<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=4730426&amp;fmt=gif">

Shifting the Burden of Proof for the Modern Enterprise Stack

For most of the history of Kubernetes in government, agencies had options. They could build their environment piece by piece, download free open-source tools, make tradeoffs, and figure out the security and compliance layer as they went. That flexibility made sense when deployments were more protracted, missions were contained, and the consequences of a security breach were easier to absorb.

With the introduction of generative AI capabilities, a diverse array of new hardware platforms, and edge computing at scale, that traditional approach does not work.

These technologies do not accommodate infrastructure assembled one piece at a time and integrated on the way to an authority to operate (ATO). The whole stack has to move as one. Compliance, provenance, authorization, and deployment speed must move in absolute lockstep. There is no longer a workable path that involves assembling the pieces separately and hoping they hold together under pressure.

Building for Production-Level Deployments

We are rooted in open source. RKE2, K3s, and Rancher Manager are our foundation, and the innovation happening in that upstream community is unparalleled. That said, while open source is a powerful engine for innovation, running unsupported open source in a federal environment is a massive operational liability.

When a program office downloads free open-source software, they inherit the entire burden of vulnerability patching, compliance mapping, and supply chain security. The "free" software quickly becomes exorbitant when you factor in the engineering hours required to manually harden, maintain and update it for Department of War (DoW) or Intelligence Community (IC) standards.

We build the RGS Suite directly from that open-source foundation, but we transform it into a fully supported, enterprise-grade vehicle. Powered by our Carbide software factory, we audit, rebuild, and cryptographically sign the upstream code, adding the security verification, STIG automation, and mission assurance that raw open source alone cannot provide. The platform itself absorbs the verification burden that program teams can no longer afford to carry alone.

The Burden Has Been in the Wrong Place

Under the legacy operating model, when a government program wanted to authorize a software platform, the work of proving that platform was secure fell largely on the agency. Program teams assembled documentation; Security Control Assessors filled gaps left by the vendor; Authorizing Officials signed off on packages built on partial evidence; and the vendor simply provided the software.

When an ATO package stalls because supply chain provenance is missing, or because a compliance scan must be run manually before every authorization cycle, the cost—and the risk—falls on the program office. That is the wrong place for it to land.

RGS takes a different approach: the vendor must own the proof. We are responsible for proving the platform is secure before it reaches a government environment. That means third-party validation instead of self-assertion, traceable supply chain verification, and documentation that comes embedded in the platform.

The FIPS 140-3 Verification Requirement is Coming Soon

RGS has DISA-published STIGs for both our Kubernetes distribution and our management platform. RGS RKE2 is FIPS 140-3 verified, carrying a third-party Letter of Attestation from Corsec and the AO-ready documentation a Security Control Assessor needs to move instantly from evaluation to authorization.

This is critical because the transition away from FIPS 140-2 is imminent. On September 21, 2026, NIST moves all FIPS 140-2 modules to the Historical List, meaning they can no longer be used in new procurements. Programs entering a new phase or renewing an ATO after that point will require FIPS 140-3 verified components.

For organizations still running piecemeal, self-asserted compliance on DIY open source, this is where the wheels come off. FIPS 140-3 verification is centralized and exclusively available through Carbide, the security engine powering the RGS Suite. We will work with existing customers through this transition, but agencies must plan their migration to the enterprise suite now.

What the RGS Suite Absorbs

When compliance, provenance, and deployment speed must move in tandem, the platform takes the weight. Every capability within the RGS Suite reflects this operational reality.

  • Verified Provenance: RGS audits and rebuilds upstream open-source software in-house before it reaches government environments. Programs know exactly where their infrastructure came from and who is responsible for it.

  • The Carbide Secured Registry: Provides teams with a controlled, verified source of container images, completely airgap-ready.

  • Compliance Operator: Handles DISA STIG compliance by scanning automatically across downstream clusters, replacing the 12 to 16 hours per month of manual validation that teams previously endured. Provides a common export format (XCCDF) most commonly used by government cyber assessors.

RGS RKE2 remains one of the most widely adopted DISA STIG-certified Kubernetes distributions for the DoW, IC, and federal security agencies. The certification work is already complete when a program needs to show it.

The Center of Gravity

The market has shifted, and so has our platform. We have built the RGS Suite into a definitive enterprise stack where a single, verified subscription covers your entire infrastructure—from Manager and Observability to RKE2 and K3s.

The RGS Suite is our center of gravity. New capabilities, compliance tooling, and security standard updates land here first, ensuring customers have the verification and documentation in hand before the requirement ever lands on their desk. Program teams do not need to rebuild the compliance case from scratch each time the platform advances.

That is what it means for the vendor to own the proof. The platform is ready. It's time to build. 

Contact RGS today for a FIPS 140-3 Gap Analysis and learn how upgrading to the RGS Suite can accelerate your next ATO.