GOVERNMENT
Every Federal Deadline Assumes You Already Know What Software Is In Your Environment
BOD 26-04 gives you three days to remediate the most critical findings. The post-quantum order gives you until 2030. Both clocks start before most agencies can locate what artifacts are in their environments.
NetRise analyzes the compiled software across your agency's estate — firmware, containers, mission and OT systems — producing the component, reachability, and cryptographic evidence those deadlines run on.
The Challenge
Washington Set the Deadlines. Nobody Sent You the Inventory.
Mission systems, OT, and air-gapped assets run vendor firmware nobody else can scan and nobody wrote down. Software manifests describe developer intent. When a directive lands with a deadline attached, discovery starts from zero against a clock that has already begun.
Where Federal Security Tooling Stop Short
Agent-based scanners
Cover what an agency can install software on, which excludes mission systems, OT, and air-gapped assets.
Manifest and vendor SBOMs
Describe what a contractor chose to declare, not what the delivered artifact compiled in.
Network scanners
Read what a device announces from outside; the firmware underneath stays closed.
Manual reverse engineering
Accurate, and far too slow to run against a three-day remediation tier.
WITH NETRISE
Evidence The Mandates Assume You Have
NetRise Turbine® analyzes the delivered artifact across firmware, containers, operating systems, and applications, with no agents, no source code, and no contractor participation. This inventories mission, OT, and air-gapped systems, and evaluates candidate builds before authorization.
The directive tiers every finding on four inputs. Three describe the software: KEV status, the exploit-automation signals behind the "automatable" call, and whether an exploit yields partial or total control. Turbine produces those from the binary. Exposure stays the agency's call.
Certificates, public and private keys, and the algorithms protecting data are classified so quantum-vulnerable cryptography separates cleanly from PQC. Exported as a CycloneDX cryptographic bill of materials a PQC migration lead can put on a POA&M and report against each cycle.
When a component is implicated, NetRise Provenance® traces how far it propagates across the libraries, products, and vendors around it. Turbine names the assets carrying it. Scoping becomes a query rather than a hunt conducted by hand.
The AI executive order directs agencies to defend systems containing AI models. Vendor firmware ships AI frameworks and model files nobody deployed knowingly and no vendor documented. Turbine identifies them in the compiled artifact and records them in the SBOM.
THE SOLUTION
Two Products. One Complete Answer.
Software delivered to the federal government arrives as a delivered artifact and nothing more. Turbine opens it and establishes the contents — components, cryptography, secrets — without source code or contractor involvement. Provenance assesses whether the open-source inside can be trusted and, when something is implicated, identifies which systems inherit it. What lands in the POA&M comes from the artifact, not the attestation.
A finding isn't the same as a threat.
The three-day lane in BOD 26-04 is narrow by design. In CISA's initial analysis at one large civilian agency, roughly one percent of vulnerability instances landed in that tier, while more than sixty percent could wait for the next scheduled system upgrade. Sorting one from the other relies on reachability, not severity.
- Present — the component is compiled into the delivered artifact.
- Reachable — running code loads it, which is what separates a three-day finding from one that can wait.
What that produces against real federal software:
- 61Kgenuinely exploitable findings identified across a six-month sample, out of 3.8M raw CVE matches surfaced by binary analysis
- 1%share of vulnerability instances landing in the three-day tier in CISA's initial analysis
- 200+artifact types analyzed, including embedded Linux, real-time operating systems, and container images
One component is implicated. Which systems inherit it?
A compromised package often is called by upstream components. Provenance maps direct and transitive relationships across ecosystems, identifying the libraries, products, and vendors the risk propagates into, including paths that never surface inside any single binary.
- Which systems carry it — the assets holding the vulnerable component, named rather than assumed.
- Whether the project is still maintained — active development, or a repository sliding toward abandonment with nobody left to issue a fix.
- Who the maintainers are — the individuals and organizations behind the code, the regions they operate from, and whether any appear in threat reporting.
The scale behind that answer:
- 3M+open-source repositories indexed
- 10M+packages resolved to their upstream sources
- 100M+contributors profiled by organization and geography
Federal Results You Can Measure
Inventory mission, OT, and air-gapped systems that agents and network scanners cannot reach.
Sort findings into BOD 26-04 remediation tiers using evidence drawn from the artifact.
Produce a CycloneDX cryptographic bill of materials ahead of the 2030 and 2031 migration deadlines.
Hand assessors CycloneDX and SPDX SBOMs tied to specific deployed assets for RMF and ATO packages.
Which of Your Systems Are You Still Guessing About?
Frequently Asked Questions
What does NetRise do for a federal agency?
It analyzes the software an agency actually received — firmware, container images, operating systems, applications, and embedded systems — and establishes what is inside the compiled artifact. Turbine identifies components, cryptography, hard-coded secrets, and exposed keys, and determines which vulnerable components running code can reach. Provenance assesses whether the open-source inside can be trusted and traces how far a compromise propagates.
How does NetRise support BOD 26-04 remediation tiering?
The directive places each vulnerability in a tier using four inputs. Three of them are properties of the software: whether the CVE is on the KEV catalog, whether exploitation can be automated, and whether a successful exploit yields partial or total control. NetRise flags KEV status at the component level, supplies the exploit-maturity and exploit-availability signals the automation call rests on, and determines reachability. The agency scores the tier and sets the fourth input, exposure, from its own network data.
Can NetRise analyze systems that can't take an agent or a scan?
That is the case it exists for. Analysis runs against the artifact itself, so mission systems, OT equipment, and air-gapped assets can be assessed without installing anything, touching the live system, or asking the vendor for cooperation.
How does NetRise help with the post-quantum cryptography executive order?
The order sets migration deadlines of December 31, 2030 for key establishment and December 31, 2031 for digital signatures, and makes a named PQC migration lead in each agency responsible for cryptographic inventory. Turbine identifies the certificates, keys, and algorithms present in the compiled artifact, classifies which are quantum-vulnerable, and exports a CycloneDX CBOM. It also surfaces the adjacent conditions — missing encryption, non-FIPS algorithms, weak or exposed keys, expired certificates — that tend to appear wherever nobody has looked.
Can NetRise evaluate a contractor's software before award?
Yes. Candidate builds can be compared on identical binary evidence with no source code and no contractor involvement, so a source-selection or authorization decision points to specific components, CVEs, KEV entries, and end-of-life findings rather than to an attestation.
Which federal mandates does this produce evidence for?
The output supports work under BOD 26-04, EO 14028 SBOM expectations, the post-quantum cryptography executive order, the AI and cybersecurity executive order, NDAA Section 5949, NIST SP 800-161 C-SCRM, the SR control family in NIST SP 800-53, and FedRAMP continuous monitoring. These are alignment points. NetRise supplies evidence an agency uses in its own reporting; it does not by itself confer compliance or an authorization.
How does NetRise support the AI and cybersecurity executive order?
The order directs agencies to defend systems containing AI models and components and to feed a shared vulnerability clearinghouse. Both presuppose knowing which systems those are. Turbine identifies AI models and components inside the compiled artifact and records them in the SBOM alongside every other component, so the AI an agency is being asked to defend appears in the same inventory as everything else. The order sets no SBOM requirement of its own; the inventory is what makes its objectives actionable.
Can NetRise identify AI models inside software an agency didn't build?
Yes. AI-classified components appear in the SBOM with a filterable provider column — OpenAI, Anthropic, Google, Hugging Face and others — and a model details view covering the producing framework, export toolchain, architecture family, and approximate parameter count where embedded metadata is present. Supported formats include ONNX, TFLite, SafeTensors, TensorRT, and pickle. Where a pickle artifact can't be fully inspected statically, it's marked unverified rather than asserted as clean.


