Back/Leidos, RegScale embed continuous ATO risk management across federal systems
USA·February 7, 2026·ldos

Leidos, RegScale embed continuous ATO risk management across federal systems

ED
Editorial
Cashu Markets·2 min read
TL;DR
  • Leidos partners with RegScale to integrate UpHold Armor and CCM for automated federal cybersecurity risk management and compliance.
  • Leidos’ solution embeds continuous controls monitoring and automated evidence collection to support federal ATOs under NIST and FedRAMP.
  • Leidos ties the program to its NorthStar 2030 modernization, positioning for large-scale federal cybersecurity, reporting about $16.7B revenue.

Leidos and RegScale embed continuous risk management into federal systems

Leidos is announcing a partnership with RegScale to integrate its UpHold Armor platform with RegScale’s Continuous Controls Monitoring (CCM) product, aiming to automate cybersecurity risk management and compliance across the Department of Defense, the U.S. Air Force and other federal agencies. The integrated offering embeds automated risk management into both modern and legacy systems, continuously tracking security controls and automatically collecting the evidence required for authorization to operate (ATO) under federal standards such as NIST SP 800-53 and FedRAMP.

The joint solution shifts agencies away from episodic, staff-intensive audits toward continuous readiness by providing ongoing compliance posture and automated evidence collection. Leidos and RegScale say this approach reduces operational risk, staff burden, time and cost associated with audits, and supports faster approvals for system deployment. Leidos Digital Modernization President Steve Hull describes the work as enabling mission-focused security, while RegScale co-founder and CEO Travis Howerton emphasizes turning ATO into a continuous capability so agencies can move at the speed of innovation.

The integration is designed to minimize the need for additional cybersecurity personnel and to avoid increasing operational complexity by embedding compliance into everyday processes. Initial deployments are supporting the U.S. Air Force and other War Department and federal organizations that are modernizing security operations, seeking improved visibility, reduced cyber risk and protection for aging systems. Leidos and RegScale present the offering as practical and cost-saving for agencies balancing mission demands with constrained budgets, enabling more secure mission delivery for taxpayers.

NorthStar modernization drive underpins move

The collaboration aligns with Leidos’ NorthStar 2030 strategic focus on digital modernization, reinforcing the company’s push into mission-led cybersecurity and systems modernization. Headquartered in Reston, Virginia, Leidos is positioning the program as part of a broader effort to bring automated, continuous security controls to large-scale federal programs; the company reports about 47,000 employees and roughly $16.7 billion in fiscal 2024 revenue.

RegScale’s role and initial rollout

RegScale is positioning its CCM platform as the automation layer that turns compliance artifacts into continuously updated operational data, and the partners are rolling out initial support for Air Force and DoD customers while promoting lower-cost, faster ATO cycles to other federal agencies. The companies unveil the offering via PR Newswire and frame it as a practical path for agencies to accelerate secure deployments without adding significant headcount.

Cashu Markets
Cashu
Markets

By Cashu Markets. Providing market news, analysis, and research for investors worldwide.

© 2026 Cashu Technologies Pty Ltd. All rights reserved. Cashu Markets is a trademark of Cashu Technologies Pty Ltd.

The content published on Cashu Markets is for informational purposes only and should not be construed as investment advice, a recommendation, or an offer to buy or sell any securities. All opinions expressed are those of the authors and do not reflect the official position of Cashu Technologies Pty Ltd or its affiliates. Past performance is not indicative of future results. Investing involves risk, including the possible loss of principal. Always conduct your own research and consult with a qualified financial advisor before making any investment decisions.

Cashu Markets and its contributors may hold positions in securities mentioned in published content. Any such holdings will be disclosed at the time of publication. Market data is provided on an "as-is" basis and may be delayed. Cashu Technologies Pty Ltd does not guarantee the accuracy, completeness, or timeliness of any information presented.

Cashu Markets
Cashu
Markets

Setting up your session...