The Defense Information Systems Agency doesn't move fast. When it selects an enterprise platform for deployment across every military service, every combatant command, and every defense agency simultaneously, that's not a procurement decision — it's a doctrine signal.
Last week, DISA selected AttackIQ as the Department of War's enterprise platform for Adversarial Exposure Validation, establishing what the agency calls the first department-wide capability for continuously measuring defensive effectiveness through adversary emulation. The same week, Assail signed Qanapi to a five-year, $4.125 million contract to run autonomous red teaming inside a live FedRAMP High, DoD Impact Level 4-aligned environment. Two different companies, two different contract sizes, one shared thesis: the Pentagon's zero-trust architecture needs continuous, automated validation — not periodic audits.
That thesis is now getting funded and contracted at scale.
Continuous Validation Is the New Compliance
The old model was periodic. Red teams came in, ran assessments, wrote reports, and left. Security posture was measured in snapshots. Zero-trust architecture changes that requirement fundamentally — if every user, device, and data flow is supposed to be continuously verified, then the security controls enforcing that verification need continuous proof they're actually working.
AttackIQ's selection by DISA addresses exactly this gap. Rather than relying on vulnerability data or scheduled assessments, the platform enables organizations to continuously prove whether security controls, detections, and defensive processes will perform against the adversary techniques most likely to target their mission. The deployment also includes AttackIQ's AVA Agentic OS — described as an agentic operating system purpose-built for cybersecurity missions — and Watchtower, its AI threat intelligence analyzer, which together automate the analysis, prioritization, and validation cycle that previously required human analysts at every step.
This is the capability unlock that matters: not just finding gaps, but closing the loop between detection, validation, and remediation without waiting for the next assessment cycle.
The Assail-Qanapi deal is smaller but operationally instructive. Assail's Reaper platform will conduct continuous autonomous red teaming across Qanapi's infrastructure, automating STIG assessments, drafting Plans of Action and Milestones for FedRAMP compliance, retesting assets to validate true and false positives, and generating patches for review — all inside Qanapi's own authorization boundary, with no sensitive data leaving the environment. The post-quantum layer matters too: the integration embeds quantum-resistant cryptography to address harvest-now-decrypt-later risks and support Executive Order 14412 and OMB M-26-15.
That's a complete autonomous security loop running inside a defense-grade cloud environment. A year ago, that sentence would have described a roadmap. Now it's a signed contract.
Zero-Trust Scope Is Expanding Faster Than the Contracts
Breaking Defense's upcoming August 26 webinar on DoD zero-trust progress frames the next phase clearly: zero-trust principles are expanding beyond users and devices to operational technology — industrial control systems, IoT devices, and weapon systems. That's a materially harder problem. Securing a laptop is a solved category. Securing a weapons system with embedded firmware, legacy communications protocols, and operational constraints that preclude rebooting mid-mission is not.
The companies winning the current contract wave — AttackIQ at the enterprise level, Assail at the platform integration level — are building toward that harder problem. Continuous validation of IT systems is the proof-of-concept. Continuous validation of OT and weapon systems is the actual prize, and the procurement frameworks being established now will determine who gets to compete for it.
The Cathedral Question Hangs Over All of It
Meanwhile, the venture side of this story has its own signal worth tracking. Cathedral, a stealth military cybersecurity startup founded by four ex-DOGE staffers including former Pentagon chief data officer Gavin Kliger, closed a $160 million round at a $1.4 billion valuation, led by Andreessen Horowitz and Sequoia Capital. The company has no public product. What it has is founders who recently sat inside the government systems they now want to sell back into — Kliger reportedly played a role in launching GenAI.mil and the Pentagon's Drone Dominance Program before leaving for the private sector.
I wrote about the DOGE-to-defense pipeline back in July as an emerging asset class. Cathedral is the clearest expression of that thesis yet: a16z and Sequoia aren't betting on a product, they're betting on access and institutional knowledge as a durable competitive moat. Whether that moat translates into actual DoD contracts is the open question — Cathedral hasn't announced a customer, and government access doesn't automatically become a procurement win.
But the timing is telling. The DoD is actively building out its zero-trust and cyber validation infrastructure right now, with DISA setting enterprise standards and the scope expanding toward OT and weapons systems. If Cathedral has a product that fits that roadmap, the founders' government tenure gives them a faster path to the right conversations. If they don't, $160 million buys them time to build one.
Watch for Cathedral's first contract announcement — that's when the access-as-moat thesis either proves out or doesn't. And watch the August 26 Breaking Defense webinar for the DoD's own framing of where zero-trust compliance stands heading into the next two-year push. The gap between where the Pentagon says it is and where the contracts are actually landing is where the next wave of startup opportunities will emerge.
