. This solution ensures that mission-critical operations remain resilient and secure, even in contested or high-demand environments.
View Solution Brief
Veeam Kasten for Kubernetes
How Veeam Kasten provides secure, scalable, and automated solutions for protecting Kubernetes applications, offering features like ransomware protection, disaster recovery, and application mobility. Given the DOD's reliance on secure and resilient data operations, this overview highlights how Veeam Kasten can mitigate cyber threats while ensuring compliance and operational continuity in complex, cloud-native environments.
View Product Overview
Qualys for Kubernetes and Container Security
Gain complete visibility and control over your containerized environments with Qualys Container Security, safeguarding applications from vulnerabilities through development, deployment, and runtime.
View Webpage
Qualys for Web Application Scanning & API Security
Qualys Web App Scanning helps identify and eliminate web application vulnerabilities, providing continuous protection against evolving threats to keep your digital assets secure.
View Webpage
Qualys' DevOps Security Solutions
Integrate security seamlessly into your DevOps pipeline with Qualys, enabling rapid, secure development cycles and continuous compliance without compromising innovation or agility.
View Qualys DevOps Solutions
Essential Strategies to Secure Modern Web Apps & APIs
Explore essential strategies to secure your web applications and APIs in today’s fast-evolving development landscape, protecting against threats while enabling innovation and agility.
View Blog Post
Black Duck Software Supply Chain Services
Find out how these services can provide the DOD with vital tools to secure software integrity, meet regulatory standards, enhance transparency, and ensure robust software supply chain management.
View Services OverviewLet’s Talk
Get in touch with one of our DOD DevSecOps experts to learn more about how we can help.